ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ52ÖÜ

°ä²¼¹¦·ò 2019-01-02
±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å£»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶£»Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý;IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨;Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬EXPÒѰ䲼;ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1. Adobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å

Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶

IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄºÅÁîÐУ¬ÌáÉýȨÏÞ¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶

Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÒªÇ󣬿ÉÈÆ¹ý°²È«ÏÞ¶È£¬Î´ÊÚȨ½Ó¼û¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£Æ¾¾ÝÕâЩÎļþ£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø²É°ì¼äµýÉ豸¡£ÀýÈç2018Äê8Ô£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹Ý°ä²¼Ò»·Ý²É¹ºÐèÒª£¬ÆäÖÐÔ̺¬94¼þ¼äµýÉ豸£¬Ô̺¬ÄÜ×°ÖÃÔÚÆû³Â·ïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°¼Ù×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÈÕ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˹àÒô»úºÍÒñ±ÎÎÞÏßµçÉ豸µÈ¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



IBM X-Force°ä²¼¹ØÓÚ2019ÄêÍøÂç·¸×ïÍþв¸ñ¾ÖµÄÔ¤²â»ã±¨£¬»ã±¨³Æ2019ÄêÆóÒµ½«Ï÷¼õʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»GDPR½«¶ÔÍþвµý±¨¡¢ÍøÂ簲ȫ´øÀ´¸ü¿í·ºµÄÓ°Ï죻¹¥»÷Õß½«¸ü¶àµØÀûÓÃÃæÏò¹«¼ÒµÄ×ÔÖ÷·þÎñÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£»ÍøÂ簲ȫ±£ÏÕ·þÎñÉ̽«¸ü¶àµØÓ밲ȫ¹©¸øÉ̽øÐкÏ×÷£»·¸×ï·Ö×Ó½«¸ü¶àµØÕë¶ÔÓÎÀÀ¡¢¾ÆµêÒµµÄÊý¾Ý£»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓйØ£¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÀûÓÃPowerShellÒÔÎÞÎļþµÄ´ó¾Ö½øÐС£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬EXPÒѰ䲼

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸ö°²È«·ì϶£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¸Ã·ì϶ÔÊÐíÈκξ­¹ýÉí·ÝÑéÖ¤µÄÓû§¼ÙÒâExchange ServerÉÏµÄÆäËüÓû§£¬¿ÉÓÃÓÚ´¹µö»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¸Ã·ì϶ÊÇÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓø÷ì϶Åú¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æ¶¨£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬Æäexp¾ç±¾Äܹ»´Ógithub¸ßµÍÔØ¡£Î¢ÈíÔÚ11Ô·ݵĽ¨¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



½üÆÚ£¬¹ú¶ÈÍøÐŰì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯ÀûÓ÷¨Ê½£¨APP£©ÂÒÏ󣬼¯Öз¢Õ¹ËãÕÊÕûÖÎרÏîÐж¯£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åᡱ¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡ÒþÖÔ¡¢ÓÕÆ­Ú¿Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼½ø½¨ÀàAPP¡£¾Ýͳ¼Æ£¬Ä¿Ç°ÔÚ¹úÄÚÀûÓÃÉ̵êÉϼܵÄAPPÒѾ­³¬¹ý480Íò¿î£¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£½üÈÕ£¬¹ú¶ÈÍøÐŰ켯ÌåԼ̸28¼ÒÀûÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬¶ÔÆäÍÆ¹ãÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨ·¡¢À©É¢Çþ·Ìá³öÖҸ棬ҪÇóÁ¢¼´¶Ô¸÷×ÔÆ½Ì¨½øÐÐÈ«ÃæÅŲ飬µ±Õæ·¢Õ¹×Ô²é×Ô¾À£¬»ý¼«×Ô¶¯²Î¼ÓÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬ËãÕʵ±ÓÃÉ̵꣬ÆÁ±Î¶ñÒâÁ´½Ó£¬²é¾¿½ÓÈë·þÎñ¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù