ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ1ÖÜ

Ðû²¼Ê±¼ä 2019-01-07

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ31ÈÕÖÁ2019Äê1ÔÂ6ÈÕ¹²ÊÕ¼Çå¾²Îó²î37¸ö£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAdobe Acrobat/Reader CVE-2018-16011ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î£»£»£»£»D-Link DIR-818LW/DIR-860L soap.cgi OSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£»£»£»£»Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç³öÎó²î£»£»£»£»Dell EMC RSA Archer»á¼û¿ØÖƹýʧÎó²î¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǰÄÖÞÊý×Ö¿µ½¡ÊðÐû²¼2017-2018Äê¶È±¨¸æ£¬£¬ £¬£¬£¬£¬Åû¶42ÆðÊý¾Ýй¶ÊÂÎñ£»£»£»£»ÃÀ¹úÎÀÉú²¿Ðû²¼Ò½ÁÆÐÐÒµÍøÂçÇ徲ʵ¼ù±¨¸æ£»£»£»£»Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÇå¾²·¨£¬£¬ £¬£¬£¬£¬ÔÊÐíÕþ¸®»á¼ûÓû§Êý¾Ý£»£»£»£»ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬£¬ £¬£¬£¬£¬240ÍòÈËÊܵ½Ó°Ï죻£»£»£»°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢Ï¢Õù£¬£¬ £¬£¬£¬£¬Å⸶38.2ÍòÃÀÔª¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Adobe Acrobat/Reader CVE-2018-16011ÊͷźóʹÓôúÂëÖ´ÐÐÎó²î

Adobe Acrobat/Reader´¦Öóͷ£PDFÎļþ±£´æÊͷźóʹÓÃÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.auscert.org.au/bulletins/73738

2. D-Link DIR-818LW/DIR-860L soap.cgi OSÏÂÁîÖ´ÐÐÎó²î

D-Link DIR-818LW/DIR-860L soap.cgi´¦Öóͷ£Service²ÎÊý±£´æÊäÈëÑéÖ¤Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£
https://github.com/pr0v3rbs/CVE/tree/master/CVE-2018-20114

3. Apache NetBeans Proxy Auto-Configuration (PAC) interpretationÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î
Apache NetBeans Proxy Auto-Configuration (PAC) interpretationʵÏÖ±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://lists.apache.org/thread.html/d1c37966a316a326ab4ff4d4bc056322e8adcbe984e8145c0ecda7fa@%3Cdev.netbeans.apache.org%3E

4. Guardzilla GZ621W CVE-2018-18601»º³åÇøÒç³öÎó²î
Guardzilla GZ621W ¡®TK_set_deviceModel_req_handle¡¯º¯Êý±£´æ»º³åÇøÒç³öÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»òÖ´ÐдúÂë¡£¡£¡£¡£
https://labs.bitdefender.com/2018/12/iot-report-major-flaws-in-guardzilla-cameras-allow-remote-hijack-of-the-security-device/

5. Dell EMC RSA Archer»á¼û¿ØÖƹýʧÎó²î
Dell EMC RSA Archer±£´æ»á¼û¿ØÖƹýʧÎó²î£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬ £¬£¬£¬£¬¶ÁÈ¡ÊÜÏÞÐÅÏ¢¡£¡£¡£¡£
https://seclists.org/fulldisclosure/2019/Jan/3


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢°ÄÖÞÊý×Ö¿µ½¡ÊðÐû²¼2017-2018Äê¶È±¨¸æ£¬£¬ £¬£¬£¬£¬Åû¶42ÆðÊý¾Ýй¶ÊÂÎñ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

°Ä´óÀûÑÇÊý×Ö¿µ½¡Êð£¨ADHA£©ÔÚÆä2017-2018Äê¶È±¨¸æÖÐÌåÏÖ£¬£¬ £¬£¬£¬£¬My Health RecordϵͳÖеÄÒ½ÁƼͼÔÚ2017Äê7ÔÂ1ÈÕÖÁ2018Äê6ÔÂ30ÈÕʱ´ú¹²±¬·¢42ÆðÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£ÆäÖдó´ó¶¼Ð¹Â¶ÊÂÎñÓëÒ½Áưü¹ÜڲƭÓйأ¬£¬ £¬£¬£¬£¬My Health Record²¢Î´Ôâµ½Ëðº¦ÆäÍêÕûÐÔºÍÇå¾²ÐԵĶñÒâ¹¥»÷¡£¡£¡£¡£×èÖ¹2018Äê7ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ÒÑÓÐÔ¼ËÄ·ÖÖ®Ò»µÄ°Ä´óÀûÑÇÈËÔÚMy Health RecordϵͳÖн¨ÉèÁËÒ½ÁƼͼ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/my-health-record-had-42-data-breaches-in-2017-18-but-no-malicious-attacks-adha/



2¡¢ÃÀ¹úÎÀÉú²¿Ðû²¼Ò½ÁÆÐÐÒµÍøÂçÇ徲ʵ¼ù±¨¸æ

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


ÃÀ¹úÎÀÉú²¿£¨HHS£©Ðû²¼Ò»·ÝÕë¶ÔÒ½ÁÆÐÐÒµµÄÍøÂçÇå¾²Ö¸ÄÏ£¬£¬ £¬£¬£¬£¬¸Ã³öÊéÎïµÄÃû³ÆÎª¡¶Ò½ÁÆÐÐÒµÍøÂçÇ徲ʵ¼ù£ºÖÎÀíÍþв¼°±£»£»£»£»¤»¼Õß¡·¡£¡£¡£¡£Õâ·Ý±¨¸æÊÇHHS¼°Ò½ÁÆ×¨¼ÒÆÆ·ÑÁ½Äêʱ¼äµÄÊÂÇéЧ¹û£¬£¬ £¬£¬£¬£¬ÊÇÓÉ2015ÄêµÄÍøÂçÇå¾²·¨°¸ÊÚȨµÄ¡£¡£¡£¡£¸ÃÖ¸ÄÏ̽ÌÖÁËÒ½ÁÆÐÐÒµÃæÁÙµÄÎå´óÏà¹ØÍþв£¬£¬ £¬£¬£¬£¬²¢½¨Òé½ÓÄÉ10ÖÖÍøÂçÇå¾²²½·¥À´»º½âÕâЩÍþв¡£¡£¡£¡£¸ÃÖ¸ÄÏ»¹Ç¿µ÷ÁË¿ìËÙÓ¦¶ÔÕâЩÍþвµÄÖ÷ÒªÐÔ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.nextgov.com/cybersecurity/2019/01/hhs-releases-voluntary-cybersecurity-practices-health-industry/153835/


3¡¢Ô½ÄÏÕþ¸®Í¨¹ýÐÂÍøÂçÇå¾²·¨£¬£¬ £¬£¬£¬£¬ÔÊÐíÕþ¸®»á¼ûÓû§Êý¾Ý

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


¾Ý·¨ÐÂÉç1ÔÂ1ÈÕ±¨µÀ£¬£¬ £¬£¬£¬£¬Ô½ÄÏ´Óµ±Ìì×îÏÈʵÑ鼫ΪÑÏ¿áµÄÍøÂçÇå¾²·¨¡£¡£¡£¡£¸Ã¹æÔò¶¨£¬£¬ £¬£¬£¬£¬»¥ÁªÍø¹«Ë¾±ØÐèɾ³ý±»Õþ¸®È϶¨Îª¡°Óж¾¡±µÄÍøÉÏÄÚÈÝ£¬£¬ £¬£¬£¬£¬Ô½ÄÏÍøÃñÒ²²»µÃÔÚ»¥ÁªÍøÉÏÉ¢²¼·´Õþ¸®ÐÅÏ¢»òÍáÇúÀúÊ·¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬Facebook¡¢GoogleµÈ¹ú¼Ê¿Æ¼¼¹«Ë¾ÒªÔÚÔ½ÄÏ¿ªÕ¹ÓªÒµ±ØÐèÔÚÔ½ÄϺ£ÄÚÉèÁ¢Ð§ÀÍ´¦£¬£¬ £¬£¬£¬£¬²¢ÇÒÔÚÔ½ÄÏÕþ¸®ÒªÇóʱ±ØÐ轫Óû§Êý¾ÝÌá½»¸øÕþ¸®¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/vietnams-new-cyber-law-threatens/


4¡¢ÃÜÂëÖÎÀíÆ÷BlurÓû§Êý¾Ýй¶£¬£¬ £¬£¬£¬£¬240ÍòÈËÊܵ½Ó°Ïì

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Abine¹«Ë¾ÌåÏÖÆäÃÜÂëÖÎÀíÆ÷²úÆ·BlurµÄÓû§Êý¾ÝÔÚЧÀÍÆ÷ÉÏ̻¶£¬£¬ £¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨2018Äê1ÔÂ6ÈÕ֮ǰע²áµÄBlurÓû§µÄÐÅÏ¢£¬£¬ £¬£¬£¬£¬Èçµç×ÓÓʼþµØµã¡¢ÐÕÃû¡¢ÃÜÂëÌáÐÑÓï¡¢×îºóµÇ¼IPºÍ¼ÓÑÎÃÜÂë¹þÏ£¡£¡£¡£¡£¸Ã¹«Ë¾Ç¿µ÷³ÆÓû§µÄÃÜÂë¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍµç»°ºÅÂëûÓÐй¶¡£¡£¡£¡£ÕâÒ»ÊÂÎñÓ°ÏìÁËÔ¼240ÍòBlurÓû§¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-2-4-million-blur-password-manager-users-left-exposed-online/


5¡¢°ÍÎ÷ÒøÐÐInter¾ÍÊý¾Ýй¶°¸¸æ¿¢Ï¢Õù£¬£¬ £¬£¬£¬£¬Å⸶38.2ÍòÃÀÔª

Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾


°ÍÎ÷ÒøÐÐInter¾Í2018ÄêÔçЩʱ¼äµÄ½üÁ½ÍòÓû§Êý¾Ýй¶°¸¼þ¸æ¿¢Ï¢Õù£¬£¬ £¬£¬£¬£¬Æ¾Ö¤°ÍÎ÷Éó²é¹Ù°ì¹«ÊÒ£¨PPO£©Ðû²¼µÄÐÂÎÅ£¬£¬ £¬£¬£¬£¬¸ÃÒøÐн«Ö§¸¶150ÍòÀ×ÑǶû£¨Ô¼ºÏ38.2ÍòÃÀÔª£©µÄÅâ³¥½ð¡£¡£¡£¡£Æ¾Ö¤¸ÃÊÂÎñÊÓ²ìίԱ»áÉó²é¹ÙFrederick MeinbergµÄÐÂÎÅ£¬£¬ £¬£¬£¬£¬InterÔøÊÔͼÑÚÊÎÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬£¬£¬Õâ¸ø¿Í»§¡¢¹É¶«ºÍͶ×ÊÕß´øÀ´Á˸ü´óµÄΣº¦¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/brazilian-bank-inter-pays-fine-over-customer-data-leak/


ÉùÃ÷£º±¾×ÊѶÓÉZ6×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí