{"id":4560,"date":"2023-10-16T13:09:24","date_gmt":"2023-10-16T05:09:24","guid":{"rendered":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=4560"},"modified":"2023-10-20T13:11:06","modified_gmt":"2023-10-20T05:11:06","slug":"google-%e4%bf%ae%e5%be%a9%e5%b7%b2%e9%81%ad%e7%94%a8%e6%96%bc%e6%94%bb%e6%93%8a%e7%9a%84-chrome-0-day-%e6%bc%8f%e6%b4%9e","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=4560","title":{"rendered":"Google \u4fee\u5fa9\u5df2\u906d\u7528\u65bc\u653b\u64ca\u7684 Chrome 0-day \u6f0f\u6d1e"},"content":{"rendered":"\n<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2023-10-16<\/p>\n\n\n\n<p>Google \u65e5\u524d\u63a8\u51fa Google Chrome \u700f\u89bd\u5668\u7684\u65b0\u7248\u672c 117.0.5938.132\uff0c\u4fee\u5fa9\u4e00\u500b\u5df2\u8b49\u5be6\u906d\u5230\u99ed\u4fb5\u8005\u7528\u65bc\u653b\u64ca\u7684 0-day \u6f0f\u6d1e CVE-2023-5217\uff1bGoogle Chrome \u8207\u5404\u76f8\u5bb9 Chromium \u7684\u700f\u89bd\u5668\u4f7f\u7528\u8005\u61c9\u76e1\u901f\u66f4\u65b0\u81f3\u6700\u65b0\u7248\u672c\u3002<\/p>\n\n\n\n<p>\u9019\u500b CVE-2023-5217 \u7684\u6f0f\u6d1e\uff0c\u5b58\u65bc Google Chrome \u700f\u89bd\u5668\u5167\u5efa\u7684\u958b\u6e90 libvpx \u8996\u8a0a\u89e3\u78bc\u7a0b\u5f0f\u5eab\u4e2d\u7684 VP8 \u7de8\u78bc\u55ae\u5143\uff0c\u5c6c\u65bc heap \u66ab\u5b58\u5668\u6ea2\u4f4d\u932f\u8aa4\uff1b\u99ed\u4fb5\u8005\u5c07\u53ef\u5229\u7528\u6b64\u6f0f\u6d1e\u4f86\u9020\u6210 App \u57f7\u884c\u5d29\u6f70\uff0c\u4ea6\u80fd\u85c9\u4ee5\u57f7\u884c\u4efb\u610f\u7a0b\u5f0f\u78bc\u3002<\/p>\n\n\n\n<p>CVE-2023-5217 \u9019\u500b\u6f0f\u6d1e\u7684 CVSS \u5371\u96aa\u7a0b\u5ea6\u8a55\u5206\u9ad8\u9054 8.8 \u5206\uff08\u6eff\u5206\u70ba 10 \u5206\uff09\uff0c\u5371\u96aa\u7a0b\u5ea6\u8a55\u7d1a\u70ba\u300c\u9ad8\uff5c\uff08high\uff09\u3002<\/p>\n\n\n\n<p>Google \u4e5f\u5728\u65e5\u524d\u767c\u8868\u7684\u8cc7\u5b89\u901a\u5831\u4e2d\u6307\u51fa\uff0c\u8a72\u516c\u53f8\u5df2\u7372\u6089 CVE-2023-5127 \u5df2\u906d\u99ed\u4fb5\u8005\u7528\u65bc\u653b\u64ca\u7684\u60c5\u8cc7\uff1bGoogle \u8868\u793a\uff0c\u5728\u5927\u591a\u6578\u4f7f\u7528\u8005\u90fd\u5df2\u7d93\u66f4\u65b0\u5230\u65b0\u7248 Google Chrome \u700f\u89bd\u5668\uff0c\u4e14\u7b2c\u4e09\u65b9\u7a0b\u5f0f\u5eab\u5df2\u7d93\u66f4\u65b0\u8a72\u6f0f\u6d1e\u4e4b\u524d\uff0cGoogle \u4e0d\u6703\u516c\u5e03\u4efb\u4f55\u95dc\u65bc\u6b64\u6f0f\u6d1e\u7684\u7d30\u7bc0\u8cc7\u8a0a\u3002<\/p>\n\n\n\n<p>Google \u4e5f\u81ea\u5373\u65e5\u8d77\u9010\u6b65\u91cb\u51fa\u65b0\u7248 Google Chrome \u700f\u89bd\u5668\u4ee5\u4fee\u5fa9\u6b64\u6f0f\u6d1e\uff1b\u65b0\u7248\u672c\u7684\u7de8\u865f\u70ba 117.0.5938.132\uff0c\u4f7f\u7528\u8005\u53ef\u671b\u5728\u8fd1\u65e5\u5728 Google Chrome \u700f\u89bd\u5668\u4e2d\u6536\u5230\u66f4\u65b0\u901a\u77e5\uff1b\u4f46\u5176\u4ed6\u4ee5\u958b\u6e90\u7684 Chromium \u88fd\u4f5c\u7684 Chrome \u76f8\u5bb9\u700f\u89bd\u5668\uff0c\u53ef\u80fd\u8981\u7a0d\u5f8c\u624d\u80fd\u9678\u7e8c\u66f4\u65b0\u3002<\/p>\n\n\n\n<p>CVE \u7de8\u865f\uff1aCVE-2023-5217<br>\u5f71\u97ff\u7522\u54c1\uff1aGoogle Chrome \u7248\u672c 117.0.5938.132 \u4e4b\u524d\u7248\u672c\uff0c\u5305\u62ec Windows\u3001Mac\u3001Linux \u7b49\u3002<br>\u89e3\u6c7a\u65b9\u6848\uff1a\u66f4\u65b0\u81f3 Google Chrome 117.0.5938.132 \u8207\u5f8c\u7e8c\u7248\u672c\u3002<\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-7452-8b860-1.html\" data-type=\"link\" data-id=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-7452-8b860-1.html\">https:\/\/www.twcert.org.tw\/tw\/cp-104-7452-8b860-1.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2023-10-16 Google \u65e5\u524d\u63a8\u51fa Google Chrome \u700f\u89bd\u5668\u7684\u65b0\u7248\u672c 117.0.5938.132\uff0c\u4fee\u5fa9\u4e00\u500b\u5df2\u8b49\u5be6\u906d\u5230\u99ed&hellip;<\/p>\n","protected":false},"author":9,"featured_media":4561,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[204],"class_list":["post-4560","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2023\/10\/391231016173591431-e1697778641439.png?fit=899%2C674&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4560"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4560\/revisions"}],"predecessor-version":[{"id":4562,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/4560\/revisions\/4562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/4561"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}