Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»£»£»£»£»£»£»TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î

Ðû²¼Ê±¼ä 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190619



1¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ£¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬£¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î£¬£¬£¬£¬£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÐͺÅ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
IBM X-ForceÑо¿Ô±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2£¬£¬£¬£¬£¬buildΪ20180213¡£¡£¡£¡£¡£¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐУ¬£¬£¬£¬£¬ÔÚ·¢ËÍ×°±¸Ê¹ÓúÍÔËÐÐshellÏÂÁîµÄÇëÇóʱ£¬£¬£¬£¬£¬¿Éͨ¹ý¸Ä¶¯HTTPÍ·ÖеÄuser agent×ֶδ¥·¢Îó²î£¬£¬£¬£¬£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÐʱ»úÐ®ÖÆ×°±¸²¢»ñµÃÍêÈ«¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day£¬£¬£¬£¬£¬PoCÒÑÐû²¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Plugin VulnerabilitiesÑо¿Ö°Ô±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ»®·ÖÊÇMessenger Customer ChatºÍFacebook for WooCommerce£¬£¬£¬£¬£¬ÆäÖÐǰÕßÔÚÁè¼Ý2Íò¸öÕ¾µãÉÏ×°Ö㬣¬£¬£¬£¬ºóÕßµÄ×°ÖÃÁ¿Áè¼Ý20Íò´Î¡£¡£¡£¡£¡£¡£Îó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÉèÖÃÑ¡Ï£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­Ðû²¼ÁËÏà¹ØÏ¸½ÚºÍPoC´úÂë¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâÍâй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
SafetyDetectiveÑо¿Ö°Ô±·¢Ã÷Ò»¸öÎÞ±£»£»£»£»£»£»£»¤µÄÊý¾Ý¿âй¶´ó×Ú¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton£¬£¬£¬£¬£¬Êý¾Ý¿âÖÐ̻¶ÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¼ÒµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢Ä¿½ñ¹ÍÖ÷¡¢ÈËΪԤÆÚ¡¢ÇóÖú״̬µÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨Áè¼Ý5Íò¸ö¼ÓÃÜÃÜÂë¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä̻¶£¬£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬£¬ÍйÜЧÀÍÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾ÒâÍâй¶15Íò·ÝΣÏÕË÷Åâ¼Í¼

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
Çå¾²Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷¹ã¸æ¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£»£»£»£»£»£»£»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝΣÏÕË÷Åâ¼Í¼¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×ÊÖú״ʦÊÂÎñËùÓëÊܺ¦ÕßÇ©ÊðЭÒ飬£¬£¬£¬£¬Êý¾Ý¿âй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÒÔ¼°Ê¹ʡ¢Î£ÏÕ»ò¼²²¡ÇéÐεÄÚ¹ÊÍ£¬£¬£¬£¬£¬»¹°üÀ¨Ð¡ÎÒ˽¼Ò¿µ½¡ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢ÖÎÁÆÏ¸½ÚµÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨300¶à¼Ò״ʦÊÂÎñËùÏò¹ã¸æ¹«Ë¾Ö§¸¶µÄÏêϸÓöÈÇåµ¥¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Áè¼Ý600ÍòÌõÓû§¼Í¼±»ÇÔ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾
 
ʳÎï¶©¹ºÐ§À͹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éµÄÏêϸÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£Æ¾Ö¤EatStreetµÄ±íÊö£¬£¬£¬£¬£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÖÆäÅÌËã»úÍøÂç²¢»á¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ»á¼û¡£¡£¡£¡£¡£¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢°üÀ¨¶©¹ºÊ³ÎïµÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õЧÀ͵ÄÐÅÏ¢£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÒøÐÐÕË»§µÈ£¬£¬£¬£¬£¬Óû§µÄÐÅÓÿ¨Ö§¸¶ÏêϸÐÅÏ¢Ò²Ôâй¶¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶Óм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬µ«ºÚ¿ÍÉù³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/