Python¿âÇÔÈ¡SSHºÍGPGÃÜÔ¿ £»AvastºÍAVG²å¼þ¼à¶½ChromeºÍFirefoxÓû§ £»ÉúÎï¼ø±ðÊý¾ÝÍþв»ã±¨

°ä²¼¹¦·ò 2019-12-05

1.GoAhead Web·þÎñÆ÷RCE·ì϶ӰÏì´óÁ¿IoTÉ豸


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿ÆTalosµÄ°²È«×¨¼ÒÔÚGoAheadǶÈëʽWeb·þÎñÆ÷Öз¢ÏÖÁËÁ½¸ö·ì϶ £¬ÆäÖÐÔ̺¬Ò»¸ö¹Ø¼üµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-5096£©¡£¸Ã·ì϶ÓëGoAhead´¦ÖÃmulti-part/form-dataÒªÇóµÄ·½Ê½ÓйØ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶´¥·¢use-after-free £¬²¢Í¨¹ý·¢ËͶñÒâHTTPÒªÇóÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£µÚ¶þ¸ö·ì϶£¨CVE-2019-5097£©´æÔÚÓÚͳһ×é¼þÖÐ £¬¿Éµ¼Ö»ؾø·þÎñ¹¥»÷¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬v5.0.1¡¢v.4.1.1ºÍv3.6.5¡£Æ¾¾ÝShodanµÄËÑË÷Á˾Ö £¬Â¶³öÔÚ¹«ÍøÉϵÄGoAhead·þÎñÆ÷ÊýÁ¿Òѳ¬¹ý130Íò¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/12/goahead-web-server-hacking.html


2.˼¿ÆTalosÅû¶Accusoft ImageGear¿âÖеÄRCE·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿ÆTalos·¢ÏÖAccusoftµÄÎĵµºÍͼƬ´¦ÖÿâImageGear´æÔÚ¶à¸öRCE·ì϶¡£µÚÒ»¸ö·ì϶£¨CVE-2019-5083£©Óëigcore19d.dllÖеÄTIF_decode_thunderscanº¯ÊýÓйØ £¬ÊÇÒ»¸öÔ½½çдÈëÎÊÌâ £¬¹¥»÷Õß¿ÉÀûÓöñÒâTIFFÎļþ´¥·¢Ô¶³Ì´úÂëÖ´ÐС£µÚ¶þ¸ö·ì϶£¨CVE-2019-5076£©Ó°ÏìÁËPNG±êÍ·½âÎöÆ÷ £¬µÚÈý¸ö·ì϶£¨CVE-2019-5132£©ÊÇGEM Raster½âÎöÆ÷ÖеÄÔ½½çд·ì϶ £¬µÚËĸö·ì϶£¨CVE-2019-5133£©ÓëBMP½âÎöÆ÷ÓйØ¡£ÎªÁËÀûÓÃÕâЩ·ì϶ £¬¹¥»÷Õß±ØÒªÓÕʹÓû§´ò¿ª¶ñÒâÎĵµ¡£ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬Accusoft ImageGear 19.3.0 £¬¸Ã¹«Ë¾ÒѾ­°ä²¼ÁËÓйؽ¨¸´²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/code-execution-vulnerabilities-patched-accusoft-imagegear


3.Á½¸ö¶ñÒâPython¿â±»·¢ÏÖÇÔÈ¡SSHºÍGPGÃÜÔ¿


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Python°²È«ÍŶӴÓPyPI£¨PythonÈí¼þ°üË÷Òý£©ÖÐɾ³ýÁËÁ½¸öÇÔÈ¡SSHºÍGPGÃÜÔ¿µÄ¶ñÒâPython¿â¡£ÕâÁ½¸ö¿âÊÇÓÉͳһλ¿ª·¢ÈËÔ±´´½¨µÄ £¬µÚÒ»¸öÊÇpython3-dateutil £¬·ÂÕÕÁËÊ¢ÐеÄdateutil¿â £¬µÚ¶þ¸ö¿âÊÇjeIlyfish¿â £¬·ÂÕÕÁËjellyfish¿â¡£¹ÌÈ»python3-dateutilÊÇÔÚÁ½Ììǰ´´½¨²¢ÉÏ´«µ½PyPIÉϵÄ £¬µ«jeIlyfish¿âÔò´æÔÚÁ˽«½üÒ»ÄêµÄ¹¦·ò¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ·¢ÏÖ £¬¶ñÒâ´úÂë½ö´æÔÚÓÚjeIlyfish¿âÖÐ £¬python3-dateutilÈí¼þ°üÖе¼ÈëÁËjeIlyfish¿â¡£¸Ã¶ñÒâ´úÂëÊÔͼ´ÓÓû§ÍÆËã»úÖÐÇÔÈ¡SSHºÍGPGÃÜÔ¿ £¬²¢½«ËüÃÇ·¢Ë͵½ÒÔÏÂIPµØÖ·£ºhttp://68.183.212.246:32258¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/two-malicious-python-libraries-removed-from-pypi/


