[情報] IOS 10.2.1 更新內容
https://support.apple.com/en-us/HT207482
This document describes the security content of iOS 10.2.1.
iOS 10.2.1
Released January 23, 2017
Auto Unlock 自動解鎖問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:當Apple watch離開你的手時仍然會自動解鎖
Impact: Auto Unlock may unlock when Apple Watch is off the user's wrist
Description: A logic issue was addressed through improved state management.
CVE-2017-2352: Ashley Fernandez of raptAware Pty Ltd
Contacts 聯絡人問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意的聯絡人資料卡可能造成程式中止
Impact: Processing a maliciously crafted contact card may lead to unexpected
application termination
Description: An input validation issue existed in the parsing of contact
cards. This issue was addressed through improved input validation.
CVE-2017-2368: Vincent Desmurs (vincedes3)
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2017-2370: Ian Beer of Google Project Zero
Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges
Description: A use after free issue was addressed through improved memory
management.
CVE-2017-2360: Ian Beer of Google Project Zero
libarchive 資料庫封存問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:打開惡意產生的封包可能導致程式碼任意執行
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code
execution
Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2016-8687: Agostino Sarubbo of Gentoo
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A prototype access issue was addressed through improved
exception handling.
CVE-2017-2350: Gareth Heyes of Portswigger Web Security
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved memory handling.
CVE-2017-2354: Neymar of Tencent's Xuanwu Lab (tencent.com) working with
Trend Micro's Zero Day Initiative
CVE-2017-2362: Ivan Fratric of Google Project Zero
CVE-2017-2373: Ivan Fratric of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: A memory initialization issue was addressed through improved
memory handling.
CVE-2017-2355: Team Pangu and lokihardt at PwnFest 2016
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution
Description: Multiple memory corruption issues were addressed through
improved input validation.
CVE-2017-2356: Team Pangu and lokihardt at PwnFest 2016
CVE-2017-2369: Ivan Fratric of Google Project Zero
CVE-2017-2366: Kai Kang of Tencent's Xuanwu Lab (tencent.com)
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of page loading. This
issue was addressed through improved logic.
CVE-2017-2363: lokihardt of Google Project Zero
CVE-2017-2364: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意網站可以打開彈出式視窗
Impact: A malicious website can open popups
Description: An issue existed in the handling of blocking popups. This was
addressed through improved input validation.
CVE-2017-2371: lokihardt of Google Project Zero
WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin
Description: A validation issue existed in the handling of variable handling.
This issue was addressed through improved validation.
CVE-2017-2365: lokihardt of Google Project Zero
WiFi 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:有啟動鎖定的裝置可以在操作下短暫的顯示首頁
Impact: An activation-locked device can be manipulated to briefly present the
home screen
Description: An issue existed with handling user input that caused a device
to present the home screen even when activation locked. This was addressed
