΢ÈíAndroid°æOutlook XSSÎó²î

Ðû²¼Ê±¼ä 2019-06-22


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Åä¾°ÐÎò


΢ÈíÐû²¼Android°æOutlookÇå¾²¸üУ¬£¬£¬ £¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105 £©¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ´¥·¢¸ÃÎó²î£¬£¬£¬ £¬´Ó¶øÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐжñÒâµÄÓ¦ÓÃÄÚ¿Í»§¶Ë´úÂë¡£¡£¡£¡£¡£¡£


Îó²îÁбí


CVE ID  £º   CVE-2019-1105
Îó²îÆ·¼¶£º   ÖÐΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ïì¹æÄ££º   Outlook for Android 3.0.88֮ǰµÄ°æ±¾

Îó²îÏêÇé


ƾ֤΢ÈíÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬ £¬Outlook for Android 3.0.88֮ǰµÄ°æ±¾±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëAPPÆÊÎö´«Èëµç×ÓÓʼþµÄ·½·¨ÓйØ£¬£¬£¬ £¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâµç×ÓÓʼþÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÊÜÓ°ÏìµÄϵͳִÐпçÕ¾¾ç±¾¹¥»÷£¬£¬£¬ £¬²¢ÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾¡£¡£¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýOutlook for AndroidÆÊÎöÌØ¶¨µç×ÓÓʼþµÄ·½·¨À´ÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£


΢Èí³Æ¸ÃÎó²îÊÇÓɶà¸öÇå¾²Ñо¿Ö°Ô±×ÔÁ¦±¨¸æµÄ£¬£¬£¬ £¬²¢ÇÒ¿ÉÄܻᵼÖÂÓÕÆ­ÀàÐ͵Ĺ¥»÷¡£¡£¡£¡£¡£¡£´ËÎó²îµÄÏêϸÊÖÒÕϸ½Ú»ò¿´·¨ÑéÖ¤ÉÐδ¹ûÕæÐû²¼¡£¡£¡£¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδ·¢Ã÷Óë´ËÎó²îÓйصÄÈκι¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£

ÐÞ¸´½¨Òé


ÈôÊÇÓû§µÄAndroid×°±¸ÉÐδ×Ô¶¯¸üУ¬£¬£¬ £¬½¨ÒéÓû§´ÓGoogle PlayÊÐËÁÊÖ¶¯¸üÐÂOutlook APP¡£¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1105
https://thehackernews.com/2019/06/outlook-app-android.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1105