Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£» £»£»£»£»TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î

Ðû²¼Ê±¼ä 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190619



1¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£ ¡£¡£¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î£¬£¬£¬£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣ ¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬣¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î£¬£¬£¬£¬Ó°Ïì¶à¸öÐͺÅ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
IBM X-ForceÑо¿Ô±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2£¬£¬£¬£¬buildΪ20180213¡£ ¡£¡£¡£¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐУ¬£¬£¬£¬ÔÚ·¢ËÍ×°±¸Ê¹ÓúÍÔËÐÐshellÏÂÁîµÄÇëÇóʱ£¬£¬£¬£¬¿Éͨ¹ý¸Ä¶¯HTTPÍ·ÖеÄuser agent×ֶδ¥·¢Îó²î£¬£¬£¬£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÐʱ»úÐ®ÖÆ×°±¸²¢»ñµÃÍêÈ«¿ØÖÆÈ¨¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day£¬£¬£¬£¬PoCÒÑÐû²¼

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Plugin VulnerabilitiesÑо¿Ö°Ô±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£ ¡£¡£¡£¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ»®·ÖÊÇMessenger Customer ChatºÍFacebook for WooCommerce£¬£¬£¬£¬ÆäÖÐǰÕßÔÚÁè¼Ý2Íò¸öÕ¾µãÉÏ×°Ö㬣¬£¬£¬ºóÕßµÄ×°ÖÃÁ¿Áè¼Ý20Íò´Î¡£ ¡£¡£¡£¡£Îó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÉèÖÃÑ¡Ï£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­Ðû²¼ÁËÏà¹ØÏ¸½ÚºÍPoC´úÂë¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâÍâй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
SafetyDetectiveÑо¿Ö°Ô±·¢Ã÷Ò»¸öÎÞ±£» £»£»£»£»¤µÄÊý¾Ý¿âй¶´ó×Ú¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£ ¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton£¬£¬£¬£¬Êý¾Ý¿âÖÐ̻¶ÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¼ÒµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢Ä¿½ñ¹ÍÖ÷¡¢ÈËΪԤÆÚ¡¢ÇóÖú״̬µÈ¡£ ¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨Áè¼Ý5Íò¸ö¼ÓÃÜÃÜÂë¡£ ¡£¡£¡£¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä̻¶£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó£¬£¬£¬£¬ÍйÜЧÀÍÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾ÒâÍâй¶15Íò·ÝΣÏÕË÷Åâ¼Í¼

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Çå¾²Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷¹ã¸æ¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£» £»£»£»£»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝΣÏÕË÷Åâ¼Í¼¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾×ÊÖú״ʦÊÂÎñËùÓëÊܺ¦ÕßÇ©ÊðЭÒ飬£¬£¬£¬Êý¾Ý¿âй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÒÔ¼°Ê¹ʡ¢Î£ÏÕ»ò¼²²¡ÇéÐεÄÚ¹ÊÍ£¬£¬£¬£¬»¹°üÀ¨Ð¡ÎÒ˽¼Ò¿µ½¡ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢ÖÎÁÆÏ¸½ÚµÈ¡£ ¡£¡£¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨300¶à¼Ò״ʦÊÂÎñËùÏò¹ã¸æ¹«Ë¾Ö§¸¶µÄÏêϸÓöÈÇåµ¥¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Áè¼Ý600ÍòÌõÓû§¼Í¼±»ÇÔ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
ʳÎï¶©¹ºÐ§À͹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éµÄÏêϸÐÅÏ¢±»ÇÔ¡£ ¡£¡£¡£¡£Æ¾Ö¤EatStreetµÄ±íÊö£¬£¬£¬£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÖÆäÅÌËã»úÍøÂç²¢»á¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ»á¼û¡£ ¡£¡£¡£¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢°üÀ¨¶©¹ºÊ³ÎïµÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õЧÀ͵ÄÐÅÏ¢£¬£¬£¬£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÒøÐÐÕË»§µÈ£¬£¬£¬£¬Óû§µÄÐÅÓÿ¨Ö§¸¶ÏêϸÐÅÏ¢Ò²Ôâй¶¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶Óм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬µ«ºÚ¿ÍÉù³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/