Chrome ä¯ÀÀÆ÷¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-08

·ì϶±àºÅ


CVE-2018-6148


·ì϶¼¶±ð


¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨Ô̺¬Windows¡¢MacºÍLinux£©ÉϵĠweb ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£


·ìϼûèÊö


5ÔÂÄ©£¬ £¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖ²¢»ã±¨ÁË´æÔÚÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣ·ì϶£¬ £¬£¬£¬£¬£¬£¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉϵĠweb ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£
Chrome °²È«ÍŶÓΪÁô¸øÎÞÊýÓû§¹¦·ò½¨¸´ä¯ÀÀÆ÷£¬ £¬£¬£¬£¬£¬£¬²¢Î´Åû¶¹ØÓڸ÷ì϶µÄÈκμ¼ÊõÏêÇ飬 £¬£¬£¬£¬£¬£¬Ö»Êǽ«¸Ã·ìϼûèÊöΪ²»ÕýÈ·µÄCSPÍ·£¨Content Security Policy£¬ £¬£¬£¬£¬£¬£¬ÄÚÈݰ²È«Õ½Êõ£©´¦Ö÷ì϶£¨CVE-2018-6148£©¡£¡£¡£¡£¡£


CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí½ÚÔìä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´Ôö³¤¶î±íµÄ°²È«²ã¡£¡£¡£¡£¡£

 

ÈôÊÇ web ä¯ÀÀÆ÷ÃýÎó´¦ÖÃÁË CSP Í·²¿£¬ £¬£¬£¬£¬£¬£¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÖ¸±êÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷½Ù³ÖÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£¡£¡£¡£¡£


½â¾ö´ëÊ©


Chrome ¸üеIJ»±ä°æ±¾ 67.0.3396.79 ÖÐÒѰ䲼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£¡£¡£¡£¡£


»ðºüÒ²ÍÆ³öÁËÔ̺¬½¨¸´¹æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£¡£¡£¡£¡£½¨Òé»ðºüä¯ÀÀÆ÷²»±ä°æÓû§¾¡¿ìÓèÒÔ¸üС£¡£¡£¡£¡£


²Î¿¼×ÊÁÏ


https://thehackernews.com/2018/06/google-chrome-csp.html