ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ27ÖÜ

Ðû²¼Ê±¼ä 2018-07-09

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


        2018Äê07ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î54¸ö£¬£¬£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇSchneider Electric U.motion Builder CVE-2018-7777Ô¶³Ì´úÂëÖ´ÐÐÎó²î £»£»£»£»£»Medtronic MyCareLink Patient MonitorÓ²±àÂëÃÜÂëÎó²î £»£»£»£»£»GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý»º³åÇøÒç³öÎó²î £»£»£»£»£»Mozilla Firefox/Firefox ESR¶à¸öÄÚ´æÆÆËðÎó²î £»£»£»£»£»Linux kernel fs/xfs/libxfs/xfs_inode_buf.c¾Ü¾øÐ§ÀÍÎó²î¡£ ¡£¡£¡£¡£¡£¡£

 

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼ £»£»£»£»£»FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ £»£»£»£»£»Ñо¿»ú¹¹Ðû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬ £¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷ £»£»£»£»£»Gentoo LinuxÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë £»£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯¡£ ¡£¡£¡£¡£¡£¡£

 

        ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£¡£¡£¡£¡£

 

¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Schneider Electric U.motion Builder CVE-2018-7777Ô¶³Ì´úÂëÖ´ÐÐÎó²î

        Schneider Electric U.motion Builder software±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬£¬¶ñÒâ¿Í»§¶Ë¿ÉÉÏ´«²¢Ê¹smbdЧÀÍÆ÷Ö´Ðй²Ïí¿â¡£ ¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£º

https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/


2¡¢Medtronic MyCareLink Patient MonitorÓ²±àÂëÃÜÂëÎó²î

 

        Medtronic MyCareLink Patient Monitor±£´æÓ²±àÂëÃÜÂëÎó²î£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-179-01
3¡¢GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý»º³åÇøÒç³öÎó²î

 

        GraphicsMagick coders/png.cÎļþµÄ¡®ReadMNGImage¡¯º¯Êý±£´æ¶Ñ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⡣ ¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://sourceforge.net/p/graphicsmagick/bugs/535/


4¡¢Mozilla Firefox/Firefox ESR¶à¸öÄÚ´æÆÆËðÎó²î

 

        Mozilla Firefox/Firefox ESR±£´æÄÚ´æÆÆËðÎó²î£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ £»£»£»£»£»òÕßÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.mozilla.org/en-US/security/advisories/mfsa2018-15/


5¡¢Linux kernel fs/xfs/libxfs/xfs_inode_buf.c¾Ü¾øÐ§ÀÍÎó²î

 

        Linux kernel fs/xfs/libxfs/xfs_inode_buf.c±£´æÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ £¬£¬£¬Ê¹ÏµÍ³Í߽⡣ ¡£¡£¡£¡£¡£¡£

 

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://bugzilla.kernel.org/show_bug.cgi?id=199915

 

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼

 

MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø

 

ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬£¬£¬ £¬£¬£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£ ¡£¡£¡£¡£¡£¡£Ô­×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬ £¬£¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/

 

2¡¢FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ

 

MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø
       

FacebookÒѾ­ÈϿɣ¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬£¬£¬ £¬£¬£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬£¬£¬ £¬£¬£¬FacebookÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬ËüÒѾ­ÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£ ¡£¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£ ¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html

 

3¡¢Ñо¿»ú¹¹Ðû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬ £¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷

 

MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø


       

±¾ÖܶþAkamaiÐû²¼2018ÄêÏÄÈÕ»¥ÁªÍøÇå¾²±¨¸æ£¬£¬£¬£¬ £¬£¬£¬ÖØµã¹Ø×¢DDoS¹¥»÷µÄÇ÷ÊÆ¡£ ¡£¡£¡£¡£¡£¡£Æ¾Ö¤AkamaiµÄÑо¿£¬£¬£¬£¬ £¬£¬£¬2018ÄêÏÄÈÕÓë2017ÄêÏÄÈÕÏà±È×ÜÌåDDoS¹¥»÷ÔöÌíÁË16%£¬£¬£¬£¬ £¬£¬£¬»ù´¡¼Ü¹¹²ã£¨µÚ3²ãºÍµÚ4²ã£©µÄ¹¥»÷ÔöÌíÁË16%£¬£¬£¬£¬ £¬£¬£¬·´ÉäÐÍDDoS¹¥»÷ÔöÌíÁË4%£¬£¬£¬£¬ £¬£¬£¬Ó¦ÓòãµÄDDoS¹¥»÷ÔöÌíÁË38%¡£ ¡£¡£¡£¡£¡£¡£Õë¶ÔGitHubµÄDDoS¹¥»÷ÊÂÎñ·åÖµÁ÷Á¿´ï1.35 Tbps£¬£¬£¬£¬ £¬£¬£¬´´Á¢ÁËеļͼ¡£ ¡£¡£¡£¡£¡£¡£Mirai¹¥»÷ÈÔÔÚÒ»Á¬£¬£¬£¬£¬ £¬£¬£¬ÐµıäÖÖÒ»Ö±·ºÆð¡£ ¡£¡£¡£¡£¡£¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-top-ddos-trends-in-2018-so-far/133038/

 

4¡¢Gentoo LinuxÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë

 

MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø
       

Gentoo Linux¿ª·¢ÍŶÓÐû²¼¹ØÓÚGitHubÕË»§ÔâºÚ¿ÍÈëÇÖÊÂÎñµÄÊӲ챨¸æ¡£ ¡£¡£¡£¡£¡£¡£¸ÃÍŶӳƹ¥»÷Õßͨ¹ýÃÜÂëÍÆ²â»ñµÃÆäGitHubÕË»§µÄÃÜÂë¼°ÖÎÀíȨÏÞ£¬£¬£¬£¬ £¬£¬£¬ÊӲ췢Ã÷µÄÎÊÌ⻹°üÀ¨Î´½ÓÄÉË«ÒòËØÈÏÖ¤¡¢Î´ÉúÑÄGitHub OrganizationÏêϸÐÅÏ¢µÄ±¸·ÝÒÔ¼°systemd repoÖ±½Ó´æ´¢ÔÚGitHubÉÏ¡£ ¡£¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬ £¬£¬£¬GentooºÍGithub¶Ô¸ÃÊÂÎñµÄÏìÓ¦½Ïʵʱ£¬£¬£¬£¬ £¬£¬£¬Ê¹µÃ¹¥»÷Ö»Ò»Á¬ÁËÔ¼70·ÖÖÓ¡£ ¡£¡£¡£¡£¡£¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/github-hacking-gentoo-linux.html

 

5¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯

 

MG±ùÇòÍ»ÆÆÊÔÍæ--ÊÖ»ú°æapp¹ÙÍø
       

PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬ £¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£ ¡£¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£ ¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬ £¬£¬£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£ ¡£¡£¡£¡£¡£¡£

 

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html