Chrome ä¯ÀÀÆ÷¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-06-08

Îó²î±àºÅ


CVE-2018-6148


Îó²î¼¶±ð


¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


¸ÃÎó²îÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨°üÀ¨Windows¡¢MacºÍLinux£©ÉϵĠweb ä¯ÀÀÈí¼þ¡£


Îó²îÐÎò


5ÔÂÄ©£¬Ñо¿Ö°Ô±·¢Ã÷²¢±¨¸æÁ˱£´æÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣÎó²î£¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉϵĠweb ä¯ÀÀÈí¼þ¡£
Chrome Çå¾²ÍŶÓΪÁô¸ø´ó¶¼Óû§Ê±¼äÐÞ¸´ä¯ÀÀÆ÷£¬²¢Î´Åû¶¹ØÓÚ¸ÃÎó²îµÄÈκÎÊÖÒÕÏêÇ飬ֻÊǽ«¸ÃÎó²îÐÎòΪ²»×¼È·µÄCSPÍ·£¨Content Security Policy£¬ÄÚÈÝÇå¾²Õ½ÂÔ£©´¦Öóͷ£Îó²î£¨CVE-2018-6148£©¡£


CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí¿ØÖÆä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´ÔöÌíÌØÁíÍâÇå¾²²ã¡£

 

ÈôÊÇ web ä¯ÀÀÆ÷¹ýʧ´¦Öóͷ£ÁË CSP Í·²¿£¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÄ¿µÄÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷Ð®ÖÆÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£


½â¾ö²½·¥


Chrome ¸üеÄÎȹ̰汾 67.0.3396.79 ÖÐÒÑÐû²¼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£


»ðºüÒ²ÍÆ³öÁ˰üÀ¨ÐÞ¸´¼Æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£½¨Òé»ðºüä¯ÀÀÆ÷Îȹ̰æÓû§¾¡¿ìÓèÒÔ¸üС£


²Î¿¼×ÊÁÏ


https://thehackernews.com/2018/06/google-chrome-csp.html