ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ52ÖÜ
°ä²¼¹¦·ò 2019-01-02
2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£»£»Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»£»£»£»£»£»£»£»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£»£»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬£¬£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý;IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨;Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬£¬£¬£¬£¬£¬£¬EXPÒѰ䲼;ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html
2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶
IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄºÅÁîÐУ¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://www.ibm.com/support/docview.wss?uid=ibm10743405
3. Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶
Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û¡£¡£¡£¡£¡£
https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶
TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£
http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å
Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.foxitsoftware.com/support/security-bulletins.php³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶
Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬£¬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/
ÔÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/
3¡¢IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/
4¡¢Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬£¬£¬£¬£¬£¬£¬EXPÒѰ䲼
ZDIÅû¶Exchange ServerÖеÄÒ»¸ö°²È«·ì϶£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíÈκξ¹ýÉí·ÝÑéÖ¤µÄÓû§¼ÙÒâExchange ServerÉÏµÄÆäËüÓû§£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¹µö»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖÓ×£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓø÷ì϶Åú¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æ¶¨£¬£¬£¬£¬£¬£¬£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬Æäexp¾ç±¾Äܹ»´Ógithub¸ßµÍÔØ¡£¡£¡£¡£¡£Î¢ÈíÔÚ11Ô·ݵĽ¨¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã·ì϶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange
5¡¢ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP
½üÆÚ£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯ÀûÓ÷¨Ê½£¨APP£©ÂÒÏ󣬣¬£¬£¬£¬£¬£¬¼¯Öз¢Õ¹ËãÕÊÕûÖÎרÏîÐж¯£¬£¬£¬£¬£¬£¬£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åᡱ¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡ÒþÖÔ¡¢ÓÕÆÚ¿Æ¡¢Î¥¹æÓÎÏ·¡¢²»Á¼½ø½¨ÀàAPP¡£¡£¡£¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚ¹úÄÚÀûÓÃÉ̵êÉϼܵÄAPPÒѾ³¬¹ý480Íò¿î£¬£¬£¬£¬£¬£¬£¬º¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£¡£¡£¡£½üÈÕ£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰ켯ÌåԼ̸28¼ÒÀûÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬£¬£¬£¬£¬£¬£¬¶ÔÆäÍÆ¹ãÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨ·¡¢À©É¢Çþ·Ìá³öÖҸ棬£¬£¬£¬£¬£¬£¬ÒªÇóÁ¢¼´¶Ô¸÷×ÔÆ½Ì¨½øÐÐÈ«ÃæÅŲ飬£¬£¬£¬£¬£¬£¬µ±Õæ·¢Õ¹×Ô²é×Ô¾À£¬£¬£¬£¬£¬£¬£¬»ý¼«×Ô¶¯²Î¼ÓÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬ËãÕʵ±ÓÃÉ̵꣬£¬£¬£¬£¬£¬£¬ÆÁ±Î¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²é¾¿½ÓÈë·þÎñ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