ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2019-01-02
±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç³ö©¶´£»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý©¶´£»Discuz! DiscuzX CVE-2018-20422Äþ¾²ÏÞÖÆÈƹý©¶´£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÃüÁî×¢È멶´£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÊ¥µØÑǸçѧÇøÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸×ïÍþвǰ¾°µÄÔ¤²â³ÂËß;Exchange ServerºáÏòÉø͸ºÍÌáȨ£¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1. Adobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç³ö©¶´

Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý©¶´

IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÃüÁîÐУ¬ÌáÉýȨÏÞ¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422Äþ¾²ÏÞÖÆÈƹý©¶´

Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬Î´ÊÚȨ·ÃÎÊ¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÃüÁî×¢È멶´

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³ö©¶´

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ê¥µØÑǸçѧÇøÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçѧÇø£¨SDUSD£©Ôâµ½ÍøÂçµöÓã¹¥»÷£¬¹¥»÷Õßͨ¹ýÊÕ¼¯µ½µÄÊÂÇéÈËԱƾ¾Ý·ÃÎÊÁ˸ÃѧÇøµÄÍøÂç·þÎñ£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ·ÃÎÊÁ¬ÐøÁ˽«½üÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬°üÂÞѧÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ô¼±ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿Áè¼Ý1.6Íò·Ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£Æ¾¾ÝÕâЩÎļþ£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖüäµýÉ豸¡£ÀýÈç2018Äê8Ô£¬ÃÀ¹úפÈø¶ûÍ߶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇó£¬ÆäÖаüÂÞ94¼þ¼äµýÉ豸£¬°üÂÞÄÜ°²×°ÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÈÕ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ±ÎÎÞÏßµçÉ豸µÈ¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸×ïÍþвǰ¾°µÄÔ¤²â³ÂËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



IBM X-ForceÐû²¼¹ØÓÚ2019ÄêÍøÂç·¸×ïÍþв¸ñʽµÄÔ¤²â³ÂËߣ¬³ÂËß³Æ2019ÄêÆóÒµ½«¼õÉÙʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»GDPR½«¶ÔÍþвÇ鱨¡¢ÍøÂçÄþ¾²´øÀ´¸ü¹ã·ºµÄÓ°Ï죻¹¥»÷Õß½«¸ü¶àµØÀûÓÃÃæÏò¹«ÖÚµÄ×ÔÖú·þÎñϵͳÊÕ¼¯ÓмÛÖµµÄÓû§Êý¾Ý£»ÍøÂçÄþ¾²±£ÏÕ·þÎñÉ̽«¸ü¶àµØÓëÄþ¾²¹©Ó¦É̽øÐкÏ×÷£»·¸×ï·Ö×Ó½«¸ü¶àµØÕë¶ÔÂÃÓΡ¢¾ÆµêÒµµÄÊý¾Ý£»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓйØ£¬2019Ä꽫»áÅû¶һЩʼþ»ò»î¶¯£»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÀûÓÃPowerShellÒÔÎÞÎļþµÄÐÎʽ½øÐС£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉø͸ºÍÌáȨ£¬EXPÒÑÐû²¼

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸öÄþ¾²Â©¶´£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¸Ã©¶´ÔÊÐíÈκξ­¹ýÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉϵÄÆäËüÓû§£¬¿ÉÓÃÓÚµöÓã»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¸Ã©¶´ÊÇÒ»¸ö·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©Â©¶´£¬Ñо¿ÈËÔ±ÑÝʾÁËÈçºÎÀûÓø鶴ÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬Æäexp½Å±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã©¶´¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



½üÆÚ£¬¹ú¼ÒÍøÐÅ°ì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦Ó÷¨Ê½£¨APP£©ÂÒÏ󣬼¯ÖпªÕ¹ÇåÀíÕûÖÎרÏîÐж¯£¬ÒÀ·¨¹Øͣϼܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åį¡±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆ­Õ©Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¾Ýͳ¼Æ£¬Ä¿Ç°ÔÚ¹úÄÚÓ¦ÓÃÉ̵êÉϼܵÄAPPÒѾ­Áè¼Ý480Íò¿î£¬º­¸ÇÁËÈËÃñÉú»îµÄ¸÷¸ö·½Ãæ¡£½üÈÕ£¬¹ú¼ÒÍøÐŰ켯ÌåԼ̸28¼ÒÓ¦ÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬¶ÔÆäÂÄÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³ö¾¯¸æ£¬ÒªÇóÁ¢¼´¶Ô¸÷×Ôƽ̨½øÐÐÈ«ÃæÅŲ飬ÈÏÕ濪չ×Ô²é×Ô¾À£¬»ý¼«Ö÷¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬ÇåÀíÓ¦ÓÃÉ̵꣬ÆÁ±Î¶ñÒâÁ´½Ó£¬Çå²é½ÓÈë·þÎñ¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí