ÐÇ°Í¿Ë×°±Æ·¸ÖÕ½áÕß-Apple RCEÎó²î£¨CVE-2018-4407£©

Ðû²¼Ê±¼ä 2018-10-31

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


ʱ¼äÏß


2018-08-09£º¹Ù·½ÊÕµ½Îó²îϸ½Ú²¢È·ÈÏ
2018-09-17£ºAppleÐû²¼iOS 12 £¬ÐÞ¸´¸ÃÎó²î
2018-09-24£ºmacOS MojaveÓÉAppleÐû²¼ £¬ÐÞ¸´¸ÃÎó²î
2018-10-30£ºÎó²î¹ûÕæ


Îó²îÏêÇé


´ËÎó²îÎÞÐèÈκÎÓû§½»»¥ £¬¿ÉÒÔÔÚͳһÍøÂçÉÏÖØÆôÈκÎMac»òiOS×°±¸¡£AppleÒѽ«´ËÎó²î¹éÀàΪÄÚºËÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î £¬ÓÉÓÚ¿ÉÄÜʹÓûº³åÇøÒç³öÀ´Ö´ÐÐÄÚºËÖеÄí§Òâ´úÂë¡£


ÒÔÏÂϵͳ°æ±¾ºÍ×°±¸Ò×Êܹ¥»÷£º
Apple iOS 11¼°¸üÔç°æ±¾£ºËùÓÐ×°±¸£¨Éý¼¶µ½iOS 12£©
Apple macOS High Sierra £¬×î¸ß¿Éµ½10.13.6£ºËùÓÐ×°±¸£¨ÔÚÇå¾²¸üÐÂ2018-001Öдò²¹¶¡£©
Apple macOS Sierra £¬°üÀ¨10.12.6£ºËùÓÐ×°±¸£¨ÔÚÇå¾²¸üÐÂ2018-005Öдò²¹¶¡£©
Apple OS X El Capitan¼°¸üÔç°æ±¾£ºËùÓÐ×°±¸


¸ÃÎó²îÊÇXNUϵͳÄÚºËÖеÄÍøÂç´úÂëÖеĶѻº³åÇøÒç³ö¡£iOSºÍmacOS¶¼Ê¹ÓÃXNU £¬Õâ¾ÍÊÇiPhone £¬iPadºÍMacbook¶¼Êܵ½Ó°ÏìµÄÔµ¹ÊÔ­ÓÉ¡£Òª´¥·¢´ËÎó²î £¬¹¥»÷ÕßÖ»Ð轫¶ñÒâIPÊý¾Ý°ü·¢Ë͵½Ä¿µÄ×°±¸µÄIPµØµã¼´¿É¡£ÎÞÐèÓû§½»»¥¡£¹¥»÷ÕßÖ»ÐèÒªÅþÁ¬µ½ÓëÄ¿µÄ×°±¸ÏàͬµÄÍøÂç¡£ÀýÈç £¬ÈôÊÇÄúÔÚ¿§·ÈµêʹÓÃÃâ·ÑWiFi £¬Ôò¹¥»÷Õß¿ÉÒÔ¼ÓÈëÏàͬµÄWiFiÍøÂç²¢ÏòÄúµÄ×°±¸·¢ËͶñÒâÊý¾Ý°ü¡££¨ÈôÊǹ¥»÷ÕßÓëÄúÔÚͳһÍøÂçÉÏ £¬ÔòËûÃǺÜÈÝÒ×ʹÓÃnmap·¢Ã÷Äú×°±¸µÄIPµØµã¡££©¸üÔã¸âµÄÊÇ £¬¸ÃÎó²îÊÇÍøÂç´úÂëµÄÒ»¸ö»ù±¾²¿·Ö £¬·´²¡¶¾Èí¼þÎÞ·¨±£»¤Äú £¬ÄúÔÚ×°±¸ÉÏÔËÐеÄÈí¼þÒ²Î޹ؽôÒª - ×ÝÈ»ÄúûÓз­¿ªÈκζ˿Ú £¬¶ñÒâÊý¾Ý°üÈԻᴥ·¢Îó²î¡£


»º½â²½·¥£º

¿ªÆômacOS·À»ðǽ²¢ÆôÓÃÉñÃØÐж¯Ä£Ê½
²»ÒªÊ¹Óù«¹²WiFiÍøÂç¡£


²Î¿¼Á´½Ó£ºhttps://lgtm.com/blog/apple_xnu_icmp_error_CVE-2018-4407