Chrome ä¯ÀÀÆ÷¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-08

·ì϶±àºÅ


CVE-2018-6148


·ì϶¼¶±ð


¸ß  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳ£¨Ô̺¬Windows¡¢MacºÍLinux£©ÉϵĠweb ä¯ÀÀÈí¼þ¡£


·ìϼûèÊö


5ÔÂÄ© £¬×êÑÐÈËÔ±·¢ÏÖ²¢»ã±¨ÁË´æÔÚÓÚ Chrome ä¯ÀÀÆ÷ÖеÄÒ»¸ö¸ßΣ·ì϶ £¬ËüÓ°ÏìËùÓÐÖ÷Á÷²Ù×÷ϵͳÉϵĠweb ä¯ÀÀÈí¼þ¡£
Chrome °²È«ÍŶÓΪÁô¸øÎÞÊýÓû§¹¦·ò½¨¸´ä¯ÀÀÆ÷ £¬²¢Î´Åû¶¹ØÓڸ÷ì϶µÄÈκμ¼ÊõÏêÇé £¬Ö»Êǽ«¸Ã·ìϼûèÊöΪ²»ÕýÈ·µÄCSPÍ·£¨Content Security Policy £¬ÄÚÈݰ²È«Õ½Êõ£©´¦Ö÷ì϶£¨CVE-2018-6148£©¡£


CSP Í·²¿ÄÜÈÃÍøÕ¾ÖÎÀíÔ±Ôڼȶ¨ÍøÒ³ÉÏͨ¹ýÔÊÐí½ÚÔìä¯ÀÀÆ÷µÄ¼ÓÔØ×ÊÔ´À´Ôö³¤¶î±íµÄ°²È«²ã¡£

 

ÈôÊÇ web ä¯ÀÀÆ÷ÃýÎó´¦ÖÃÁË CSP Í·²¿ £¬Ôò¿Éµ¼Ö¹¥»÷ÕßÔÚÖ¸±êÍøÒ³ÉÏÖ´ÐпçÕ¾µã¾ç±¾¹¥»÷¡¢µã»÷½Ù³ÖÒÔ¼°ÆäËüÀàÐ͵ĴúÂë×¢Èë¹¥»÷¡£


½â¾ö´ëÊ©


Chrome ¸üеIJ»±ä°æ±¾ 67.0.3396.79 ÖÐÒѰ䲼Õë¶ÔËùÓÐÖ÷Á÷²Ù×÷ϵͳµÄ²¹¶¡¡£


»ðºüÒ²ÍÆ³öÁËÔ̺¬½¨¸´¹æ»®µÄä¯ÀÀÆ÷а汾 60.0.2¡£½¨Òé»ðºüä¯ÀÀÆ÷²»±ä°æÓû§¾¡¿ìÓèÒÔ¸üС£


²Î¿¼×ÊÁÏ


https://thehackernews.com/2018/06/google-chrome-csp.html