ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ38ÖÜ

Ðû²¼Ê±¼ä 2018-09-25
 Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö

2018Äê09ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼Çå¾²Îó²î55¸ö£¬£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache SpamAssassin meta ruleÓï·¨í§Òâ´úÂëÖ´ÐÐÎó²î£» £»£»Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£» £»£»Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£» £»£»Adobe AcrobatºÍReader CVE-2018-12848Ô½½çдÎó²î£» £»£»Apple iOS Core Bluetooth  CVE-2018-4330í§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÑо¿ÍŶӳÆÁè¼Ý20ÒŲ́װ±¸ÈÔÊÜBlueBorneÎó²îµÄÓ°Ï죻 £»£»Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑ×èֹЧÀÍÁ½Ì죻 £»£»MongoDBÉèÖùýʧµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹ûÕæ»á¼û£» £»£»GovPayNet¹ÙÍø±£´æÎó²î£¬£¬£¬£¬ £¬£¬Áè¼Ý1400ÍòÓû§¼Í¼ÒÉй¶£» £»£»ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶¡£¡£¡£ ¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£ ¡£¡£¡£

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache SpamAssassin meta ruleÓï·¨í§Òâ´úÂëÖ´ÐÐÎó²î


Apache SpamAssassin meta ruleÓï·¨´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£

https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c@%3Cannounce.apache.org%3E


2. Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´ÐÐÎó²î


RSLinx Classic´¦Öóͷ£ÌØÊâµÄCIP±¨Îı£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇóµ½44818¶Ë¿Ú£¬£¬£¬£¬ £¬£¬¿Éʹϵͳ±ÀÀ£» £»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1075712


3. Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


Adobe ColdFusion·´ÐòÁл¯´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html


4. Adobe AcrobatºÍReader CVE-2018-12848Ô½½çдÎó²î


Adobe AcrobatºÍReader±£´æÔ½½çдÎó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬ £¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html


5. Apple iOS Core Bluetooth  CVE-2018-4330í§Òâ´úÂëÖ´ÐÐÎó²î


Apple iOS Core Bluetooth×é¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£
https://support.apple.com/en-us/HT208848

 Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ñо¿ÍŶӳÆÁè¼Ý20ÒŲ́װ±¸ÈÔÊÜBlueBorneÎó²îµÄÓ°Ïì

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Armis LabsÑо¿ÍŶӳÆÁè¼Ý20ÒÚ×°±¸ÈÔÊÜÒ»ÄêǰÅû¶µÄBlueBorneÎó²îµÄÓ°Ïì¡£¡£¡£ ¡£¡£¡£BlueBorne°üÀ¨9¸öÀ¶ÑÀÎó²î£¬£¬£¬£¬ £¬£¬ÓÚ2017Äê9Ô±»Åû¶²¢Ëæºó¾ÙÐÐÐÞ¸´¡£¡£¡£ ¡£¡£¡£µ½Ò»ÄêºóµÄ½ñÌ죬£¬£¬£¬ £¬£¬Ô¼Èý·ÖÖ®¶þµÄÊÜÓ°Ïì×°±¸ÒѾ­¾ÙÐÐÁ˸üУ¬£¬£¬£¬ £¬£¬µ«ÈÔÓдó×ÚµÄЧÀÍÆ÷¡¢ÖÇÄÜÊÖ±í¡¢Ò½ÁÆ×°±¸ºÍ¹¤Òµ×°±¸µÈ»¹Î´¾ÙÐÐÐÞ¸´£¬£¬£¬£¬ £¬£¬°üÀ¨7.68ÒŲ́Linux×°±¸¡¢7.34ÒŲ́ÔËÐÐAndroid5.1¼°¸üÔç°æ±¾µÄ×°±¸¡¢2.61ÒŲ́ÔËÐÐAndroid6¼°¸üÔç°æ±¾µÄ×°±¸¡¢2ÒŲ́Windows×°±¸ÒÔ¼°5000Íǫ̀ÔËÐÐiOS9.3.5¼°¸üÔç°æ±¾µÄ×°±¸¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.armis.com/blueborne-one-year-later/


2¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑ×èֹЧÀÍÁ½Ìì


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑ×èֹЧÀÍÁ½Ìì¡£¡£¡£ ¡£¡£¡£¸Ã»ú³¡µÄ½²»°ÈËÌåÏÖº½°à²»ÊÜÓ°Ï죬£¬£¬£¬ £¬£¬µ«±ØÐèʹÓÃÓ¦¼±²½·¥ºÍÊÖ¶¯µÄÁ÷³Ì£¬£¬£¬£¬ £¬£¬°üÀ¨°×°åºÍ¼ÇºÅ±ÊµÈÀ´È¡´úÏÔʾÆÁ¡£¡£¡£ ¡£¡£¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð¡£¡£¡£ ¡£¡£¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬£¬£¬£¬ £¬£¬¶øÊÇËæ»úµÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£¸Ã»ú³¡ÕýÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚÖØÐÂÉÏÏß֮ǰÊÇÇå¾²µÄ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html


3¡¢MongoDBÉèÖùýʧµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹ûÕæ»á¼û


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Çå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄMongoDB£¬£¬£¬£¬ £¬£¬¸ÃÊý¾Ý¿âÖаüÀ¨Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£¡£¡£ ¡£¡£¡£Êý¾Ý¿âµÄ¾ÞϸΪ43.5GB£¬£¬£¬£¬ £¬£¬°üÀ¨ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØµã¡¢ÓÊÕþ±àÂëºÍÆÜÉí¶¼»áµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬£¬£¬£¬ £¬£¬ÏÖÔÚ»¹²»ÖªµÀ¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/


4¡¢GovPayNet¹ÙÍø±£´æÎó²î£¬£¬£¬£¬ £¬£¬Áè¼Ý1400ÍòÓû§¼Í¼ÒÉй¶


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ΪÃÀ¹úÖÝÕþ¸®ºÍµØ·½Õþ¸®ÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬Áè¼Ý1400ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ÒÉй¶¡£¡£¡£ ¡£¡£¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öÕþ¸®»ú¹¹ÌṩЧÀÍ£¬£¬£¬£¬ £¬£¬¹«Ãñ¿ÉÒÔͨ¹ýËüÀ´Ö§¸¶·£¿£¿£¿£¿£¿£¿î¡¢ÅÆÕշѺÍÕ˵¥µÈ¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤Brian KrebsµÄ˵·¨£¬£¬£¬£¬ £¬£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´Ë³Ðò±àºÅµÄ£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄURLÖеÄÊý×ÖÀ´Éó²éÆäËüÈ˵ļͼ¡£¡£¡£ ¡£¡£¡£ÕâЩ¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒÑÔÚÖÜÄ©ÐÞ¸´ÁËÕâÒ»ÎÊÌâ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/


5¡¢ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶


c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬ £¬£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄСÎÒ˽¼ÒÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤¹úÎñÔºÐû²¼µÄͨ¸æ£¬£¬£¬£¬ £¬£¬¸Ãµç×ÓÓʼþϵͳÊÇ·ÇÉñÃØÐÔµç×ÓÓʼþϵͳ£¬£¬£¬£¬ £¬£¬Æä±»ÐÎòΪÃô¸Ðµ«²»Éæ¼°ÉñÃØ¡£¡£¡£ ¡£¡£¡£¹úÎñÔº½²»°ÈËNicole ThompsonÌåÏÖÕâÒ»ÊÂÎñ»¹ÔÚÊÓ²ìÖ®ÖУ¬£¬£¬£¬ £¬£¬¹úÎñÔºÕýÔÚÓëÏàÖúͬ°éºÍ˽Ӫ²¿·ÖЧÀÍÉÌÅäºÏ¾ÙÐÐÖÜÈ«µÄÆÀ¹À¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665


ÉùÃ÷£º±¾×ÊѶÓÉc7c7ÓéÀÖÆ½Ì¨Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí