Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»£»£»£»TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î

Ðû²¼Ê±¼ä 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190619



1¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1 £¬£¬£¬£¬£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ £¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î £¬£¬£¬£¬£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌâ £¬£¬£¬£¬£¬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î £¬£¬£¬£¬£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣¡£¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓà £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î £¬£¬£¬£¬£¬Ó°Ïì¶à¸öÐͺÅ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
IBM X-ForceÑо¿Ô±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¸ÃÎó²îÓ°ÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500 £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2 £¬£¬£¬£¬£¬buildΪ20180213¡£¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐÐ £¬£¬£¬£¬£¬ÔÚ·¢ËÍ×°±¸Ê¹ÓúÍÔËÐÐshellÏÂÁîµÄÇëÇóʱ £¬£¬£¬£¬£¬¿Éͨ¹ý¸Ä¶¯HTTPÍ·ÖеÄuser agent×ֶδ¥·¢Îó²î £¬£¬£¬£¬£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÐʱ»úÐ®ÖÆ×°±¸²¢»ñµÃÍêÈ«¿ØÖÆÈ¨¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day £¬£¬£¬£¬£¬PoCÒÑÐû²¼

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
Plugin VulnerabilitiesÑо¿Ö°Ô±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ»®·ÖÊÇMessenger Customer ChatºÍFacebook for WooCommerce £¬£¬£¬£¬£¬ÆäÖÐǰÕßÔÚÁè¼Ý2Íò¸öÕ¾µãÉÏ×°Öà £¬£¬£¬£¬£¬ºóÕßµÄ×°ÖÃÁ¿Áè¼Ý20Íò´Î¡£¡£Îó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÉèÖÃÑ¡Ïî £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­Ðû²¼ÁËÏà¹ØÏ¸½ÚºÍPoC´úÂë¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâÍâй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
SafetyDetectiveÑо¿Ö°Ô±·¢Ã÷Ò»¸öÎÞ±£»£»£»£»¤µÄÊý¾Ý¿âй¶´ó×Ú¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton £¬£¬£¬£¬£¬Êý¾Ý¿âÖÐ̻¶ÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¼ÒµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢Ä¿½ñ¹ÍÖ÷¡¢ÈËΪԤÆÚ¡¢ÇóÖú״̬µÈ¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨Áè¼Ý5Íò¸ö¼ÓÃÜÃÜÂë¡£¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä̻¶ £¬£¬£¬£¬£¬ÔÚ½Óµ½±¨¸æºó £¬£¬£¬£¬£¬ÍйÜЧÀÍÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾ÒâÍâй¶15Íò·ÝΣÏÕË÷Åâ¼Í¼

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
Çå¾²Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷¹ã¸æ¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£»£»£»£»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝΣÏÕË÷Åâ¼Í¼¡£¡£¸Ã¹«Ë¾×ÊÖú״ʦÊÂÎñËùÓëÊܺ¦ÕßÇ©ÊðЭÒé £¬£¬£¬£¬£¬Êý¾Ý¿âй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÒÔ¼°Ê¹ʡ¢Î£ÏÕ»ò¼²²¡ÇéÐεÄÚ¹ÊÍ £¬£¬£¬£¬£¬»¹°üÀ¨Ð¡ÎÒ˽¼Ò¿µ½¡ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢ÖÎÁÆÏ¸½ÚµÈ¡£¡£¸ÃÊý¾Ý¿â»¹°üÀ¨300¶à¼Ò״ʦÊÂÎñËùÏò¹ã¸æ¹«Ë¾Ö§¸¶µÄÏêϸÓöÈÇåµ¥¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬Áè¼Ý600ÍòÌõÓû§¼Í¼±»ÇÔ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø
 
ʳÎï¶©¹ºÐ§À͹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬¿Í»§¼°ÏàÖúͬ°éµÄÏêϸÐÅÏ¢±»ÇÔ¡£¡£Æ¾Ö¤EatStreetµÄ±íÊö £¬£¬£¬£¬£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÖÆäÅÌËã»úÍøÂç²¢»á¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢ £¬£¬£¬£¬£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ»á¼û¡£¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢°üÀ¨¶©¹ºÊ³ÎïµÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õЧÀ͵ÄÐÅÏ¢ £¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÒøÐÐÕË»§µÈ £¬£¬£¬£¬£¬Óû§µÄÐÅÓÿ¨Ö§¸¶ÏêϸÐÅÏ¢Ò²Ôâй¶¡£¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶Óм¸¶àÓû§Êܵ½Ó°Ïì £¬£¬£¬£¬£¬µ«ºÚ¿ÍÉù³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/