through improved input validation.
CVE-2017-2351: Sriram (@Sri_Hxor) of Primefort Pvt. Ltd., Hemanth Joseph
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 131.215.107.226
※ 文章網址: https://www.ptt.cc/bbs/iPhone/M.1485207039.A.B60.html
→
01/24 06:22, , 1F
01/24 06:22, 1F
噓
01/24 08:02, , 2F
01/24 08:02, 2F
噓
01/24 08:25, , 3F
01/24 08:25, 3F
噓
01/24 08:27, , 4F
01/24 08:27, 4F
噓
01/24 08:27, , 5F
01/24 08:27, 5F
→
01/24 08:31, , 6F
01/24 08:31, 6F
※ 編輯: kyle5241 (206.117.40.12), 01/24/2017 08:32:25
噓
01/24 08:34, , 7F
01/24 08:34, 7F
→
01/24 08:34, , 8F
01/24 08:34, 8F
噓
01/24 08:41, , 9F
01/24 08:41, 9F
→
01/24 08:41, , 10F
01/24 08:41, 10F
→
01/24 08:47, , 11F
01/24 08:47, 11F
噓
01/24 08:50, , 12F
01/24 08:50, 12F
噓
01/24 08:51, , 13F
01/24 08:51, 13F
→
01/24 08:52, , 14F
01/24 08:52, 14F
噓
01/24 08:54, , 15F
01/24 08:54, 15F
噓
01/24 08:58, , 16F
01/24 08:58, 16F
推
01/24 08:58, , 17F
01/24 08:58, 17F
噓
01/24 08:59, , 18F
01/24 08:59, 18F
推
01/24 09:00, , 19F
01/24 09:00, 19F
噓
01/24 09:02, , 20F
01/24 09:02, 20F
→
01/24 09:03, , 21F
01/24 09:03, 21F
噓
01/24 09:18, , 22F
01/24 09:18, 22F
推
01/24 09:39, , 23F
01/24 09:39, 23F
噓
01/24 09:53, , 24F
01/24 09:53, 24F
→
01/24 09:56, , 25F
01/24 09:56, 25F
噓
01/24 09:57, , 26F
01/24 09:57, 26F
噓
01/24 09:58, , 27F
01/24 09:58, 27F
噓
01/24 10:20, , 28F
01/24 10:20, 28F
推
01/24 10:29, , 29F
01/24 10:29, 29F
推
01/24 10:37, , 30F
01/24 10:37, 30F
推
01/24 10:39, , 31F
01/24 10:39, 31F
噓
01/24 10:47, , 32F
01/24 10:47, 32F
噓
01/24 10:48, , 33F
01/24 10:48, 33F
噓
01/24 10:54, , 34F
01/24 10:54, 34F
推
01/24 10:59, , 35F
01/24 10:59, 35F
推
01/24 11:43, , 36F
01/24 11:43, 36F
噓
01/24 11:47, , 37F
01/24 11:47, 37F
推
01/24 12:10, , 38F
01/24 12:10, 38F
還有 38 則推文
還有 1 段內文
推
01/24 21:06, , 77F
01/24 21:06, 77F
推
01/24 21:25, , 78F
01/24 21:25, 78F
推
01/24 21:35, , 79F
01/24 21:35, 79F
推
01/24 21:42, , 80F
01/24 21:42, 80F
推
01/24 21:47, , 81F
01/24 21:47, 81F
推
01/24 22:19, , 82F
01/24 22:19, 82F
推
01/24 22:22, , 83F
01/24 22:22, 83F
推
01/24 22:55, , 84F
01/24 22:55, 84F
推
01/24 22:58, , 85F
01/24 22:58, 85F
推
01/24 23:13, , 86F
01/24 23:13, 86F
推
01/25 00:15, , 87F
01/25 00:15, 87F
推
01/25 02:19, , 88F
01/25 02:19, 88F
推
01/25 02:36, , 89F
01/25 02:36, 89F
推
01/25 03:09, , 90F
01/25 03:09, 90F
推
01/25 03:32, , 91F
01/25 03:32, 91F
推
01/25 03:48, , 92F
01/25 03:48, 92F
推
01/25 04:31, , 93F
01/25 04:31, 93F
推
01/25 05:25, , 94F
01/25 05:25, 94F
推
01/25 08:16, , 95F
01/25 08:16, 95F
推
01/25 08:35, , 96F
01/25 08:35, 96F
推
01/25 09:50, , 97F
01/25 09:50, 97F
推
01/25 10:11, , 98F
01/25 10:11, 98F
推
01/25 11:34, , 99F
01/25 11:34, 99F
推
01/25 12:24, , 100F
01/25 12:24, 100F
推
01/25 12:28, , 101F
01/25 12:28, 101F
推
01/25 12:56, , 102F
01/25 12:56, 102F
推
01/25 12:59, , 103F
01/25 12:59, 103F
推
01/25 13:55, , 104F
01/25 13:55, 104F
推
01/25 14:43, , 105F
01/25 14:43, 105F
推
01/25 15:39, , 106F
01/25 15:39, 106F
推
01/26 18:08, , 107F
01/26 18:08, 107F
推
01/27 22:54, , 108F
01/27 22:54, 108F
推
01/28 03:29, , 109F
01/28 03:29, 109F
推
01/28 07:57, , 110F
01/28 07:57, 110F
推
01/28 22:59, , 111F
01/28 22:59, 111F
推
01/29 18:45, , 112F
01/29 18:45, 112F
推
01/31 00:25, , 113F
01/31 00:25, 113F
推
01/31 13:05, , 114F
01/31 13:05, 114F
推
02/01 02:00, , 115F
02/01 02:00, 115F
推
02/01 12:44, , 116F
02/01 12:44, 116F