ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ52ÖÜ

°ä²¼¹¦·ò 2019-01-02
±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ24ÈÕ30ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£» £»IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£» £»Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»£»£»£»£»£»£» £»TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£» £»Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å¡£¡£ ¡£ ¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÊ¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶;ά»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬£¬£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý;IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨;Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬£¬£¬£¬£¬£¬£¬EXPÒѰ䲼;ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP¡£¡£ ¡£ ¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£ ¡£ ¡£¡£


³ÁÒª°²È«·ì϶Áбí


1. Adobe AcrobatºÍReader TIFFͼÏñ½âÎö»º³åÇøÒç¶Âí½Å

Adobe AcrobatºÍReader´¦ÖÃTIFFͼÏñ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£ ¡£¡£

https://helpx.adobe.com/security/products/acrobat/apsb18-34.html



2. IBM NotesºÍDomino NSD·þÎñȨÏÞÌáÉý·ì϶

IBM NotesºÍDomino NSD·þÎñ´¦ÖÃIPC´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄºÅÁîÐУ¬£¬£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£ ¡£ ¡£¡£

https://www.ibm.com/support/docview.wss?uid=ibm10743405


3. Discuz! DiscuzX CVE-2018-20422°²È«ÏÞ¶ÈÈÆ¹ý·ì϶

Discuz! DiscuzXÆôÓÃWeChatʱ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ïòplugin.php ac=wxregister·¢ËÍ¿Õ#wechat#common_member_wechatmpµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û¡£¡£ ¡£ ¡£¡£

https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI


4. TOSHIBA Home Gateway HEM-GW26A/HEM-GW16A OSºÅÁî×¢Èë·ì϶

TOSHIBA Home Gateway HEM-GW26AºÍTOSHIBA Home Gateway HEM-GW16A´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâOSºÅÁî¡£¡£ ¡£ ¡£¡£

http://www.tlt.co.jp/tlt/information/seihin/notice/defect/20181219/20181219.htm


5. Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý»º³åÇøÒç¶Âí½Å

Foxit Quick PDF Library LoadFromFile¡¢LoadFromStringºÍLoadFromStreamº¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£» £»òÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£ ¡£¡£

https://www.foxitsoftware.com/support/security-bulletins.php


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬£¬£¬£¬£¬£¬£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£¡£ ¡£ ¡£¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬£¬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£ ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Î¬»ù½âÃÜÅû¼ûÀ¹ú´óʹ¹Ý¹ºÎïÇåµ¥£¬£¬£¬£¬£¬£¬£¬ÎļþÊýÁ¿³¬¹ý1.6Íò·Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



12ÔÂ21ÈÕά»ù½âÃÜÅû¶1.6Íò·ÝÎļþ£¬£¬£¬£¬£¬£¬£¬ÕâЩÎļþÊÇÃÀ¹ú´óʹ¹ÝµÄ¹ºÎïÇåµ¥¡£¡£ ¡£ ¡£¡£Æ¾¾ÝÕâЩÎļþ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úפ¶à¹ú´óʹ¹Ý¶¼Ôø²É°ì¼äµýÉ豸¡£¡£ ¡£ ¡£¡£ÀýÈç2018Äê8Ô£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú×¤Èø¶ûÍß¶àʹ¹Ý°ä²¼Ò»·Ý²É¹ºÐèÒª£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬94¼þ¼äµýÉ豸£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÄÜ×°ÖÃÔÚÆû³Â·ïµÄÒ¹ÊÓÉãÏñÍ·ÒÔ¼°¼Ù×°Ôڸֱʡ¢´ò»ð»ú¡¢³ÄÉÀŦ¿Û¡¢ÑÛ¾µµÈÈÕ³£ÓÃÆ·ÖеÄÉãÏñÍ·¡£¡£ ¡£ ¡£¡£ÃÀ¹úפÎÚ¿ËÀ¼Ê¹¹ÝÔò²É¹ºÁ˹àÒô»úºÍÒñ±ÎÎÞÏßµçÉ豸µÈ¡£¡£ ¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://shoppinglist.wikileaks.org/


3¡¢IBM X-Force°ä²¼2019ÄêÍøÂç·¸×ïÍþвԶ¾°µÄÔ¤²â»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



IBM X-Force°ä²¼¹ØÓÚ2019ÄêÍøÂç·¸×ïÍþв¸ñ¾ÖµÄÔ¤²â»ã±¨£¬£¬£¬£¬£¬£¬£¬»ã±¨³Æ2019ÄêÆóÒµ½«Ï÷¼õʹÓÃÉç±£ºÅÂë×÷ΪÉí·ÝÑéÖ¤±êʶ£»£»£»£»£»£»£» £»GDPR½«¶ÔÍþвµý±¨¡¢ÍøÂ簲ȫ´øÀ´¸ü¿í·ºµÄÓ°Ï죻£»£»£»£»£»£» £»¹¥»÷Õß½«¸ü¶àµØÀûÓÃÃæÏò¹«¼ÒµÄ×ÔÖ÷·þÎñÏµÍ³ÍøÂçÓмÛÖµµÄÓû§Êý¾Ý£»£»£»£»£»£»£» £»ÍøÂ簲ȫ±£ÏÕ·þÎñÉ̽«¸ü¶àµØÓ밲ȫ¹©¸øÉ̽øÐкÏ×÷£»£»£»£»£»£»£» £»·¸×ï·Ö×Ó½«¸ü¶àµØÕë¶ÔÓÎÀÀ¡¢¾ÆµêÒµµÄÊý¾Ý£»£»£»£»£»£»£» £»Ò»Ð©¹ÉƱÂô¿Õ¿ÉÄÜÓëÍøÂç¹¥»÷ÓйØ£¬£¬£¬£¬£¬£¬£¬2019Ä꽫»áÅû¶һЩÊÂÎñ»ò»î¶¯£»£»£»£»£»£»£» £»¶ñÒâÍÚ¿ó¹¥»÷½«¸ü¶àµØÀûÓÃPowerShellÒÔÎÞÎļþµÄ´ó¾Ö½øÐÓ×£¡£ ¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityintelligence.com/ibm-x-force-security-predictions-for-the-2019-cybercrime-threat-landscape/


4¡¢Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬£¬£¬£¬£¬£¬£¬EXPÒѰ䲼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ZDIÅû¶Exchange ServerÖеÄÒ»¸ö°²È«·ì϶£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¡£ ¡£ ¡£¡£¸Ã·ì϶ÔÊÐíÈκξ­¹ýÉí·ÝÑéÖ¤µÄÓû§¼ÙÒâExchange ServerÉÏµÄÆäËüÓû§£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ´¹µö»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖÓ×£¡£ ¡£ ¡£¡£¸Ã·ì϶ÊÇÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓø÷ì϶Åú¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æ¶¨£¬£¬£¬£¬£¬£¬£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬£¬£¬£¬£¬£¬£¬Æäexp¾ç±¾Äܹ»´Ógithub¸ßµÍÔØ¡£¡£ ¡£ ¡£¡£Î¢ÈíÔÚ11Ô·ݵĽ¨¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã·ì϶¡£¡£ ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


5¡¢ÍøÐŰ췢չAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬Ï¼Ü3469¿îAPP

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½üÆÚ£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰì»áͬÓйز¿ÃÅÕë¶ÔÍøÃñ·´Ó³Ç¿ÁÒµÄÎ¥·¨Î¥¹æ¡¢µÍËײ»Á¼Òƶ¯ÀûÓ÷¨Ê½£¨APP£©ÂÒÏ󣬣¬£¬£¬£¬£¬£¬¼¯Öз¢Õ¹ËãÕÊÕûÖÎרÏîÐж¯£¬£¬£¬£¬£¬£¬£¬ÒÀ·¨¹ØÍ£Ï¼ܡ°³ÉÈËÔ¼ÁÄ¡±¡°Á½ÐÔ˽ÃÜȦ¡±¡°°ÄÃŽðɳ¡±¡°Ò¹É«µÄ¼Åᡱ¡°È«ÃñÉäË®¹û¡±µÈ3469¿îÉæ»ÆÉæ¶Ä¡¢¶ñÒâ¿Û·Ñ¡¢ÇÔÈ¡ÒþÖÔ¡¢ÓÕÆ­Ú¿Æ­¡¢Î¥¹æÓÎÏ·¡¢²»Á¼½ø½¨ÀàAPP¡£¡£ ¡£ ¡£¡£¾Ýͳ¼Æ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚ¹úÄÚÀûÓÃÉ̵êÉϼܵÄAPPÒѾ­³¬¹ý480Íò¿î£¬£¬£¬£¬£¬£¬£¬º­¸ÇÁËÈËÃñÉúÑĵĸ÷¸ö·½Ãæ¡£¡£ ¡£ ¡£¡£½üÈÕ£¬£¬£¬£¬£¬£¬£¬¹ú¶ÈÍøÐŰ켯ÌåԼ̸28¼ÒÀûÓÃÉ̵ꡢÉ罻ƽ̨ºÍÔÆ·þÎñÆóÒµ£¬£¬£¬£¬£¬£¬£¬¶ÔÆäÍÆ¹ãÖ÷ÌåÔðÈβ»Á¦¡¢¿Í¹ÛÉÏΪΥ·¨Î¥¹æAPPÌṩ½ÓÈëͨ·¡¢À©É¢Çþ·Ìá³öÖҸ棬£¬£¬£¬£¬£¬£¬ÒªÇóÁ¢¼´¶Ô¸÷×ÔÆ½Ì¨½øÐÐÈ«ÃæÅŲ飬£¬£¬£¬£¬£¬£¬µ±Õæ·¢Õ¹×Ô²é×Ô¾À£¬£¬£¬£¬£¬£¬£¬»ý¼«×Ô¶¯²Î¼ÓÎ¥·¨Î¥¹æAPPÂÒÏóרÏîÕûÖÎÐж¯£¬£¬£¬£¬£¬£¬£¬ËãÕʵ±ÓÃÉ̵꣬£¬£¬£¬£¬£¬£¬ÆÁ±Î¶ñÒâÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²é¾¿½ÓÈë·þÎñ¡£¡£ ¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º
http://www.cac.gov.cn/2018-12/28/c_1123919199.htm


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù