ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2019-01-02
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î£»£»£»£»IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î£»£»£»£»Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î£»£»£»£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î£»£»£»£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ £¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬ £¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ;Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬£¬£¬£¬ £¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬ £¬Ï¼Ü3469¿îAPP¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î

Adobe AcrobatºÍReader´¦Öóͷ£TIFFͼÏñ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î

IBM NotesºÍDomino NSDЧÀÍ´¦Öóͷ£IPC±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÏÂÁîÐУ¬£¬£¬£¬£¬ £¬ÌáÉýȨÏÞ¡£¡£¡£¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î

Discuz! DiscuzXÆôÓÃWeChatʱ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÏòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬ £¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬ £¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬ £¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬ £¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬ £¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬ £¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬ £¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬£¬£¬£¬£¬ £¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£¡£¡£Æ¾Ö¤ÕâЩÎļþ£¬£¬£¬£¬£¬ £¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£¡£¡£¡£ÀýÈç2018Äê8Ô£¬£¬£¬£¬£¬ £¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇ󣬣¬£¬£¬£¬ £¬ÆäÖаüÀ¨94¼þÌØ¹¤×°±¸£¬£¬£¬£¬£¬ £¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾



IBM X-ForceÐû²¼¹ØÓÚ2019ÄêÍøÂç·¸·¨ÍþвÃûÌõÄÕ¹Íû±¨¸æ£¬£¬£¬£¬£¬ £¬±¨¸æ³Æ2019ÄêÆóÒµ½«ïÔ̭ʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»£»£»£»GDPR½«¶ÔÍþвÇ鱨¡¢ÍøÂçÇå¾²´øÀ´¸üÆÕ±éµÄÓ°Ï죻£»£»£»¹¥»÷Õß½«¸ü¶àµØÊ¹ÓÃÃæÏò¹«ÖÚµÄ×ÔÖúЧÀÍÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£»£»£»£»ÍøÂçÇå¾²°ü¹ÜЧÀÍÉ̽«¸ü¶àµØÓëÇå¾²¹©Ó¦É̾ÙÐÐÏàÖú£»£»£»£»·¸·¨·Ö×Ó½«¸ü¶àµØÕë¶ÔÂÃÓΡ¢ÂùÝÒµµÄÊý¾Ý£»£»£»£»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓйØ£¬£¬£¬£¬£¬ £¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£»£»£»£»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÊ¹ÓÃPowerShellÒÔÎÞÎļþµÄÐÎʽ¾ÙÐС£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬£¬£¬£¬ £¬EXPÒÑÐû²¼

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸öÇå¾²Îó²î£¨CVE-2018-8581£©µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÈκξ­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉÏµÄÆäËüÓû§£¬£¬£¬£¬£¬ £¬¿ÉÓÃÓÚ´¹Âڻ¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓøÃÎó²îÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬£¬£¬£¬£¬ £¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬£¬£¬£¬ £¬Æäexp¾ç±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸ÃÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬ £¬Ï¼Ü3469¿îAPP

¿­Ðý¹ú¼ÊÓÎÏ·(Öйú)¹Ù·½ÍøÕ¾



½üÆÚ£¬£¬£¬£¬£¬ £¬¹ú¼ÒÍøÐŰì»áͬÓйز¿·ÖÕë¶ÔÍøÃñ·´Ó¦Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦ÓóÌÐò£¨APP£©ÂÒÏ󣬣¬£¬£¬£¬ £¬¼¯ÖпªÕ¹ÕûÀíÕûÖÎרÏîÐж¯£¬£¬£¬£¬£¬ £¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄÁȼš±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆ­Õ©Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¡£¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬ £¬ÏÖÔÚÔÚº£ÄÚÓ¦ÓÃÊÐËÁÉϼܵÄAPPÒѾ­Áè¼Ý480Íò¿î£¬£¬£¬£¬£¬ £¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£¡£¿ËÈÕ£¬£¬£¬£¬£¬ £¬¹ú¼ÒÍøÐŰìÕûÌåԼ̸28¼ÒÓ¦ÓÃÊÐËÁ¡¢É罻ƽ̨ºÍÔÆÐ§ÀÍÆóÒµ£¬£¬£¬£¬£¬ £¬¶ÔÆäÍÆÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³öÖÒÑÔ£¬£¬£¬£¬£¬ £¬ÒªÇóÁ¬Ã¦¶Ô¸÷×ÔÆ½Ì¨¾ÙÐÐÖÜÈ«ÅŲ飬£¬£¬£¬£¬ £¬ÈÏÕæ¿ªÕ¹×Ô²é×Ô¾À£¬£¬£¬£¬£¬ £¬Æð¾¢×Ô¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬ £¬ÕûÀíÓ¦ÓÃÊÐËÁ£¬£¬£¬£¬£¬ £¬ÆÁÕ϶ñÒâÁ´½Ó£¬£¬£¬£¬£¬ £¬Çå²é½ÓÈëЧÀÍ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉùÃ÷£º±¾×ÊѶÓÉ¿­Ðý¹ú¼ÊÓÎϷάËûÃüÇ徲С×é·­ÒëºÍÕûÀí