Vulnerabilities nyob rau hauv webOS uas tso cai rau cov ntaub ntawv yuav overwritten ntawm LG TVs

Cov ntaub ntawv tau tshaj tawm txog qhov tsis zoo hauv qhov qhib webOS platform uas tuaj yeem siv tau kom nkag mus rau APIs qib qis qis ntawm qhov system ib puag ncig ntawm LG TVs thiab lwm yam khoom siv raws li lub platform no. Qhov kev tawm tsam yog ua los ntawm kev tso tawm ntawm daim ntawv thov tsis tsim nyog uas ua rau muaj qhov tsis zoo los ntawm kev nkag mus rau APIs sab hauv, thiab tso cai rau koj los sau / nyeem cov ntaub ntawv tsis txaus ntseeg lossis ua lwm yam kev ua haujlwm uas tau tso cai los ntawm system APIs.

Thawj qhov kev tsis pom zoo tso cai rau koj hla kev txwv tsis pub nkag mus rau Tus Thawj Tswj Kev Ceeb Toom API, thiab qhov thib ob tso cai rau koj siv Tus Thawj Saib Xyuas Kev Ceeb Toom kom nkag mus rau lwm cov APIs sab hauv uas tsis ncaj qha rau cov neeg siv daim ntawv thov. CVE tus cim tseem tsis tau muab rau cov teeb meem. Lub peev xwm los siv qhov tsis zoo tau raug sim ntawm LG 65SM8500PLA TV nrog firmware raws li webOS TV 05.10.30.

Lub ntsiab lus ntawm thawj qhov tsis zoo yog tias los ntawm lub neej ntawd, xa cov ntawv ceeb toom hauv webOS tsuas yog tso cai rau cov kev pabcuam hauv lub cev, tab sis qhov kev txwv no tuaj yeem hla thiab kev ceeb toom tuaj yeem xa los ntawm daim ntawv thov tsis muaj cai siv luna-xa-pub hais kom ua (com.webos .lunasendpub). Qhov thib ob qhov tsis zoo yog cuam tshuam nrog qhov tseeb tias los ntawm kev hu rau API "luna://com.webos.notification/createAlert" nrog rau onclick, onclose lossis onfail tsis, koj tuaj yeem tso tawm ib tus neeg tuav haujlwm thiab, piv txwv li, hu rau Download Manager system. kev pabcuam, uas tsuas yog tso cai rau tso tawm cov ntawv thov tshwj xeeb los rub tawm thiab khaws cov ntaub ntawv tsis txaus ntseeg.

Tau qhov twg los: opennet.ru

Ntxiv ib saib