ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ1ÖÜ

Ðû²¼Ê±¼ä 2019-01-07

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ31ÈÕÖÁ2019Äê1ÔÂ6ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´37¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Acrobat/Reader CVE-2018-16011ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´£»D-Link DIR-818LW/DIR-860L soap.cgi OSÃüÁîÖ´ÐЩ¶´£»Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌÃüÁîÖ´ÐЩ¶´£»Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç³ö©¶´£»Dell EMC RSA Archer·ÃÎÊ¿ØÖÆ´íÎ󩶴¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ°ÄÖÞÊý×Ö½¡¿µÊðÐû²¼2017-2018Äê¶È³ÂËߣ¬Åû¶42ÆðÊý¾Ýй¶Ê¼þ£»ÃÀ¹úÎÀÉú²¿Ðû²¼Ò½ÁÆÐÐÒµÍøÂçÄþ¾²Êµ¼ù³ÂËߣ»Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÄþ¾²·¨£¬ÔÊÐíÕþ¸®·ÃÎÊÓû§Êý¾Ý£»ÃÜÂë¹ÜÀíÆ÷BlurÓû§Êý¾Ýй¶£¬240ÍòÈËÊܵ½Ó°Ï죻°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢ºÍ½â£¬Å⸶38.2ÍòÃÀÔª¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1. Adobe Acrobat/Reader CVE-2018-16011ÊͷźóÀûÓôúÂëÖ´ÐЩ¶´

Adobe Acrobat/Reader´¦ÖÃPDFÎļþ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/73738

2. D-Link DIR-818LW/DIR-860L soap.cgi OSÃüÁîÖ´ÐЩ¶´

D-Link DIR-818LW/DIR-860L soap.cgi´¦ÖÃService²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-20114

3. Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌÃüÁîÖ´ÐЩ¶´
Apache NetBeans Proxy Auto-Configuration (PAC) interpretationʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://lists.apache.org/thread.html/d1c37966a316a326ab4ff4d4bc056322e8adcbe984e8145c0ecda7fa@%3Cdev.netbeans.apache.org%3E

4. Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç³ö©¶´
Guardzilla GZ621W ¡®TK_set_deviceModel_req_handle¡¯º¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐдúÂë¡£
https://labs.bitdefender.com/2018/12/iot-report-major-flaws-in-guardzilla-cameras-allow-remote-hijack-of-the-security-device/

5. Dell EMC RSA Archer·ÃÎÊ¿ØÖÆ´íÎ󩶴
Dell EMC RSA Archer´æÔÚ·ÃÎÊ¿ØÖÆ´íÎ󩶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬¶ÁÈ¡ÊÜÏÞÐÅÏ¢¡£
https://seclists.org/fulldisclosure/2019/Jan/3


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢°ÄÖÞÊý×Ö½¡¿µÊðÐû²¼2017-2018Äê¶È³ÂËߣ¬Åû¶42ÆðÊý¾Ýй¶Ê¼þ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°Ä´óÀûÑÇÊý×Ö½¡¿µÊð£¨ADHA£©ÔÚÆä2017-2018Äê¶È³ÂËßÖÐÌåÏÖ£¬My Health RecordϵͳÖеÄÒ½ÁƼǼÔÚ2017Äê7ÔÂ1ÈÕÖÁ2018Äê6ÔÂ30ÈÕÆڼ乲·¢Éú42ÆðÊý¾Ýй¶Ê¼þ¡£ÆäÖдó¶àÊýй¶Ê¼þÓëÒ½ÁƱ£ÏÕÆÛÕ©ÓйØ£¬My Health Record²¢Î´Ôâµ½Ëðº¦ÆäÍêÕûÐÔºÍÄþ¾²ÐԵĶñÒâ¹¥»÷¡£½ØÖÁ2018Äê7ÔÂ27ÈÕ£¬ÒÑÓÐÔ¼ËÄ·ÖÖ®Ò»µÄ°Ä´óÀûÑÇÈËÔÚMy Health RecordϵͳÖн¨Á¢ÁËÒ½ÁƼǼ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/my-health-record-had-42-data-breaches-in-2017-18-but-no-malicious-attacks-adha/



