ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ52ÖÜ

Ðû²¼Ê±¼ä 2019-01-02
±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î£» £»£»£»£»IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î£» £»£»£»£»Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î£» £»£»£»£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î£» £»£»£»£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬£¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý;IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ;Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬£¬£¬£¬£¬EXPÒÑÐû²¼;ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP¡£¡£¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe AcrobatºÍReader TIFFͼÏñÆÊÎö»º³åÇøÒç³öÎó²î

Adobe AcrobatºÍReader´¦Öóͷ£TIFFͼÏñ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSDЧÀÍȨÏÞÌáÉýÎó²î

IBM NotesºÍDomino NSDЧÀÍ´¦Öóͷ£IPC±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÏÂÁîÐУ¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422Çå¾²ÏÞÖÆÈÆ¹ýÎó²î

Discuz! DiscuzXÆôÓÃWeChatʱ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÏòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSÏÂÁî×¢ÈëÎó²î

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç³öÎó²î

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£» £»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¶ÃÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬£¬ÎļþÊýÄ¿Áè¼Ý1.6Íò·Ý

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬£¬£¬£¬£¬£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÕâЩÎļþ£¬£¬£¬£¬£¬£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø¹ºÖÃÌØ¹¤×°±¸¡£¡£¡£¡£¡£¡£ÀýÈç2018Äê8Ô£¬£¬£¬£¬£¬£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹ÝÐû²¼Ò»·Ý²É¹ºÐèÇ󣬣¬£¬£¬£¬£¬ÆäÖаüÀ¨94¼þÌØ¹¤×°±¸£¬£¬£¬£¬£¬£¬°üÀ¨ÄÜ×°ÖÃÔÚÆû³µÀïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°Î±×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÒ»Ñùƽ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£¡£¡£¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˼Òô»úºÍÒþ²ØÎÞÏßµç×°±¸µÈ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-ForceÐû²¼2019ÄêÍøÂç·¸·¨ÍþвԶ¾°µÄÕ¹Íû±¨¸æ

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



IBM X-ForceÐû²¼¹ØÓÚ2019ÄêÍøÂç·¸·¨ÍþвÃûÌõÄÕ¹Íû±¨¸æ£¬£¬£¬£¬£¬£¬±¨¸æ³Æ2019ÄêÆóÒµ½«ïÔ̭ʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£» £»£»£»£»GDPR½«¶ÔÍþвÇ鱨¡¢ÍøÂçÇå¾²´øÀ´¸üÆÕ±éµÄÓ°Ï죻 £»£»£»£»¹¥»÷Õß½«¸ü¶àµØÊ¹ÓÃÃæÏò¹«ÖÚµÄ×ÔÖúЧÀÍÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£» £»£»£»£»ÍøÂçÇå¾²°ü¹ÜЧÀÍÉ̽«¸ü¶àµØÓëÇå¾²¹©Ó¦É̾ÙÐÐÏàÖú£» £»£»£»£»·¸·¨·Ö×Ó½«¸ü¶àµØÕë¶ÔÂÃÓΡ¢ÂùÝÒµµÄÊý¾Ý£» £»£»£»£»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓйØ£¬£¬£¬£¬£¬£¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£» £»£»£»£»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÊ¹ÓÃPowerShellÒÔÎÞÎļþµÄÐÎʽ¾ÙÐС£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÍ¸ºÍÌáȨ£¬£¬£¬£¬£¬£¬EXPÒÑÐû²¼

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ZDIÅû¶Exchange ServerÖеÄÒ»¸öÇå¾²Îó²î£¨CVE-2018-8581£©µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐíÈκξ­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ã°³äExchange ServerÉÏµÄÆäËüÓû§£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¹Âڻ¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öЧÀÍÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓøÃÎó²îÐÞ¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æÔò£¬£¬£¬£¬£¬£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬£¬£¬£¬£¬Æäexp¾ç±¾¿ÉÒÔ´ÓgithubÉÏÏÂÔØ¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵÄÐÞ¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸ÃÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ쿪չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP

¿­Ê±K66¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



½üÆÚ£¬£¬£¬£¬£¬£¬¹ú¼ÒÍøÐŰì»áͬÓйز¿·ÖÕë¶ÔÍøÃñ·´Ó¦Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯Ó¦ÓóÌÐò£¨APP£©ÂÒÏ󣬣¬£¬£¬£¬£¬¼¯ÖпªÕ¹ÕûÀíÕûÖÎרÏîÐж¯£¬£¬£¬£¬£¬£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄÁȼš±¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡Òþ˽¡¢ÓÕÆ­Õ©Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼Ñ§Ï°ÀàAPP¡£¡£¡£¡£¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬ÏÖÔÚÔÚº£ÄÚÓ¦ÓÃÊÐËÁÉϼܵÄAPPÒѾ­Áè¼Ý480Íò¿î£¬£¬£¬£¬£¬£¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£¡£¡£¡£¿ËÈÕ£¬£¬£¬£¬£¬£¬¹ú¼ÒÍøÐŰìÕûÌåԼ̸28¼ÒÓ¦ÓÃÊÐËÁ¡¢É罻ƽ̨ºÍÔÆÐ§ÀÍÆóÒµ£¬£¬£¬£¬£¬£¬¶ÔÆäÍÆÐÐÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨµÀ¡¢À©É¢ÇþµÀÌá³öÖÒÑÔ£¬£¬£¬£¬£¬£¬ÒªÇóÁ¬Ã¦¶Ô¸÷×ÔÆ½Ì¨¾ÙÐÐÖÜÈ«ÅŲ飬£¬£¬£¬£¬£¬ÈÏÕæ¿ªÕ¹×Ô²é×Ô¾À£¬£¬£¬£¬£¬£¬Æð¾¢×Ô¶¯¼ÓÈëÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬ÕûÀíÓ¦ÓÃÊÐËÁ£¬£¬£¬£¬£¬£¬ÆÁÕ϶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬Çå²é½ÓÈëЧÀÍ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉùÃ÷£º±¾×ÊѶÓÉ¿­Ê±K66άËûÃüÇ徲С×é·­ÒëºÍÕûÀí