ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ8ÖÜ

Ðû²¼Ê±¼ä 2019-02-25

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ18ÈÕÖÁ24ÈÕ¹²ÊÕ¼Çå¾²Îó²î48¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDrupal CVE-2019-6340Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»£»WinRAR ACEÎļþí§Òâ´úÂëÖ´ÐÐÎó²î; Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉýÎó²î£»£»£»£»£»£»£»£»Adobe Acrobat/Reader CVE-2019-7018í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»£»Huawei Mate20 CVE-2019-5296»º³åÇøÒç³öÎó²î¡£¡£¡£¡£ ¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺڿͰµÍø³öÊÛµÚÈýÅúÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§£»£»£»£»£»£»£»£»Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀԪϢÕù½ð£»£»£»£»£»£»£»£»IxigoÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼1800ÍòÓû§Êý¾Ýй¶£»£»£»£»£»£»£»£»WinRAR´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ï죻£»£»£»£»£»£»£»Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£ ¡£¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Drupal CVE-2019-6340Ô¶³Ì´úÂëÖ´ÐÐÎó²î
DrupalÔÚͨ¹ý·Ç±í¸ñ£¨non-form resources£©ÀàÐÍÊäÈëʱδÄÜ׼ȷ¹ýÂËijЩ×ֶΣ¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£
https://www.drupal.org/sa-core-2019-003

2. WinRAR ACEÎļþí§Òâ´úÂëÖ´ÐÐÎó²î
WinRAR UNACEV2.dll¿â´¦Öóͷ£.aceÎļþ±£´æÄ¿Â¼´©Ô½ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£
http://win-rar.com/

3. Intel Data Center Manager SDK CVE-2019-0107ȨÏÞÌáÉýÎó²î
Intel Data Center Manager SDK×°ÖóÌÐòÓû§ÌáÐÑʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£ ¡£¡£¡£
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html

4. Adobe Acrobat/Reader CVE-2019-7018í§Òâ´úÂëÖ´ÐÐÎó²î
Adobe Acrobat/Reader±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-07.html

5. Huawei Mate20 CVE-2019-5296»º³åÇøÒç³öÎó²î
Huawei Mate20±£´æÔ½½ç¶ÁÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿Éʹװ±¸Òì³£¡£¡£¡£¡£ ¡£¡£¡£
https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190220-01-phone-cn

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ºÚ¿Í°µÍø³öÊÛµÚÈýÅúÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°8¸öÍøÕ¾Ô¼9300ÍòÓû§

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

GnosticplayersÔÚ°µÍøÊг¡ÉÏÐû²¼Á˵ÚÈýÅú´ýÊÛµÄÓû§ÕË»§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°µ½8¸öÍøÕ¾µÄ9276ÍòÓû§¡£¡£¡£¡£ ¡£¡£¡£Õâ8¸öÍøÕ¾°üÀ¨£ºLegendas.tv£¨386Íò£©¡¢Jobandtalent£¨1100Íò£©¡¢Onebip£¨260Íò£©¡¢StoryBird£¨400Íò£©¡¢StreetEasy£¨100Íò£©¡¢GfyCat£¨800Íò£©¡¢ClassPass£¨150Íò£©ºÍPizap£¨6080Íò£©¡£¡£¡£¡£ ¡£¡£¡£ÕâÅúÓû§Êý¾ÝµÄ×ܼÛǮΪ2.6249¸ö±ÈÌØ±Ò£¬£¬£¬£¬£¬£¬£¬£¬¹²Ô¼9400ÃÀÔª¡£¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-puts-up-for-sale-third-round-of-hacked-databases-on-the-dark-web/

2¡¢Wendy'sÔÞ³ÉΪÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀԪϢÕù½ð

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤×îб¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬²ÍÒû¹«Ë¾Wendy'sÒÑÔÞ³ÉΪ2015ÄêµÄÊý¾Ýй¶ÊÂÎñÖ§¸¶5000ÍòÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£¡£ ¡£¡£¡£ÔÚ¸ÃÊý¾Ýй¶ÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬Ô¼1800ÍòÕÅÐÅÓÿ¨¼°½è¼Ç¿¨ÐÅÏ¢Ô⵽й¶£¬£¬£¬£¬£¬£¬£¬£¬Îª´Ë½ðÈÚ»ú¹¹ÔÚ2016ÄêÌáÆðÁËËßËÏ¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤Ìá½»¸øÆ¥×ȱ¤Áª°î·¨ÔºµÄÒ»·ÝÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩϢÕù½ð½«Ö§¸¶¸øÔ¼7500¼ÒÒøÐкÍÐÅÓÃÉç¡£¡£¡£¡£ ¡£¡£¡£¸ÃÉúÒâÈÔÐè»ñµÃ·¨ÔºµÄÅú×¼¡£¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.databreaches.net/update-wendys-settles-financial-firms-lawsuit-over-data-breach-for-50-mln/

