Libarchive´úÂëÖ´ÐÐÎó²îÓ°ÏìLinux¼°BSD¿¯Ðа棻£»£»£»£»Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ
Ðû²¼Ê±¼ä 2019-11-07
¹È¸èÇå¾²Ñо¿Ö°Ô±ÔÚLibarchiveÖз¢Ã÷Ò»¸ö´úÂëÖ´ÐÐÎó²î£¨CVE-2019-18408£©£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕʹÓû§·¿ª¶ñÒâ´æµµÎļþÔÚÆäϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£Debian¡¢Ubuntu¡¢Gentoo¡¢Arch LinuxÒÔ¼°FreeBSDºÍNetBSD¿¯Ðаæ¾ùÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«WindowsºÍmacOS²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£LibarchiveÍŶÓÔÚа汾3.4.0ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδÔÚÒ°Íâ·¢Ã÷¸ÃÎó²îµÄPoC»òʹÓôúÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/libarchive-vulnerability-can-lead-to-code-execution-on-linux-freebsd-netbsd/2¡¢¹È¸èÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î
¹È¸è±¾ÖÜÐû²¼11ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Á˽ü40¸öÎó²î¡£¡£¡£¡£¡£¡£¹È¸èÔÚ2019-11-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁËFramework¡¢Library¡¢Ã½Ìå¿ò¼ÜºÍϵͳÖеÄ17¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇϵͳ×é¼þÖеÄÈý¸öRCEÎó²î£¨CVE-2019-2204~CVE-2019-2206£©£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳ°æ±¾Îª8.0¡¢8.1¡¢9ºÍ10¡£¡£¡£¡£¡£¡£¹È¸è»¹ÔÚ2019-11-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÖÐÐÞ¸´ÁË21¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÊǸßͨ×é¼þÖеÄ5¸öÎó²î¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/google-patches-critical-flaws-androids-system-component3¡¢NVIDIAÐÞ¸´ÏÔ¿¨Çý¶¯¼°GeForce Experience 12¸öÎó²î
NVIDIAÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäÏÔ¿¨Çý¶¯³ÌÐòºÍGFEÈí¼þÖеÄ12¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Îó²î¹æÄ£º¸Ç´úÂëÖ´ÐС¢È¨ÏÞÌáÉý¡¢ÐÅϢй¶ºÍ¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£ËùÓеÄÎó²î¶¼²»¿É±»Ô¶³ÌʹÓ㬣¬£¬£¬£¬£¬£¬£¬±ØÐèÍâµØÓû§»á¼û£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷Õß±ØÐèÒÀÀµÓû§½»»¥À´Ê¹ÓÃËüÃÇ¡£¡£¡£¡£¡£¡£ÕâЩÎó²îµÄCVSS V3ÆÀ·ÖΪ5.1µ½7.8Ö®¼ä£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ4¸ö¸ßΣÎó²îΪÏÔ¿¨Çý¶¯ÖеĻº³åÇøÒç³ö£¨CVE?2019?5690£©¡¢¿ÕÖ¸Õë½âÒýÓã¨CVE?2019?5691£©¡¢Êý×éË÷ÒýÔ½½ç£¨CVE?2019?5692£©ÒÔ¼°GFEÖеÄDLLÐ®ÖÆ£¨CVE?2019?5701£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nvidia-fixes-security-flaws-in-gpu-driver-geforce-experience/4¡¢FacebookÔÙÆØÒþ˽й¶£¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±Î¥¹æ»á¼ûÓû§ÐÅÏ¢
FacebookÔÙÆØÒþ˽й¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼100Ãû¿ª·¢Ö°Ô±¿ÉÎ¥¹æ»á¼ûÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£±¾ÖܶþFacebookƽ̨ÏàÖú×ܼàKonstantinos PapamiltiadisÔÚһƪ²©ÎÄÖÐ͸¶£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü2018Äê4ÔÂÔø¶ÔÆäȨÏÞ¾ÙÐÐÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬µ«²¿·Ö¿ª·¢Ö°Ô±ÈÔ¿ÉÒÔ»á¼ûÓû§µÄÐÕÃû¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏͼƬÒÔ¼°ÏµÍ³APIµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£×ܹ²Ô¼ÓÐ100Ãû¿ª·¢Ö°Ô±¿ÉÒÔ»á¼û´ËÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬FacebookÈ·ÈÏÖÁÉÙÓÐ11Ãû¿ª·¢Ö°Ô±ÔÚÒÑÍù60ÌìÄÚ»á¼ûÁËÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒѾ×÷·ÏÁËÕâÒ»»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ»á¶ÔÏà¹ØÇéÐξÙÐÐÉó²é¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐ͸¶Óм¸¶àÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/facebook-reveals-another-data-breach-this-time-involving-developers/
5¡¢Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡Áè¼Ý12ÍòÓû§ÐÅÏ¢²¢³öÊÛ
Ç÷ÊÆ¿Æ¼¼ÄÚ²¿Ô±¹¤ÇÔÈ¡¹«Ë¾¿Í»§ÐÅÏ¢²¢½«Æä³öÊÛ¸øµÚÈý·½Õ©ÆÍŻ¡£¡£¡£¡£¡£ÔÚ¿Í»§Ôâµ½ÊÖÒÕÖ§³Öթƺ󣬣¬£¬£¬£¬£¬£¬£¬Ç÷ÊÆ¿Æ¼¼Õö¿ªÊӲ첢·¢Ã÷¸ÃÔ±¹¤²»·¨»á¼ûÁ˿ͻ§Ö§³ÖÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÄܱ»ÇÔµÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖÒÕÖ§³Öµ¥ºÅÒÔ¼°µç»°ºÅÂ룬£¬£¬£¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ç¿µ÷ûÓм£ÏóÅú×¢²ÆÎñ»òÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÉæ¼°µ½ÆóÒµ»òÕþ¸®¿Í»§¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÆäÄÚ²¿ÊӲ죬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¿Í»§Ö»Õ¼Ç÷ÊÆ¿Æ¼¼1200Íò¿Í»§ÈºµÄ²»µ½1%£¬£¬£¬£¬£¬£¬£¬£¬¼´12Íò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trendmicro-employee-sold-customer-info-to-tech-support-scammers/
6¡¢AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûÔËÓªÉÌLyca Mobile
AnonymousºÍLulzSecITAÈëÇÖÒâ´óÀûͨѶÔËÓªÉÌLyca Mobile£¬£¬£¬£¬£¬£¬£¬£¬´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË5.4GBµÄÎļþ¡£¡£¡£¡£¡£¡£´Óй¶µÄÎļþÀ´¿´£¬£¬£¬£¬£¬£¬£¬£¬ÎĵµÖаüÀ¨Lyca MobileÓû§µÄ¹«¹²ID¡¢»¤ÕÕ¡¢¼ÝÕÕ¡¢µç»°¼Í¼¼°ÐÅÓÿ¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸öÎļþ¼ÐµÄÄÚÈÝËÆºõÊôÓڸù«Ë¾µÄ¹Ù·½ÓÊÏäÕË»§lycamobile[at]lycamobile[.]it¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞ·¨ÑéÖ¤ÕâЩÎĵµµÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊǺڿÍ×éÖ¯ÌᳫÕâЩ¹¥»÷Ö»ÊÇΪÁËÑéÖ¤ÆäÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊǶÔÓû§¾ÙÐÐڲơ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/93474/hacktivism/lulzsecita-lyca-mobile.html


¾©¹«Íø°²±¸11010802024551ºÅ