ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ52ÖÜ
°ä²¼¹¦·ò 2019-01-02
2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å£»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶£»Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý;IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨;Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬EXPÒѰ䲼;ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html
2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶
IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄºÅÁîÐУ¬ÌáÉýȨÏÞ¡£
https://www.ibm.com/support/docview.wss?uid=ibm10743405
3. Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶
Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÒªÇ󣬿ÉÈÆ¹ý°²È«ÏÞ¶È£¬Î´ÊÚȨ½Ó¼û¡£
https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶
TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£
http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å
Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://www.foxitsoftware.com/support/security-bulletins.php³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶
Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/
ÔÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/
3¡¢IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/
4¡¢Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬EXPÒѰ䲼
ZDIÅû¶Exchange ServerÖеÄÒ»¸ö°²È«·ì϶£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¸Ã·ì϶ÔÊÐíÈκξ¹ýÉí·ÝÑéÖ¤µÄÓû§¼ÙÒâExchange ServerÉÏµÄÆäËüÓû§£¬¿ÉÓÃÓÚ´¹µö»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¸Ã·ì϶ÊÇÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓø÷ì϶Åú¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æ¶¨£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬Æäexp¾ç±¾Äܹ»´Ógithub¸ßµÍÔØ¡£Î¢ÈíÔÚ11Ô·ݵĽ¨¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange
5¡¢ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬Ï¼Ü3469¿îAPP
½üÆÚ£¬¹ú¶ÈÍøÐŰì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯ÀûÓ÷¨Ê½£¨APP£©ÂÒÏ󣬼¯Öз¢Õ¹ËãÕÊÕûÖÎרÏîÐж¯£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åᡱ¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡ÒþÖÔ¡¢ÓÕÆÚ¿Æ¡¢Î¥¹æÓÎÏ·¡¢²»Á¼½ø½¨ÀàAPP¡£¾Ýͳ¼Æ£¬Ä¿Ç°ÔÚ¹úÄÚÀûÓÃÉ̵êÉϼܵÄAPPÒѾ³¬¹ý480Íò¿î£¬º¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£½üÈÕ£¬¹ú¶ÈÍøÐŰ켯ÌåԼ̸28¼ÒÀûÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬¶ÔÆäÍÆ¹ãÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨ·¡¢À©É¢Çþ·Ìá³öÖҸ棬ҪÇóµ±¼´¶Ô¸÷×ÔÆ½Ì¨½øÐÐÈ«ÃæÅŲ飬µ±Õæ·¢Õ¹×Ô²é×Ô¾À£¬»ý¼«×Ô¶¯²Î¼ÓÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬ËãÕʵ±ÓÃÉ̵꣬ÆÁ±Î¶ñÒâÁ´½Ó£¬²é¾¿½ÓÈë·þÎñ¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