4.AvastºÍAVG²å¼þ±»·¢ÏּලChromeºÍFirefoxÓû§


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÈËÔ±Wladimir Palant·¢ÏÖAvastºÍAVGµÄËĸöä¯ÀÀÆ÷²å¼þ´æÔÚ¸ú×ÙChromeºÍFirefoxÓû§µÄÐÐΪ £¬²¢ÏòMozillaºÍ¹È¸è»ã±¨Á˸÷¢ÏÖ £¬MozillaÒѾ­Ò»Ê±É¾³ýÁËÕâЩ²å¼þ¡£ÊÜÓ°ÏìµÄ²å¼þÔ̺¬Avast Online Security¡¢AVG Online Security¡¢Avast SafePriceºÍAVG SafePrice £¬ÕâЩ²å¼þÖ¼ÔÚµ±Óû§½Ó¼û¶ñÒâÍøÕ¾»ò´¹µöÍøÕ¾Ê±ÏòÓû§·¢³öÖÒ¸æ £¬SafePrice²å¼þ¿ÉÔ®ÊÖ¹ºÎïÕß½øÐбȼÛ¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ²å¼þÍøÂç´óÁ¿ÓйØÓû§ä¯ÀÀϰ¹ßµÄÊý¾Ý·¢Ë͵½¹«Ë¾µÄ·þÎñÆ÷ £¬Ô̺¬URL¡¢UID¡¢Ò³Ãæ±êÌâ¡¢ÆðÔ´ÍøÖ·¡¢ÈôºÎ½Ó¼û¸ÃÒ³Ãæ£¨ÀýÈçÖ±½ÓÊäÈëµØÖ·»òʹÓÃÊéÇ©»òµã»÷Á´½Ó£©¡¢¹ú¶È´úÂë¡¢ä¯ÀÀÆ÷Ãû³Æ¼°°æ±¾ºÅ¡¢²Ù×÷ϵͳ¼°°æ±¾ºÅµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/12/avast-and-avg-browser-plugins.html


5.¿¨°Í˹»ù°ä²¼Õë¶ÔÉúÎï¼ø±ðÊý¾ÝµÄÍþвÇ÷Ïò»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¿¨°Í˹»ù×êÑÐÈËÔ±·¢ÏÖ £¬ÔÚµÚÈý¼¾¶Å×ÃÓÚÍøÂç¡¢´¦Öúʹ洢ÉúÎï¼ø±ðÊý¾ÝµÄÍÆËã»úÖÐÓÐÈý·ÖÖ®Ò»£¨37£¥£©Ôâµ½¶ñÒâÈí¼þ¹¥»÷ £¬ËùÉæ¼°µÄ¶ñÒâÈí¼þÔ̺¬¼äµýÈí¼þºÍÔ¶¿ØÄ¾Âí£¨5.4%£©¡¢´¹µö¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ-ÖØÒªÊǼäµýÈí¼þDownloaderºÍDropper£¨5.1%£©¡¢ÀÕË÷Èí¼þ£¨1.9£¥£©ºÍÒøÐÐľÂí£¨1.5£¥£©¡£ÔÚÍþвÆðÔ´·½Ãæ £¬»¥ÁªÍø£¨14.4£¥£©ÊÇÉúÎï¼ø±ðÊý¾Ý´¦ÖÃϵͳµÄÖØÒªÍþвԴ £¬Æä´ÎÊÇ¿ÉÒÆ¶¯Ã½Ì壨8£¥£©ºÍÍøÂç¹²ÏíÎļþ¼Ð£¨6.1£¥£©¡£Ëæ×ÅÉúÎï¼ø±ðÈÏÖ¤¼¼ÊõÔ½À´Ô½¶àµØ±»ÓÃÓÚµ±¾ÖºÍóÒװ칫ÊÒ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³¡¢¹«Ë¾ºÍÓ×ÎұʼDZ¾µçÄÔÒÔ¼°ÊÖ»úµÈ £¬ÉúÎï¼ø±ðÊý¾ÝµÄ°²È«½ü¿ö±ØÒªÒýÆðÐÐÒµºÍµ±¾ÐÄà¹Ü»ú¹¹¡¢°²È«ÉçÇø¼°¹«¼ÒÈ·°ÑÎÈ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/biometric-data-processing-and-storage-system-threats/95364/


6.Ó¢¹ú»î¶¯ÁãÊÛÉÌSweaty BettyÔâµ½Magecart¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¢¹ú»î¶¯ÁãÊÛÉÌSweaty BettyµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ £¬¿Í»§µÄÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£´ËÀ๥»÷±»Í³³ÆÎªMagecart¹¥»÷ £¬Æ¾¾Ý¸Ã¹«Ë¾·¢Ë͸ø¿Í»§µÄ֪ͨÓʼþ £¬¸ÃÊÂÎñÓ°ÏìÁË11ÔÂ19ÈÕÏÂÎç6:24£¨GMT£©µ½11ÔÂ27ÈÕÏÂÎç2:52 PM£¨GMT£©ÆÚ¼äÔÚ¸ÃÍøÕ¾ÉϹºÎïµÄ¿Í»§¡£¿ÉÄܱ»µÁµÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØÖ·¡¢½»¸¶µØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨/½è¼Ç¿¨ºÅ¡¢CVVÊý×ÖºÍÓÐЧÆÚ¡£Sweaty BettyÖ¸³öʹÓÃPayPal»òApple Pay½øÐйºÎïµÄ¿Í»§²»ÊÜÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-retailer-sweaty-betty-hacked-to-steal-customer-payment-info/