Chrome ä¯ÀÀÆ÷¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-06-08Îó²î±àºÅ
CVE-2018-6148
Îó²î¼¶±ð
¸ß CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
¸ÃÎó²îÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨°üÀ¨Windows¡¢MacºÍLinux£©É쵀 web ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£¡£¡£
Îó²îÐÎò
5ÔÂÄ©£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷²¢±¨¸æÁ˱£´æÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣÎó²î£¬£¬£¬£¬£¬£¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉ쵀 web ä¯ÀÀÈí¼þ¡£¡£¡£¡£¡£¡£¡£
Chrome Çå¾²ÍŶÓΪÁô¸ø´ó¶¼Óû§Ê±¼äÐÞ¸´ä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬²¢Î´Åû¶¹ØÓÚ¸ÃÎó²îµÄÈκÎÊÖÒÕÏêÇ飬£¬£¬£¬£¬£¬Ö»Êǽ«¸ÃÎó²îÐÎòΪ²»×¼È·µÄCSPÍ·£¨Content Security Policy£¬£¬£¬£¬£¬£¬ÄÚÈÝÇå¾²Õ½ÂÔ£©´¦Öóͷ£Îó²î£¨CVE-2018-6148£©¡£¡£¡£¡£¡£¡£¡£
CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí¿ØÖÆä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´ÔöÌíÌØÁíÍâÇå¾²²ã¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇ web ä¯ÀÀÆ÷¹ýʧ´¦Öóͷ£ÁË CSP Í·²¿£¬£¬£¬£¬£¬£¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÄ¿µÄÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷Ð®ÖÆÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£¡£
½â¾ö²½·¥
Chrome ¸üеÄÎȹ̰汾 67.0.3396.79 ÖÐÒÑÐû²¼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£¡£¡£¡£¡£¡£¡£
»ðºüÒ²ÍÆ³öÁ˰üÀ¨ÐÞ¸´¼Æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£¡£¡£¡£¡£¡£¡£½¨Òé»ðºüä¯ÀÀÆ÷Îȹ̰æÓû§¾¡¿ìÓèÒÔ¸üС£¡£¡£¡£¡£¡£¡£
²Î¿¼×ÊÁÏ
https://thehackernews.com/2018/06/google-chrome-csp.html