ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2019-01-02
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î£»£»£»£»£» £»IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î£»£»£»£»£» £»Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î£»£»£»£»£» £»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î£»£»£»£»£» £»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬ £¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ;Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬ £¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬ £¬Ï¼Ü3469¿îAPP¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î

Adobe AcrobatºÍReader´¦Öóͷ£TIFFͼÏñ±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£» £»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î

IBM NotesºÍDomino NSDЧÀÍ´¦Öóͷ£IPC±£´æÇå¾²Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÏÂÁîÐУ¬£¬ £¬ÌáÉýȨÏÞ¡£¡£¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î

Discuz! DiscuzXÆôÓÃWeChatʱ±£´æÇå¾²Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÏòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇ󣬣¬ £¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬ £¬Î´ÊÚȨ»á¼û¡£¡£¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A±£´æÊäÈëÑéÖ¤Îó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬ £¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»£» £»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬ £¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬ £¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬ £¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬ £¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬ £¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬£¬ £¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£¡£Æ¾Ö¤ÕâЩÎļþ£¬£¬ £¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£¡£¡£ÀýÈç2018Äê8Ô£¬£¬ £¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇ󣬣¬ £¬ÆäÖаüÀ¨94¼þÌØ¹¤×°±¸£¬£¬ £¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



IBM X-ForceÐû²¼¹ØÓÚ2019ÄêÍøÂç·¸·¨ÍþвÃûÌõÄÕ¹Íû±¨¸æ£¬£¬ £¬±¨¸æ³Æ2019ÄêÆóÒµ½«ïÔ̭ʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»£»£»£»£» £»GDPR½«¶ÔÍþвÇ鱨¡¢ÍøÂçÇå¾²´øÀ´¸üÆÕ±éµÄÓ°Ï죻£»£»£»£» £»¹¥»÷Õß½«¸ü¶àµØÊ¹ÓÃÃæÏò¹«ÖÚµÄ×ÔÖúЧÀÍÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£»£»£»£»£» £»ÍøÂçÇå¾²°ü¹ÜЧÀÍÉ̽«¸ü¶àµØÓëÇå¾²¹©Ó¦É̾ÙÐÐÏàÖú£»£»£»£»£» £»·¸·¨·Ö×Ó½«¸ü¶àµØÕë¶ÔÂÃÓΡ¢ÂùÝÒµµÄÊý¾Ý£»£»£»£»£» £»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷Óйأ¬£¬ £¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£»£»£»£»£» £»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÊ¹ÓÃPowerShellÒÔÎÞÎļþµÄÐÎʽ¾ÙÐС£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬ £¬EXPÒÑÐû²¼

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸öÇå¾²Îó²î£¨CVE-2018-8581£©µÄÊÖÒÕϸ½Ú¡£¡£¡£¸ÃÎó²îÔÊÐíÈκξ­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉÏµÄÆäËüÓû§£¬£¬ £¬¿ÉÓÃÓÚ´¹Âڻ¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¡£¡£¸ÃÎó²îÊÇÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î£¬£¬ £¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓøÃÎó²îÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬£¬ £¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬ £¬Æäexp¾ç±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸ÃÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬ £¬Ï¼Ü3469¿îAPP

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



½üÆÚ£¬£¬ £¬¹ú¼ÒÍøÐŰì»áͬÓйز¿·ÖÕë¶ÔÍøÃñ·´Ó¦Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦ÓóÌÐò£¨APP£©ÂÒÏ󣬣¬ £¬¼¯ÖпªÕ¹ÕûÀíÕûÖÎרÏîÐж¯£¬£¬ £¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄÁȼš±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆ­Õ©Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¡£¡£¾Ýͳ¼Æ£¬£¬ £¬ÏÖÔÚÔÚº£ÄÚÓ¦ÓÃÊÐËÁÉϼܵÄAPPÒѾ­Áè¼Ý480Íò¿î£¬£¬ £¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£¿ËÈÕ£¬£¬ £¬¹ú¼ÒÍøÐŰìÕûÌåԼ̸28¼ÒÓ¦ÓÃÊÐËÁ¡¢É罻ƽ̨ºÍÔÆÐ§ÀÍÆóÒµ£¬£¬ £¬¶ÔÆäÍÆÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³öÖÒÑÔ£¬£¬ £¬ÒªÇóÁ¬Ã¦¶Ô¸÷×ÔÆ½Ì¨¾ÙÐÐÖÜÈ«ÅŲ飬£¬ £¬ÈÏÕæ¿ªÕ¹×Ô²é×Ô¾À£¬£¬ £¬Æð¾¢×Ô¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬ £¬ÕûÀíÓ¦ÓÃÊÐËÁ£¬£¬ £¬ÆÁÕ϶ñÒâÁ´½Ó£¬£¬ £¬Çå²é½ÓÈëЧÀÍ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉùÃ÷£º±¾×ÊѶÓÉÍòÀû¹ú¼Ê¹ÙÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí