ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ38ÖÜ

Ðû²¼Ê±¼ä 2019-09-30

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê9ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬£¬ £¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇRIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓÃÎó²î; vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£» £»Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£» £»Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£» £»phpstudyºóÃÅÖ²ÈëÎó²î ¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTescoÍ£³µÓ¦Óñ£´æÎó²îµ¼ÖÂÊýÍòÍò³µÅÆÍ¼Ïñй¶£»£»£»£»£»£» £»Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î£»£»£»£»£»£» £»¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»£» £»iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ£»£»£»£»£»£» £»iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü ¡£ ¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£ ¡£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. RIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓÃÎó²î
RIOT MQTT-SNʵÏÖ±£´æ¿ÕÖ¸ÕëÒýÓÃÎó²î£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬ £¬¿ÉʹϵͳÍ߽⠡£ ¡£¡£¡£
https://github.com/RIOT-OS/RIOT/pull/12293

2. vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î
vBulletin ajax/render/widget_php routestring´¦Öóͷ£widgetConfig[code]±£´æÇå¾²Îó²î£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî ¡£ ¡£¡£¡£
https://seclists.org/fulldisclosure/2019/Sep/31

3. Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î
Adobe ColdFusionij×é¼þ±£´æÇå¾²Îó²î£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬ £¬¿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐÐ ¡£ ¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html

4. Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Internet Explorer´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬ £¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬ £¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£» £»òÖ´ÐÐí§Òâ´úÂë ¡£ ¡£¡£¡£
https://support.microsoft.com/zh-cn/help/4522007/cumulative-security-update-for-internet-explorer

5. phpstudyºóÃÅÖ²ÈëÎó²î
phpstudy±»×¢ÈëºóÃÅ£¬£¬ £¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬ £¬¿ØÖÆÄ¿µÄÓ¦ÓÃϵͳ ¡£ ¡£¡£¡£
https://www.xp.cn/


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢TescoÍ£³µÓ¦Óñ£´æÎó²îµ¼ÖÂÊýÍòÍò³µÅÆÍ¼Ïñй¶

welcome-°ÙÀÖ²©


ÔÚÍâýThe Register±¨µÀÊýÍòÍòÕÅANPR£¨³µÅÆ×Ô¶¯Ê¶±ð£©Í¼ÏñÔÚMicrosoft AzureÖÐ̻¶֮ºó£¬£¬ £¬£¬ £¬TescoÒÑ¹Ø±ÕÆäÍ£³µÑéÖ¤WebÓ¦Óà ¡£ ¡£¡£¡£ÕâЩͼÏñÓÉÓ¢¹ú¸÷µØµÄ19¸öTescoÍ£³µ³¡ºÏÅÄÉãµÄ½øÈëºÍÍÑÀëµÄÆû³µÕÕÆ¬×é³É£¬£¬ £¬£¬ £¬ÕÕÆ¬ÖÐÍ»³öÏÔʾÁËÆû³µµÄ³µÅÆ£¬£¬ £¬£¬ £¬ËäÈ»ÓÉÓÚÇø·ÖÂʽϵͶø¿´²»µ½¼ÝʻԱ ¡£ ¡£¡£¡£ANPRͼÏñÒÔ´øÓÐʱ¼ä´ÁµÄjpegÃûÌÃÉúÑÄÔÚAzure blobÖУ¬£¬ £¬£¬ £¬²¢ÇÒͼÏñÎļþÃûÒ²°üÀ¨Ê±¼äÐÅÏ¢£¬£¬ £¬£¬ £¬´Ó¶øÊ¹µÃÈκÎ×¼È·ÍÆ¶Ï³öËùÐèHTTP POSTÇëÇóÃûÌõÄÈË¿ÉÒÔÅúÁ¿»ñÈ¡ÕâЩͼÏñÒÔ¹©²»·¨Ê¹Óà ¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/

2¡¢Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î


welcome-°ÙÀÖ²©


΢ÈíÐû²¼½ôÆÈÇå¾²¸üУ¬£¬ £¬£¬ £¬ÐÞ¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoSÎó²î ¡£ ¡£¡£¡£ÆäÖÐIE 0dayΪ¹È¸èÑо¿Ö°Ô±Cl¨¦mentLecigne·¢Ã÷µÄ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1367£©£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë ¡£ ¡£¡£¡£¸ÃÎó²î¿ÉÒÔͨ¹ý½«Ä¿µÄÓû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾À´Ê¹Ó㬣¬ £¬£¬ £¬ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨IE9¡¢10ºÍ11 ¡£ ¡£¡£¡£ÁíÒ»¸öÎó²îÊÇWindows DefenderÖеľܾøÐ§ÀÍÎó²î£¨CVE-2019-1255£©£¬£¬ £¬£¬ £¬¸ÃÎó²îÓëDefender´¦Öóͷ£ÎļþµÄ·½·¨ÓйØ£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²î×èÖ¹Õýµ±ÕË»§Ö´ÐÐÕýµ±µÄϵͳÎļþ ¡£ ¡£¡£¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬£¬ £¬£¬ £¬²¢ÒÑÔÚ1.1.16400.2ÖÐÐÞ¸´ ¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/

