Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©£»TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î

Ðû²¼Ê±¼ä 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190619



1¡¢Firefox½ôÆÈÐÞ¸´RCE 0day£¨CVE-2019-11707£©

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
MozillaÐû²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬ÓÃÓÚ½ôÆÈÐÞ¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¸ÃÎó²îÓÉGoogle Project ZeroÍŶӷ¢Ã÷²¢±¨¸æ£¬ÊÇÒ»¸öÀàÐÍ»ìÏýÎó²î£¬Îó²î±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬²Ù×÷JavaScript¹¤¾ßʱ¿ÉÄܻᴥ·¢Îó²î£¬µ¼Ö¿ÉʹÓõÄÍ߽⡣¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓ㬽¨ÒéÓû§¾¡¿ì¸üС£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCEÎó²î£¬Ó°Ïì¶à¸öÐͺÅ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
IBM X-ForceÑо¿Ô±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¸ÃÎó²îÓ°ÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2£¬buildΪ20180213¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐУ¬ÔÚ·¢ËÍ×°±¸Ê¹ÓúÍÔËÐÐshellÏÂÁîµÄÇëÇóʱ£¬¿Éͨ¹ý¸Ä¶¯HTTPÍ·ÖеÄuser agent×ֶδ¥·¢Îó²î£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÐʱ»úÐ®ÖÆ×°±¸²¢»ñµÃÍêÈ«¿ØÖÆÈ¨¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day£¬PoCÒÑÐû²¼

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Plugin VulnerabilitiesÑо¿Ö°Ô±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ»®·ÖÊÇMessenger Customer ChatºÍFacebook for WooCommerce£¬ÆäÖÐǰÕßÔÚÁè¼Ý2Íò¸öÕ¾µãÉÏ×°Ö㬺óÕßµÄ×°ÖÃÁ¿Áè¼Ý20Íò´Î¡£Îó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÉèÖÃÑ¡ÏÑо¿Ö°Ô±ÒѾ­Ðû²¼ÁËÏà¹ØÏ¸½ÚºÍPoC´úÂë¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâÍâй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
SafetyDetectiveÑо¿Ö°Ô±·¢Ã÷Ò»¸öÎÞ±£»¤µÄÊý¾Ý¿âй¶´ó×Ú¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton£¬Êý¾Ý¿âÖÐ̻¶ÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¼ÒµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄСÎÒ˽¼ÒÐÅÏ¢£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢Ä¿½ñ¹ÍÖ÷¡¢ÈËΪԤÆÚ¡¢ÇóÖú״̬µÈ¡£¸ÃÊý¾Ý¿â»¹°üÀ¨Áè¼Ý5Íò¸ö¼ÓÃÜÃÜÂë¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä̻¶£¬ÔÚ½Óµ½±¨¸æºó£¬ÍйܷþÎñÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾ÒâÍâй¶15Íò·ÝΣÏÕË÷Åâ¼Í¼

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Çå¾²Ñо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷¹ã¸æ¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝΣÏÕË÷Åâ¼Í¼¡£¸Ã¹«Ë¾×ÊÖú״ʦÊÂÎñËùÓëÊܺ¦ÕßÇ©ÊðЭÒ飬Êý¾Ý¿âй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëÒÔ¼°Ê¹ʡ¢Î£ÏÕ»ò¼²²¡ÇéÐεÄÚ¹ÊÍ£¬»¹°üÀ¨Ð¡ÎÒ˽¼Ò¿µ½¡ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢ÖÎÁÆÏ¸½ÚµÈ¡£¸ÃÊý¾Ý¿â»¹°üÀ¨300¶à¼Ò״ʦÊÂÎñËùÏò¹ã¸æ¹«Ë¾Ö§¸¶µÄÏêϸÓöÈÇåµ¥¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý600ÍòÌõÓû§¼Í¼±»ÇÔ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
ʳÎï¶©¹º·þÎñ¹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬¿Í»§¼°ÏàÖúͬ°éµÄÏêϸÐÅÏ¢±»ÇÔ¡£Æ¾Ö¤EatStreetµÄ±íÊö£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÖÆäÅÌËã»úÍøÂç²¢»á¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ»á¼û¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢°üÀ¨¶©¹ºÊ³ÎïµÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õ·þÎñµÄÐÅÏ¢£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÒøÐÐÕË»§µÈ£¬Óû§µÄÐÅÓÿ¨Ö§¸¶ÏêϸÐÅÏ¢Ò²Ôâй¶¡£¸Ã¹«Ë¾²¢Î´Í¸Â¶Óм¸¶àÓû§Êܵ½Ó°Ï죬µ«ºÚ¿ÍÉù³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/