2¡¢ÃÀ¹úÎÀÉú²¿Ðû²¼Ò½ÁÆÐÐÒµÍøÂçÄþ¾²Êµ¼ù³ÂËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÎÀÉú²¿£¨HHS£©Ðû²¼Ò»·ÝÕë¶ÔÒ½ÁÆÐÐÒµµÄÍøÂçÄþ¾²Ö¸ÄÏ£¬¸Ã³öÊéÎïµÄÃû³ÆΪ¡¶Ò½ÁÆÐÐÒµÍøÂçÄþ¾²Êµ¼ù£º¹ÜÀíÍþв¼°±£»¤»¼Õß¡·¡£Õâ·Ý³ÂËßÊÇHHS¼°Ò½ÁÆר¼Ò»¨·ÑÁ½Äêʱ¼äµÄÊÂÇé½á¹û£¬ÊÇÓÉ2015ÄêµÄÍøÂçÄþ¾²·¨°¸ÊÚȨµÄ¡£¸ÃÖ¸ÄÏ̽ÌÖÁËÒ½ÁÆÐÐÒµÃæÁÙµÄÎå´óÏà¹ØÍþв£¬²¢½¨Òé½ÓÄÉ10ÖÖÍøÂçÄþ¾²´ëÊ©À´»º½âÕâЩÍþв¡£¸ÃÖ¸ÄÏ»¹Ç¿µ÷ÁË¿ìËÙÓ¦¶ÔÕâЩÍþвµÄÖØÒªÐÔ¡£


Ô­ÎÄÁ´½Ó£º
https://www.nextgov.com/cybersecurity/2019/01/hhs-releases-voluntary-cybersecurity-practices-health-industry/153835/


3¡¢Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÄþ¾²·¨£¬ÔÊÐíÕþ¸®·ÃÎÊÓû§Êý¾Ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý·¨ÐÂÉç1ÔÂ1ÈÕ±¨µÀ£¬Ô½ÄÏ´Óµ±Ì쿪ʼʵʩ¼«ÎªÑϸñµÄÍøÂçÄþ¾²·¨¡£¸Ã¹æÔò¶¨£¬»¥ÁªÍø¹«Ë¾±ØÐëɾ³ý±»Õþ¸®È϶¨Îª¡°Óж¾¡±µÄÍøÉÏÄÚÈÝ£¬Ô½ÄÏÍøÃñÒ²²»µÃÔÚ»¥ÁªÍøÉÏÉ¢²¼·´Õþ¸®ÐÅÏ¢»òÍáÇúÀúÊ·¡£´ËÍ⣬Facebook¡¢GoogleµÈ¹ú¼Ê¿Æ¼¼¹«Ë¾ÒªÔÚÔ½ÄÏ¿ªÕ¹ÒµÎñ±ØÐëÔÚÔ½ÄϹúÄÚÉèÁ¢·þÎñ´¦£¬¶øÇÒÔÚÔ½ÄÏÕþ¸®ÒªÇóʱ±ØÐ뽫Óû§Êý¾ÝÌá½»¸øÕþ¸®¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/vietnams-new-cyber-law-threatens/


4¡¢ÃÜÂë¹ÜÀíÆ÷BlurÓû§Êý¾Ýй¶£¬240ÍòÈËÊܵ½Ó°Ïì

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Abine¹«Ë¾ÌåÏÖÆäÃÜÂë¹ÜÀíÆ÷²úÎïBlurµÄÓû§Êý¾ÝÔÚ·þÎñÆ÷ÉÏ̻¶£¬ÕâЩÊý¾Ý°üÂÞ2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëÌáʾÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£ÕâһʼþÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/


5¡¢°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢ºÍ½â£¬Å⸶38.2ÍòÃÀÔª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°ÍÎ÷ÒøÐÐInter¾Í2018ÄêÔçЩʱºòµÄ½üÁ½ÍòÓû§Êý¾Ýй¶°¸¼þ¸æ¿¢ºÍ½â£¬Æ¾¾Ý°ÍÎ÷¼ì²ì¹Ù°ì¹«ÊÒ£¨PPO£©Ðû²¼µÄÏûÏ¢£¬¸ÃÒøÐн«Ö§¸¶150ÍòÀ×ÑǶû£¨Ô¼ºÏ38.2ÍòÃÀÔª£©µÄÅâ³¥½ð¡£Æ¾¾Ý¸ÃʼþÊÓ²ìίԱ»á¼ì²ì¹ÙFrederick MeinbergµÄÏûÏ¢£¬InterÔøÊÔͼÑÚ¸ÇÕâÒ»Êý¾Ýй¶Ê¼þ£¬Õâ¸ø¿Í»§¡¢¹É¶«ºÍͶ×ÊÕß´øÀ´Á˸ü´óµÄ·çÏÕ¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/brazilian-bank-inter-pays-fine-over-customer-data-leak/


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí