ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ39ÖÜ
Ðû²¼Ê±¼ä 2019-10-08> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ30ÈÕÖÁ10ÔÂ06ÈÕÊÕ¼Çå¾²Îó²î42¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇExim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³öÎó²î; Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³öÎó²î£»£»£»£»£»£»Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Cisco Security Manager Java·´ÐòÁл¯í§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»WhatsApp DDGifSlurpÄÚ´æ¹ýʧÒýÓÃÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺڿÍÇÔÈ¡Áè¼Ý2.18ÒÚWords With FriendsÍæ¼ÒÊý¾Ý£»£»£»£»£»£»µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª£»£»£»£»£»£»eGobblerжñÒâ¹ã¸æ»î¶¯Ð®ÖÆÁè¼Ý10ÒÚÓû§»á»°£»£»£»£»£»£»¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄ˰Êռͼ¼°PIIÔÚÍøÉÏй¶£»£»£»£»£»£»Ñо¿Ö°Ô±Åû¶AndroidϵͳÖеÄÐÂLPE 0day¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1. Exim ¡®string_vformat¡¯º¯Êý»º³åÇøÒç³öÎó²î
https://lists.exim.org/lurker/message/20190927.032457.c1044d4c.en.html
2. Linux kernel cfg80211_mgd_wext_giwessid»º³åÇøÒç³öÎó²î
https://marc.info/?l=linux-wireless&m=157018270915487&w=2
3. Liferay Portal JSON¸ºÔØ·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/
4. Cisco Security Manager Java·´ÐòÁл¯í§Òâ´úÂëÖ´ÐÐÎó²î
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-sm-java-deserial
5. WhatsApp DDGifSlurpÄÚ´æ¹ýʧÒýÓÃÎó²î
https://www.facebook.com/security/advisories/cve-2019-11932
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91850/data-breach/zynga-game-data-breach.html
2¡¢µ¤Âó¹«Ë¾DemantÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ëðʧ9500ÍòÃÀÔª
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-incident-to-cost-danish-company-a-whopping-95-million/
3¡¢eGobblerжñÒâ¹ã¸æ»î¶¯Ð®ÖÆÁè¼Ý10ÒÚÓû§»á»°
Ñо¿Ö°Ô±·¢Ã÷ÁËÓÉÍþв×éÖ¯eGobblerÌᳫµÄÐÂÒ»²¨¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÊܺ¦Õß±»Öض¨Ïòµ½´øÓжñÒâµÄÍøÕ¾¡£¡£¡£¡£Ç徲ר¼ÒÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬eGobblerÊǽñÄ긴Éú½Ú¶à·¢ÐÔ¶ñÒâ¹¥»÷µÄÄ»ºóºÚÊÖ¡£¡£¡£¡£Õâ´Î£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃWebkitä¯ÀÀÆ÷ÒýÇæÎó²îÐ®ÖÆÁËÁè¼Ý10ÒÚ¸ö¹ã¸æÕ¹Ê¾¡£¡£¡£¡£×îеĻ»¹Åú×¢£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÒÔÇ°ÔøÒÔÒÆ¶¯×°±¸Îª¹¥»÷Ä¿µÄµÄÍþв¼ÓÈëÕߵijÌÐòÓÐËù¸Ä±ä£ºÔÚ´Ëʱ´ú£¬£¬£¬£¬£¬£¬£¬£¬eGobbler¶Ǫ̂ʽ»úµÄÆ«ÐÒÖ§³ÖÁËËûÃÇ×îеÄWebKitʹÓᣡ£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/malvertising-attack-hijacks-1b-sessions-with-webkit-exploit/148795/4¡¢¶íÂÞ˹Áè¼Ý2000Íò¹«ÃñµÄ˰Êռͼ¼°PIIÔÚÍøÉÏй¶
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/plaintext-tax-records-of-20-million-russians-leaked-online/5¡¢Ñо¿Ö°Ô±Åû¶AndroidϵͳÖеÄÐÂLPE 0day
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/android-kernel-vulnerability.html


¾©¹«Íø°²±¸11010802024551ºÅ