ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2019-01-02
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö £¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î£»£»£»IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î£»£»£»Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î£»£»£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î£»£»£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î¡£¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ £¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥ £¬£¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ;Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ £¬£¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯ £¬£¬Ï¼Ü3469¿îAPP¡£¡£¡£ ¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö £¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£ ¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î

Adobe AcrobatºÍReader´¦Öóͷ£TIFFͼÏñ±£´æ»º³åÇøÒç³öÎó²î £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ £¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î

IBM NotesºÍDomino NSDЧÀÍ´¦Öóͷ£IPC±£´æÇå¾²Îó²î £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÏÂÁîÐÐ £¬£¬ÌáÉýȨÏÞ¡£¡£¡£ ¡£¡£¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î

Discuz! DiscuzXÆôÓÃWeChatʱ±£´æÇå¾²Îó²î £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÏòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇó £¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ £¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£ ¡£¡£¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A±£´æÊäÈëÑéÖ¤Îó²î £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£ ¡£¡£¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý±£´æ»º³åÇøÒç³öÎó²î £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ £¬£¬ÓÕʹÓû§ÆÊÎö £¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ £¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷ £¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ £¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£ ¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£© £¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄê £¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥ £¬£¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ £¬£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ÕâЩÎļþ £¬£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£¡£¡£ ¡£¡£¡£ÀýÈç2018Äê8Ô £¬£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇó £¬£¬ÆäÖаüÀ¨94¼þÌØ¹¤×°±¸ £¬£¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£¡£ ¡£¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



IBM X-ForceÐû²¼¹ØÓÚ2019ÄêÍøÂç·¸·¨ÍþвÃûÌõÄÕ¹Íû±¨¸æ £¬£¬±¨¸æ³Æ2019ÄêÆóÒµ½«ïÔ̭ʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»£»£»GDPR½«¶ÔÍþвÇ鱨¡¢ÍøÂçÇå¾²´øÀ´¸üÆÕ±éµÄÓ°Ï죻£»£»¹¥»÷Õß½«¸ü¶àµØÊ¹ÓÃÃæÏò¹«ÖÚµÄ×ÔÖúЧÀÍÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£»£»£»ÍøÂçÇå¾²°ü¹ÜЧÀÍÉ̽«¸ü¶àµØÓëÇå¾²¹©Ó¦É̾ÙÐÐÏàÖú£»£»£»·¸·¨·Ö×Ó½«¸ü¶àµØÕë¶ÔÂÃÓΡ¢ÂùÝÒµµÄÊý¾Ý£»£»£»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓÐ¹Ø £¬£¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£»£»£»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÊ¹ÓÃPowerShellÒÔÎÞÎļþµÄÐÎʽ¾ÙÐС£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ £¬£¬EXPÒÑÐû²¼

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸öÇå¾²Îó²î£¨CVE-2018-8581£©µÄÊÖÒÕϸ½Ú¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îÔÊÐíÈκξ­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉÏµÄÆäËüÓû§ £¬£¬¿ÉÓÃÓÚ´¹Âڻ¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¡£¡£ ¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î £¬£¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓøÃÎó²îÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò £¬£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õß £¬£¬Æäexp¾ç±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£¡£¡£ ¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸ÃÎó²î¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯ £¬£¬Ï¼Ü3469¿îAPP

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



½üÆÚ £¬£¬¹ú¼ÒÍøÐŰì»áͬÓйز¿·ÖÕë¶ÔÍøÃñ·´Ó¦Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦ÓóÌÐò£¨APP£©ÂÒÏó £¬£¬¼¯ÖпªÕ¹ÕûÀíÕûÖÎרÏîÐж¯ £¬£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄÁȼš±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆ­Õ©Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¡£¡£ ¡£¡£¡£¾Ýͳ¼Æ £¬£¬ÏÖÔÚÔÚº£ÄÚÓ¦ÓÃÊÐËÁÉϼܵÄAPPÒѾ­Áè¼Ý480Íò¿î £¬£¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£ ¡£¡£¡£¿ËÈÕ £¬£¬¹ú¼ÒÍøÐŰìÕûÌåԼ̸28¼ÒÓ¦ÓÃÊÐËÁ¡¢É罻ƽ̨ºÍÔÆÐ§ÀÍÆóÒµ £¬£¬¶ÔÆäÍÆÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³öÖÒÑÔ £¬£¬ÒªÇóÁ¬Ã¦¶Ô¸÷×ÔÆ½Ì¨¾ÙÐÐÖÜÈ«ÅÅ²é £¬£¬ÈÏÕæ¿ªÕ¹×Ô²é×Ô¾À £¬£¬Æð¾¢×Ô¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯ £¬£¬ÕûÀíÓ¦ÓÃÊÐËÁ £¬£¬ÆÁÕ϶ñÒâÁ´½Ó £¬£¬Çå²é½ÓÈëЧÀÍ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·­ÒëºÍÕûÀí