Chrome ä¯ÀÀÆ÷¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-08

Îó²î±àºÅ


CVE-2018-6148


Îó²î¼¶±ð


¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


¸ÃÎó²îÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨°üÀ¨Windows¡¢MacºÍLinux£©ÉϵĠweb ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£


Îó²îÐÎò


5ÔÂÄ© £¬£¬£¬ £¬£¬Ñо¿Ö°Ô±·¢Ã÷²¢±¨¸æÁ˱£´æÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣÎó²î £¬£¬£¬ £¬£¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉϵĠweb ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£
Chrome Çå¾²ÍŶÓΪÁô¸ø´ó¶¼Óû§Ê±¼äÐÞ¸´ä¯ÀÀÆ÷ £¬£¬£¬ £¬£¬²¢Î´Åû¶¹ØÓÚ¸ÃÎó²îµÄÈκÎÊÖÒÕÏêÇé £¬£¬£¬ £¬£¬Ö»Êǽ«¸ÃÎó²îÐÎòΪ²»×¼È·µÄCSPÍ·£¨Content Security Policy £¬£¬£¬ £¬£¬ÄÚÈÝÇå¾²Õ½ÂÔ£©´¦Öóͷ£Îó²î£¨CVE-2018-6148£©¡£¡£¡£¡£¡£¡£ ¡£


CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí¿ØÖÆä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´ÔöÌíÌØÁíÍâÇå¾²²ã¡£¡£¡£¡£¡£¡£ ¡£

 

ÈôÊÇ web ä¯ÀÀÆ÷¹ýʧ´¦Öóͷ£ÁË CSP Í·²¿ £¬£¬£¬ £¬£¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÄ¿µÄÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷Ð®ÖÆÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£


½â¾ö²½·¥


Chrome ¸üеÄÎȹ̰汾 67.0.3396.79 ÖÐÒÑÐû²¼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£¡£¡£¡£¡£¡£ ¡£


»ðºüÒ²ÍÆ³öÁ˰üÀ¨ÐÞ¸´¼Æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£¡£¡£¡£¡£¡£ ¡£½¨Òé»ðºüä¯ÀÀÆ÷Îȹ̰æÓû§¾¡¿ìÓèÒÔ¸üС£¡£¡£¡£¡£¡£ ¡£


²Î¿¼×ÊÁÏ


https://thehackernews.com/2018/06/google-chrome-csp.html