Python¿âÇÔÈ¡SSHºÍGPGÃÜÔ¿ £»£»£»£» £»£»£»£»AvastºÍAVG²å¼þ¼àÊÓChromeºÍFirefoxÓû§ £»£»£»£» £»£»£»£»ÉúÎïʶ±ðÊý¾ÝÍþв±¨¸æ

Ðû²¼Ê±¼ä 2019-12-05

1.GoAhead WebЧÀÍÆ÷RCEÎó²îÓ°Ïì´ó×ÚIoT×°±¸


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆTalosµÄÇ徲ר¼ÒÔÚGoAheadǶÈëʽWebЧÀÍÆ÷Öз¢Ã÷ÁËÁ½¸öÎó²î £¬£¬ £¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öÒªº¦µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-5096£©¡£¡£¡£¡£¸ÃÎó²îÓëGoAhead´¦Öóͷ£multi-part/form-dataÇëÇóµÄ·½·¨ÓÐ¹Ø £¬£¬ £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓøÃÎó²î´¥·¢use-after-free £¬£¬ £¬£¬£¬£¬£¬²¢Í¨¹ý·¢ËͶñÒâHTTPÇëÇóÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2019-5097£©±£´æÓÚͳһ×é¼þÖÐ £¬£¬ £¬£¬£¬£¬£¬¿Éµ¼Ö¾ܾøÐ§À͹¥»÷¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨v5.0.1¡¢v.4.1.1ºÍv3.6.5¡£¡£¡£¡£Æ¾Ö¤ShodanµÄËÑË÷Ч¹û £¬£¬ £¬£¬£¬£¬£¬Ì»Â¶ÔÚ¹«ÍøÉϵÄGoAheadЧÀÍÆ÷ÊýÄ¿ÒÑÁè¼Ý130Íò¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/12/goahead-web-server-hacking.html


2.˼¿ÆTalosÅû¶Accusoft ImageGear¿âÖеÄRCEÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆTalos·¢Ã÷AccusoftµÄÎĵµºÍͼƬ´¦Öóͷ£¿âImageGear±£´æ¶à¸öRCEÎó²î¡£¡£¡£¡£µÚÒ»¸öÎó²î£¨CVE-2019-5083£©Óëigcore19d.dllÖеÄTIF_decode_thunderscanº¯ÊýÓÐ¹Ø £¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»¸öÔ½½çдÈëÎÊÌâ £¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓöñÒâTIFFÎļþ´¥·¢Ô¶³Ì´úÂëÖ´ÐС£¡£¡£¡£µÚ¶þ¸öÎó²î£¨CVE-2019-5076£©Ó°ÏìÁËPNG±êÍ·ÆÊÎöÆ÷ £¬£¬ £¬£¬£¬£¬£¬µÚÈý¸öÎó²î£¨CVE-2019-5132£©ÊÇGEM RasterÆÊÎöÆ÷ÖеÄÔ½½çдÎó²î £¬£¬ £¬£¬£¬£¬£¬µÚËĸöÎó²î£¨CVE-2019-5133£©ÓëBMPÆÊÎöÆ÷ÓйØ¡£¡£¡£¡£ÎªÁËʹÓÃÕâЩÎó²î £¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÐèÒªÓÕʹÓû§·­¿ª¶ñÒâÎĵµ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾°üÀ¨Accusoft ImageGear 19.3.0 £¬£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѾ­Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/code-execution-vulnerabilities-patched-accusoft-imagegear


3.Á½¸ö¶ñÒâPython¿â±»·¢Ã÷ÇÔÈ¡SSHºÍGPGÃÜÔ¿


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


PythonÇå¾²ÍŶӴÓPyPI£¨PythonÈí¼þ°üË÷Òý£©ÖÐɾ³ýÁËÁ½¸öÇÔÈ¡SSHºÍGPGÃÜÔ¿µÄ¶ñÒâPython¿â¡£¡£¡£¡£ÕâÁ½¸ö¿âÊÇÓÉͳһλ¿ª·¢Ö°Ô±½¨ÉèµÄ £¬£¬ £¬£¬£¬£¬£¬µÚÒ»¸öÊÇpython3-dateutil £¬£¬ £¬£¬£¬£¬£¬Ä£ÄâÁËÊ¢ÐеÄdateutil¿â £¬£¬ £¬£¬£¬£¬£¬µÚ¶þ¸ö¿âÊÇjeIlyfish¿â £¬£¬ £¬£¬£¬£¬£¬Ä£ÄâÁËjellyfish¿â¡£¡£¡£¡£ËäÈ»python3-dateutilÊÇÔÚÁ½Ììǰ½¨Éè²¢ÉÏ´«µ½PyPIÉ쵀 £¬£¬ £¬£¬£¬£¬£¬µ«jeIlyfish¿âÔò±£´æÁË¿ìÒªÒ»ÄêµÄʱ¼ä¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ·¢Ã÷ £¬£¬ £¬£¬£¬£¬£¬¶ñÒâ´úÂë½ö±£´æÓÚjeIlyfish¿âÖÐ £¬£¬ £¬£¬£¬£¬£¬python3-dateutilÈí¼þ°üÖе¼ÈëÁËjeIlyfish¿â¡£¡£¡£¡£¸Ã¶ñÒâ´úÂëÊÔͼ´ÓÓû§ÅÌËã»úÖÐÇÔÈ¡SSHºÍGPGÃÜÔ¿ £¬£¬ £¬£¬£¬£¬£¬²¢½«ËüÃÇ·¢Ë͵½ÒÔÏÂIPµØµã£ºhttp://68.183.212.246:32258¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/two-malicious-python-libraries-removed-from-pypi/


4.AvastºÍAVG²å¼þ±»·¢Ã÷¼àÊÓChromeºÍFirefoxÓû§


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±Wladimir Palant·¢Ã÷AvastºÍAVGµÄËĸöä¯ÀÀÆ÷²å¼þ±£´æ¸ú×ÙChromeºÍFirefoxÓû§µÄÐÐΪ £¬£¬ £¬£¬£¬£¬£¬²¢ÏòMozillaºÍ¹È¸è±¨¸æÁ˸÷¢Ã÷ £¬£¬ £¬£¬£¬£¬£¬MozillaÒѾ­ÔÝʱɾ³ýÁËÕâЩ²å¼þ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²å¼þ°üÀ¨Avast Online Security¡¢AVG Online Security¡¢Avast SafePriceºÍAVG SafePrice £¬£¬ £¬£¬£¬£¬£¬ÕâЩ²å¼þÖ¼ÔÚµ±Óû§»á¼û¶ñÒâÍøÕ¾»ò´¹ÂÚÍøÕ¾Ê±ÏòÓû§·¢³öÖÒÑÔ £¬£¬ £¬£¬£¬£¬£¬SafePrice²å¼þ¿É×ÊÖú¹ºÎïÕß¾ÙÐбȼÛ¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩ²å¼þÍøÂç´ó×ÚÓйØÓû§ä¯ÀÀϰ¹ßµÄÊý¾Ý·¢Ë͵½¹«Ë¾µÄЧÀÍÆ÷ £¬£¬ £¬£¬£¬£¬£¬°üÀ¨URL¡¢UID¡¢Ò³ÃæÎÊÌâ¡¢ÈªÔ´ÍøÖ·¡¢ÔõÑù»á¼û¸ÃÒ³Ãæ£¨ÀýÈçÖ±½ÓÊäÈëµØµã»òʹÓÃÊéÇ©»òµã»÷Á´½Ó£©¡¢¹ú¼Ò´úÂë¡¢ä¯ÀÀÆ÷Ãû³Æ¼°°æ±¾ºÅ¡¢²Ù×÷ϵͳ¼°°æ±¾ºÅµÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/12/avast-and-avg-browser-plugins.html


5.¿¨°Í˹»ùÐû²¼Õë¶ÔÉúÎïʶ±ðÊý¾ÝµÄÍþвÇ÷ÊÆ±¨¸æ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÑо¿Ö°Ô±·¢Ã÷ £¬£¬ £¬£¬£¬£¬£¬ÔÚµÚÈý¼¾¶ÈÓÃÓÚÍøÂç¡¢´¦Öóͷ£ºÍ´æ´¢ÉúÎïʶ±ðÊý¾ÝµÄÅÌËã»úÖÐÓÐÈý·ÖÖ®Ò»£¨37£¥£©Ôâµ½¶ñÒâÈí¼þ¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬ËùÉæ¼°µÄ¶ñÒâÈí¼þ°üÀ¨Ìع¤Èí¼þºÍÔ¶¿ØÄ¾Âí£¨5.4%£©¡¢´¹ÂÚ¹¥»÷ÖÐʹÓõĶñÒâÈí¼þ-Ö÷ÒªÊÇÌØ¹¤Èí¼þDownloaderºÍDropper£¨5.1%£©¡¢ÀÕË÷Èí¼þ£¨1.9£¥£©ºÍÒøÐÐľÂí£¨1.5£¥£©¡£¡£¡£¡£ÔÚÍþвȪԴ·½Ãæ £¬£¬ £¬£¬£¬£¬£¬»¥ÁªÍø£¨14.4£¥£©ÊÇÉúÎïʶ±ðÊý¾Ý´¦Öóͷ£ÏµÍ³µÄÖ÷ÒªÍþвԴ £¬£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇ¿ÉÒÆ¶¯Ã½Ì壨8£¥£©ºÍÍøÂç¹²ÏíÎļþ¼Ð£¨6.1£¥£©¡£¡£¡£¡£Ëæ×ÅÉúÎïʶ±ðÈÏÖ¤ÊÖÒÕÔ½À´Ô½¶àµØ±»ÓÃÓÚÕþ¸®ºÍÉÌÒµ°ì¹«ÊÒ¡¢¹¤Òµ×Ô¶¯»¯ÏµÍ³¡¢¹«Ë¾ºÍСÎÒ˽¼ÒÌõ¼Ç±¾µçÄÔÒÔ¼°ÊÖ»úµÈ £¬£¬ £¬£¬£¬£¬£¬ÉúÎïʶ±ðÊý¾ÝµÄÇå¾²ÏÖ×´ÐèÒªÒýÆðÐÐÒµºÍÕþ¸®î¿Ïµ»ú¹¹¡¢Çå¾²ÉçÇø¼°¹«ÖÚµÄ×¢ÖØ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/biometric-data-processing-and-storage-system-threats/95364/


6.Ó¢¹úÔ˶¯ÁãÊÛÉÌSweaty BettyÔâµ½Magecart¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ó¢¹úÔ˶¯ÁãÊÛÉÌSweaty BettyµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶ÐÅÏ¢¿ÉÄܱ»ÇÔ¡£¡£¡£¡£´ËÀ๥»÷±»Í³³ÆÎªMagecart¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾·¢Ë͸ø¿Í»§µÄ֪ͨÓʼþ £¬£¬ £¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË11ÔÂ19ÈÕÏÂÖç6:24£¨GMT£©µ½11ÔÂ27ÈÕÏÂÖç2:52 PM£¨GMT£©Ê±´úÔÚ¸ÃÍøÕ¾ÉϹºÎïµÄ¿Í»§¡£¡£¡£¡£¿£¿£¿ÉÄܱ»µÁµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢ÃÜÂë¡¢Õ˵¥µØµã¡¢½»¸¶µØµã¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅ¡¢CVVÊý×ÖºÍÓÐÓÃÆÚ¡£¡£¡£¡£Sweaty BettyÖ¸³öʹÓÃPayPal»òApple Pay¾ÙÐйºÎïµÄ¿Í»§²»ÊÜÓ°Ïì¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-retailer-sweaty-betty-hacked-to-steal-customer-payment-info/