ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ38ÖÜ
Ðû²¼Ê±¼ä 2019-09-30±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2019Äê9ÔÂ23ÈÕÖÁ29ÈÕ¹²ÊÕ¼Çå¾²Îó²î43¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRIOT MQTT-SN CVE-2019-16754¿ÕÖ¸Õë¼ä½ÓÒýÓÃÎó²î; vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î£»Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»phpstudyºóÃÅÖ²ÈëÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTescoÍ£³µÓ¦Óñ£´æÎó²îµ¼ÖÂÊýÍòÍò³µÅÆͼÏñй¶£»Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î£»¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷£»iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ£»iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü¡£
Ö÷ÒªÇå¾²Îó²îÁбí
RIOT MQTT-SNʵÏÖ±£´æ¿ÕÖ¸ÕëÒýÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹϵͳÍ߽⡣
https://github.com/RIOT-OS/RIOT/pull/12293
2. vBulletin widgetConfig[code]Ô¶³Ì´úÂëÖ´ÐÐÎó²î
vBulletin ajax/render/widget_php routestring´¦Öóͷ£widgetConfig[code]±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£
https://seclists.org/fulldisclosure/2019/Sep/31
3. Adobe ColdFusioní§Òâ´úÂëÖ´ÐÐÎó²î
Adobe ColdFusionij×é¼þ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èëí§ÒâÏÂÁî²¢Ö´ÐС£
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html
4. Microsoft Internet ExplorerÄڴ湤¾ß´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î
Microsoft Internet Explorer´¦Öóͷ£Äڴ湤¾ß±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://support.microsoft.com/zh-cn/help/4522007/cumulative-security-update-for-internet-explorer
5. phpstudyºóÃÅÖ²ÈëÎó²î
phpstudy±»×¢ÈëºóÃÅ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ØÖÆÄ¿µÄÓ¦ÓÃϵͳ¡£
https://www.xp.cn/
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/
2¡¢Î¢Èí½ôÆÈÐÞ¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoSÎó²î
΢ÈíÐû²¼½ôÆÈÇå¾²¸üУ¬ÐÞ¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoSÎó²î¡£ÆäÖÐIE 0dayΪ¹È¸èÑо¿Ö°Ô±Cl¨¦mentLecigne·¢Ã÷µÄ¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2019-1367£©£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÄ¿½ñÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¸ÃÎó²î¿ÉÒÔͨ¹ý½«Ä¿µÄÓû§Öض¨ÏòÖÁ¶ñÒâÍøÕ¾À´Ê¹Óã¬ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨IE9¡¢10ºÍ11¡£ÁíÒ»¸öÎó²îÊÇWindows DefenderÖеľܾø·þÎñÎó²î£¨CVE-2019-1255£©£¬¸ÃÎó²îÓëDefender´¦Öóͷ£ÎļþµÄ·½·¨Óйأ¬¹¥»÷Õß¿ÉʹÓøÃÎó²î×èÖ¹Õýµ±ÕË»§Ö´ÐÐÕýµ±µÄϵͳÎļþ¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬²¢ÒÑÔÚ1.1.16400.2ÖÐÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/
3¡¢¾Ýͳ¼Æ2019ÄêÃÀ¹úÒÑÓжà´ï500ËùѧУÔâÀÕË÷Èí¼þ¹¥»÷
ƾ֤ÔÆÇå¾²¹«Ë¾ArmorµÄµ÷ÑУ¬ÃÀ¹úÒÑÓÐ49¸öѧÇøµÄ½ÌÓý»ú¹¹Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Ê¹µÃ½ÌÓýÐÐÒµ³ÉΪ½ö´ÎÓڵط½Õþ¸®µÄµÚ¶þ´óÒ×Êܹ¥»÷Ä¿µÄ¡£¸Ã¹«Ë¾ÆÊÎöÁË×Ô2019Äê1ÔÂÒÔÀ´¹ûÕ汨µÀµÄ¹¥»÷£¬·¢Ã÷ÔÚ2019ÄêÇ°9¸öÔÂÒÑÓжà´ï500ËùK-12ѧУÔâµ½¹¥»÷£¬¶øÈ¥ÄêÖ»ÓÐ11ËùѧУ¡£½öÔÚ9ÔÂÖÐÑ®µÄÒ»Öܶàʱ¼äÀï¾ÍÓÐ9¸öÐÂѧÇøºÍ1Ëù´óѧÊܵ½¹¥»÷£¬²¨¼°Ô¼100ËùK-12ѧУ¡£¿µÄùµÒ¸ñÖݵÄѧÇøÊܵ½µÄÍþв×îΪÑÏÖØ£¬¸ÃÖݹ²ÔâÓöÁË7´Î¹¥»÷£¬º¸Ç104ËùѧУ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hundreds-of-us-schools-hit-by/4¡¢iOS 13ºÍiPadOSÎó²î¿Éµ¼ÖµÚÈý·½¼üÅÌ»ñÈ¡ÍêÈ«»á¼ûȨÏÞ
ÔÎÄÁ´½Ó£º
https://threatpost.com/bug-granting-full-access-keyboards/148638/5¡¢iOSÎó²îCheckm8¿Éµ¼ÖÂiPhone4µ½XÓÀÊÀÔ½Óü
Çå¾²Ñо¿Ô±axi0mXÅû¶iOSÖеÄÇå¾²Îó²îcheckm8£¬¸ÃÎó²î¿ÉÒÔʹiPhone4S£¨A5оƬ£©µ½iPhone8¡¢iPhoneX£¨A11оƬ£©µÄËùÓÐÆ»¹ûÊÖ»ú¼°Í¬¿îAϵÁд¦Öóͷ£Æ÷µÄiPad¡¢iPod touchµÈiOS×°±¸ÓÀÊÀÔ½Óü¡£Ã»ÓÐÌáµ½×îеÄA12ºÍA13ÊÇ·ñÊܵ½Ó°Ïì¡£¸Ã¹¥»÷ʹÓÃÁËbootromÎó²î£¬¼´´æ´¢ÁËiPhoneÆô¶¯Ö¸ÁîµÄÖ»¶Á´æ´¢Æ÷£¨ROM£©Îó²î£¬ÓÉÓڸò¿·ÖÄÚ´æÊÇÖ»¶ÁµÄ£¬Òò´ËÎÞ·¨Í¨¹ýÇå¾²¸üÐÂÀ´ÐÞ¸´Îó²î¡£Ñо¿Ö°Ô±ÔÚGithubÉÏÐû²¼ÁËÏà¹ØÎó²îʹÓ㬵«ÉÐÎÞ¹ûÕæ¿ÉÓõÄÔ½Óü³ÌÐò¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ios-exploit-checkm8-could-allow-permanent-iphone-jailbreaks/148762/