΢ÈíAndroid°æOutlook XSSÎó²î

Ðû²¼Ê±¼ä 2019-06-22


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Åä¾°ÐÎò


΢ÈíÐû²¼Android°æOutlookÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105 £© ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâµç×ÓÓʼþ´¥·¢¸ÃÎó²î£¬£¬£¬£¬´Ó¶øÔÚÄ¿µÄ×°±¸ÉÏÖ´ÐжñÒâµÄÓ¦ÓÃÄÚ¿Í»§¶Ë´úÂë ¡£¡£¡£¡£¡£¡£


Îó²îÁбí


CVE ID  £º   CVE-2019-1105
Îó²îÆ·¼¶£º   ÖÐΣ
CVSSÆÀ·Ö£º   ÔÝÎÞ
Ó°Ïì¹æÄ££º   Outlook for Android 3.0.88֮ǰµÄ°æ±¾

Îó²îÏêÇé


ƾ֤΢ÈíÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬Outlook for Android 3.0.88֮ǰµÄ°æ±¾±£´æÒ»¸ö´æ´¢ÐÍXSSÎó²î£¨CVE-2019-1105£© ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëAPPÆÊÎö´«Èëµç×ÓÓʼþµÄ·½·¨Óйأ¬£¬£¬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòÄ¿µÄ·¢ËͶñÒâµç×ÓÓʼþÀ´Ê¹ÓôËÎó²î ¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÄÜ»á¶ÔÊÜÓ°ÏìµÄϵͳִÐпçÕ¾¾ç±¾¹¥»÷£¬£¬£¬£¬²¢ÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾 ¡£¡£¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýOutlook for AndroidÆÊÎöÌØ¶¨µç×ÓÓʼþµÄ·½·¨À´ÐÞ¸´¸ÃÎó²î ¡£¡£¡£¡£¡£¡£


΢Èí³Æ¸ÃÎó²îÊÇÓɶà¸öÇå¾²Ñо¿Ö°Ô±×ÔÁ¦±¨¸æµÄ£¬£¬£¬£¬²¢ÇÒ¿ÉÄܻᵼÖÂÓÕÆ­ÀàÐ͵Ĺ¥»÷ ¡£¡£¡£¡£¡£¡£´ËÎó²îµÄÏêϸÊÖÒÕϸ½Ú»ò¿´·¨ÑéÖ¤ÉÐδ¹ûÕæÐû²¼ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ΢ÈíÉÐδ·¢Ã÷Óë´ËÎó²îÓйصÄÈκι¥»÷ÊÂÎñ ¡£¡£¡£¡£¡£¡£

ÐÞ¸´½¨Òé


ÈôÊÇÓû§µÄAndroid×°±¸ÉÐδ×Ô¶¯¸üУ¬£¬£¬£¬½¨ÒéÓû§´ÓGoogle PlayÊÐËÁÊÖ¶¯¸üÐÂOutlook APP ¡£¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1105
https://thehackernews.com/2019/06/outlook-app-android.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1105