3¡¢¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷


welcome-°ÙÀÖ²©


Æ¾Ö¤ÔÆÇå¾²¹«Ë¾ArmorµÄµ÷ÑУ¬£¬ £¬£¬ £¬ÃÀ¹úÒÑÓÐ49¸öÑ§ÇøµÄ½ÌÓý»ú¹¹Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬ £¬Ê¹µÃ½ÌÓýÐÐÒµ³ÉΪ½ö´ÎÓڵط½Õþ¸®µÄµÚ¶þ´óÒ×Êܹ¥»÷Ä¿µÄ ¡£ ¡£¡£¡£¸Ã¹«Ë¾ÆÊÎöÁË×Ô2019Äê1ÔÂÒÔÀ´¹ûÕæ±¨µÀµÄ¹¥»÷£¬£¬ £¬£¬ £¬·¢Ã÷ÔÚ2019Äêǰ9¸öÔÂÒÑÓжà´ï500ËùK-12ѧУÔâµ½¹¥»÷£¬£¬ £¬£¬ £¬¶øÈ¥ÄêÖ»ÓÐ11ËùѧУ ¡£ ¡£¡£¡£½öÔÚ9ÔÂÖÐÑ®µÄÒ»Öܶàʱ¼äÀï¾ÍÓÐ9¸öÐÂÑ§ÇøºÍ1Ëù´óѧÊܵ½¹¥»÷£¬£¬ £¬£¬ £¬²¨¼°Ô¼100ËùK-12ѧУ ¡£ ¡£¡£¡£¿£¿£¿£¿£¿£¿£¿µÄùµÒ¸ñÖݵÄÑ§ÇøÊܵ½µÄÍþв×îΪÑÏÖØ£¬£¬ £¬£¬ £¬¸ÃÖݹ²ÔâÓöÁË7´Î¹¥»÷£¬£¬ £¬£¬ £¬º­¸Ç104ËùѧУ ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/hundreds-of-us-schools-hit-by/

4¡¢iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ

welcome-°ÙÀÖ²©


Æ»¹û¹Ù·½Ðû²¼ÁËÒ»·ÝеÄÖ§³ÖÎĵµ£¬£¬ £¬£¬ £¬ÖÒÑÔÓû§ÓйØiOS 13ºÍiPadOSµÚÈý·½¼üÅ̱£´æµÄÇå¾²Îó²î ¡£ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬ £¬£¬ £¬Ò»Ð©µÚÈý·½¼üÅÌÈí¼þ×ÝȻδ±»Åú×¼ÍêÈ«»á¼ûȨÏÞÒ²¿ÉÄÜ»áÓÉÓÚiOS 13ºÍiPadOSÖеÄÎó²î¶ø±»ÊÚÓèÍêÈ«»á¼ûȨÏÞ ¡£ ¡£¡£¡£ÕâÒ»ÎÊÌâÓ°ÏìÁËiPhone¡¢iPad»òiPod touch×°ÖõļüÅÌ£¬£¬ £¬£¬ £¬µ«²»Ó°ÏìÆ»¹ûµÄÄÚÖüüÅÌ£¬£¬ £¬£¬ £¬Ò²²»»áÓ°ÏìδʹÓÃÍêÈ«»á¼ûȨÏ޵ĵÚÈý·½¼üÅÌ£¬£¬ £¬£¬ £¬Æ»¹û½«ÔÚ¼´½«µ½À´µÄÈí¼þ¸üÐÂÖÐÐÞ¸´´ËÎó²î ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/bug-granting-full-access-keyboards/148638/

5¡¢iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü


welcome-°ÙÀÖ²©


Çå¾²Ñо¿Ô±axi0mXÅû¶iOSÖеÄÇå¾²Îó²îcheckm8£¬£¬ £¬£¬ £¬¸ÃÎó²î¿ÉÒÔʹiPhone4S£¨A5оƬ£©µ½iPhone8¡¢iPhoneX£¨A11оƬ£©µÄËùÓÐÆ»¹ûÊÖ»ú¼°Í¬¿îAϵÁд¦Öóͷ£Æ÷µÄiPad¡¢iPod touchµÈiOS×°±¸ÓÀÊÀÔ½Óü ¡£ ¡£¡£¡£Ã»ÓÐÌáµ½×îеÄA12ºÍA13ÊÇ·ñÊܵ½Ó°Ïì ¡£ ¡£¡£¡£¸Ã¹¥»÷ʹÓÃÁËbootromÎó²î£¬£¬ £¬£¬ £¬¼´´æ´¢ÁËiPhoneÆô¶¯Ö¸ÁîµÄÖ»¶Á´æ´¢Æ÷£¨ROM£©Îó²î£¬£¬ £¬£¬ £¬ÓÉÓڸò¿·ÖÄÚ´æÊÇÖ»¶ÁµÄ£¬£¬ £¬£¬ £¬Òò´ËÎÞ·¨Í¨¹ýÇå¾²¸üÐÂÀ´ÐÞ¸´Îó²î ¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼ÁËÏà¹ØÎó²îʹÓ㬣¬ £¬£¬ £¬µ«ÉÐÎÞ¹ûÕæ¿ÉÓõÄÔ½Óü³ÌÐò ¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/ios-exploit-checkm8-could-allow-permanent-iphone-jailbreaks/148762/