3¡¢IxigoÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Ô¼1800ÍòÓû§Êý¾Ýй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚÏßÂÃÓÎÆ½Ì¨IxigoµÄÔ¼1800ÍòÓû§Êý¾Ý±»µÁ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÖ÷Òª°üÀ¨Óû§µÄµç×ÓÓʼþIDºÍ¹þÏ£ÃÜÂëµÈ¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾CEO Aloke BajpaiÌåÏָù«Ë¾²¢Î´´æ´¢Óû§µÄÖ§¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËûÓÐÏà¹ØÐÅÏ¢±»µÁ£¬£¬£¬£¬£¬£¬£¬£¬ÇҸù«Ë¾ÕýÔÚ֪ͨ²¢ÒªÇóÓû§ÖØÖÃÆäÃÜÂëºÍÇå¾²ÁîÅÆ¡£¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÓû§×ÜÊýΪԼ1ÒÚ¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://timesofindia.indiatimes.com/business/india-business/emails-hashed-passwords-of-18m-ixigo-users-stolen/articleshow/68016866.cms

4¡¢WinRAR´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý5ÒÚÓû§Êܵ½Ó°Ïì

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Check PointÑо¿ÍŶÓÅû¶WinRARÖеĴúÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒѱ£´æÁËÁè¼Ý19ÄêµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÁè¼Ý5ÒÚÓû§¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î£¨CVE-2018-20250¡¢CVE-2018-20251¡¢CVE-2018-20252ºÍCVE-2018-20253£©±£´æÓÚWinRARµÄUNACEV2.DLL¿âÖУ¬£¬£¬£¬£¬£¬£¬£¬Õâ¸ö¿âÈÏÕæ½âѹËõACEÃûÌõÄѹËõÎļþ¡£¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¸Ã¿â±£´æ±àÂëȱÏÝ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâACEÎļþÔÚ½âѹËõµÄÄ¿µÄ·¾¶Ö®ÍâÖ²Èë¶ñÒâÈí¼þ¡£¡£¡£¡£ ¡£¡£¡£WinRARÍŶÓÌåÏÖÓÉÓÚUNACEV2.DLL´Ó2005ÄêÆð¾Í×èÖ¹Á˸üУ¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢Ö°Ô±ÒѾ­Ê§È¥Á˸ÿâÔ´´úÂëµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Òò´ËËûÃÇÑ¡Ôñ·ÅÆú¶ÔACEÃûÌõÄÖ§³Ö¡£¡£¡£¡£ ¡£¡£¡£WinRAR¿ª·¢ÕßÔÚ1ÔÂ28ÈÕÐû²¼ÁËWinRAR 5.70 Beta 1ÒÔÐÞ¸´´ËÎó²î¡£¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://research.checkpoint.com/extracting-code-execution-from-winrar/

5¡¢Ó¡¶ÈIndane¹«Ë¾Ð¹Â¶Ô¼679ÍòAadhaar¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


·¨¹úÇå¾²Ñо¿Ô±Baptiste RobertÔÚһλÄäÃûÓ¡¶ÈÑо¿Ö°Ô±µÄ×ÊÖúÏ£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷Ó¡¶È¹úÓÐÒº»¯Ê¯ÓÍÆø¹«Ë¾IndaneµÄ¹ÙÍøÐ¹Â¶ÁËÊý°ÙÍòAadhaar¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£RobertÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Ëû¿ÉÒÔʹÓÃIndaneÒÆ¶¯APPÖеÄÎó²îÕÒµ½11062¸öÓÐÓõľ­ÏúÉÌID£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÕâЩIDÔÚ¾­ÏúÉÌÃÅ»§ÍøÕ¾ÉÏ»ñÈ¡AadhaarÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨AadhaarºÅÂë¡¢ÐÕÃûºÍסַ¡£¡£¡£¡£ ¡£¡£¡£RobertÔ¤¼ÆÊÜÓ°ÏìµÄÓû§ÊýԼΪ679Íò¡£¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/indane-aadhaar-leak.html

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí