Chrome ä¯ÀÀÆ÷¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-06-08·ì϶±àºÅ
CVE-2018-6148
·ì϶¼¶±ð
¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
¸Ã·ì϶ӰÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨Ô̺¬Windows¡¢MacºÍLinux£©É쵀 web ä¯ÀÀÈí¼þ¡£
·ìϼûèÊö
5ÔÂÄ©£¬×êÑÐÈËÔ±·¢ÏÖ²¢»ã±¨ÁË´æÔÚÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣ·ì϶£¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉ쵀 web ä¯ÀÀÈí¼þ¡£
Chrome °²È«ÍŶÓΪÁô¸øÎÞÊýÓû§¹¦·ò½¨¸´ä¯ÀÀÆ÷£¬²¢Î´Åû¶¹ØÓڸ÷ì϶µÄÈκμ¼ÊõÏêÇ飬ֻÊǽ«¸Ã·ìϼûèÊöΪ²»ÕýÈ·µÄCSPÍ·£¨Content Security Policy£¬ÄÚÈݰ²È«Õ½Êõ£©´¦Ö÷ì϶£¨CVE-2018-6148£©¡£
CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí½ÚÔìä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´Ôö³¤¶î±íµÄ°²È«²ã¡£
ÈôÊÇ web ä¯ÀÀÆ÷ÃýÎó´¦ÖÃÁË CSP Í·²¿£¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÖ¸±êÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷½Ù³ÖÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£
½â¾ö´ëÊ©
Chrome ¸üеIJ»±ä°æ±¾ 67.0.3396.79 ÖÐÒѰ䲼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£
»ðºüÒ²ÍÆ³öÁËÔ̺¬½¨¸´¹æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£½¨Òé»ðºüä¯ÀÀÆ÷²»±ä°æÓû§¾¡¿ìÓèÒÔ¸üС£
²Î¿¼×ÊÁÏ
https://thehackernews.com/2018/06/google-chrome-csp.html


¾©¹«Íø°²±¸11010802024551ºÅ