IOS 10.2.1 正式版推出 - iOS

Table of Contents

https://support.apple.com/en-us/HT207482

This document describes the security content of iOS 10.2.1.

iOS 10.2.1

Released January 23, 2017


Auto Unlock 自動解鎖問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:當Apple watch離開你的手時仍然會自動解鎖
Impact: Auto Unlock may unlock when Apple Watch is off the user's wrist

Description: A logic issue was addressed through improved state management.
CVE-2017-2352: Ashley Fernandez of raptAware Pty Ltd


Contacts 聯絡人問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意的聯絡人資料卡可能造成程式中止
Impact: Processing a maliciously crafted contact card may lead to unexpected
application termination

Description: An input validation issue existed in the parsing of contact
cards. This issue was addressed through improved input validation.
CVE-2017-2368: Vincent Desmurs (vincedes3)


Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges

Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2017-2370: Ian Beer of Google Project Zero


Kernel 內核
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:程式利用內核的特殊權限任意執行程式碼
Impact: An application may be able to execute arbitrary code with kernel
privileges

Description: A use after free issue was addressed through improved memory
management.
CVE-2017-2360: Ian Beer of Google Project Zero


libarchive 資料庫封存問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:打開惡意產生的封包可能導致程式碼任意執行
Impact: Unpacking a maliciously crafted archive may lead to arbitrary code
execution

Description: A buffer overflow issue was addressed through improved memory
handling.
CVE-2016-8687: Agostino Sarubbo of Gentoo


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A prototype access issue was addressed through improved
exception handling.
CVE-2017-2350: Gareth Heyes of Portswigger Web Security


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: Multiple memory corruption issues were addressed through
improved memory handling.
CVE-2017-2354: Neymar of Tencent's Xuanwu Lab (tencent.com) working with
Trend Micro's Zero Day Initiative
CVE-2017-2362: Ivan Fratric of Google Project Zero
CVE-2017-2373: Ivan Fratric of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: A memory initialization issue was addressed through improved
memory handling.
CVE-2017-2355: Team Pangu and lokihardt at PwnFest 2016


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致執行任何程式碼
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution

Description: Multiple memory corruption issues were addressed through
improved input validation.
CVE-2017-2356: Team Pangu and lokihardt at PwnFest 2016
CVE-2017-2369: Ivan Fratric of Google Project Zero
CVE-2017-2366: Kai Kang of Tencent's Xuanwu Lab (tencent.com)


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A validation issue existed in the handling of page loading. This
issue was addressed through improved logic.
CVE-2017-2363: lokihardt of Google Project Zero
CVE-2017-2364: lokihardt of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:惡意網站可以打開彈出式視窗
Impact: A malicious website can open popups

Description: An issue existed in the handling of blocking popups. This was
addressed through improved input validation.
CVE-2017-2371: lokihardt of Google Project Zero


WebKit 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:處理惡意網站內容可能導致別的來源的資料流出
Impact: Processing maliciously crafted web content may exfiltrate data
cross-origin

Description: A validation issue existed in the handling of variable handling.
This issue was addressed through improved validation.
CVE-2017-2365: lokihardt of Google Project Zero


WiFi 問題
Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch
6th generation and later
影響:有啟動鎖定的裝置可以在操作下短暫的顯示首頁
Impact: An activation-locked device can be manipulated to briefly present the
home screen

Description: An issue existed with handling user input that caused a device
to present the home screen even when activation locked. This was addressed
through improved input validation.
CVE-2017-2351: Sriram (@Sri_Hxor) of Primefort Pvt. Ltd., Hemanth Joseph

--

All Comments

Kelly avatarKelly2017-01-28
TL;DR
Edith avatarEdith2017-01-31
不要上來丟臉了好嗎 你懂英文嗎
Steve avatarSteve2017-02-03
我英文素質低落
Isabella avatarIsabella2017-02-06
可以桶他嗎?
Edith avatarEdith2017-02-09
貼這幹嘛
Adele avatarAdele2017-02-13
iOS 10.2.1 的更新內容啊......
Franklin avatarFranklin2017-02-18
貼上來沒翻譯沒解釋 洗文喔
Franklin avatarFranklin2017-02-19
這個版是怎麼回事......
Quanna avatarQuanna2017-02-22
複製貼上誰都會,內文完全沒有個人意見、看法或說明見
Barb Cronin avatarBarb Cronin2017-02-26
板規6
Frederic avatarFrederic2017-02-26
.
Tracy avatarTracy2017-03-02
板龜6c
Iris avatarIris2017-03-02
都用這麼久的ptt了,難道不知道不行複製貼上嗎?
Suhail Hany avatarSuhail Hany2017-03-05
Oliver avatarOliver2017-03-06
噓你才怎麼了 發文不看版規
Oliver avatarOliver2017-03-08
快推不然以為我們不懂英文
Kumar avatarKumar2017-03-13
喔好棒棒喔你懂英文好厲害
Linda avatarLinda2017-03-16
我竟然看得懂......(噗~~~)
Rosalind avatarRosalind2017-03-21
Ctrl C + V 這樣也好意思一篇?
Andrew avatarAndrew2017-03-21
所以鬧鐘修好了沒?(x
Elizabeth avatarElizabeth2017-03-25
呃...
Elma avatarElma2017-03-27
複製貼上的被噓 反觀只貼張截圖就沒問題 廠廠
Noah avatarNoah2017-03-29
我才想問你是怎麼回事咧....
Skylar Davis avatarSkylar Davis2017-04-01
所以勿擾模式修好了沒?
Hedwig avatarHedwig2017-04-02
什麼叫他媽的驚喜
Daniel avatarDaniel2017-04-04
87
Anonymous avatarAnonymous2017-04-06
欺負我沒讀書喔~ 奇怪捏
Carol avatarCarol2017-04-08
推推
Andy avatarAndy2017-04-09
好啦幫搬運工補個血
Bennie avatarBennie2017-04-11
好可憐 幫你QQ 果粉不意外
Skylar DavisLinda avatarSkylar DavisLinda2017-04-15
你貼這樣我直接去蘋果不是更快
Carol avatarCarol2017-04-16
我傻眼XD
Blanche avatarBlanche2017-04-17
跟上一篇一樣半斤八兩,反正這邊根本沒版主,貼什麼有差嗎
Isabella avatarIsabella2017-04-19
我覺得有東西看不用去找,不錯啊
Madame avatarMadame2017-04-22
為什麼要噓?
Hardy avatarHardy2017-04-27
第一篇是情報,第二篇是洗文
Brianna avatarBrianna2017-04-29
這個版素質真的越來越差了
Hedy avatarHedy2017-04-30
這篇看似洗文章 其實重要性不亞於更新的情報
Gilbert avatarGilbert2017-05-03
個人認為安全性更新非常重要 必須像有原po這樣的好人
跟大家分享
Agnes avatarAgnes2017-05-06
這篇至少把連結貼出來 情報量比上一篇多太多了
Elizabeth avatarElizabeth2017-05-08
而且這次的安全性更新本來就是10.2.1的核心
Caroline avatarCaroline2017-05-09
這個板的板主真的好好當喔
Todd Johnson avatarTodd Johnson2017-05-11
.
Yedda avatarYedda2017-05-13
推個 補血
Callum avatarCallum2017-05-13
自己能力不好,不能去加強嗎,拿別人用好的資料來看,
不就代表自己懶得找懶得看,比別人貼一張好多了吧
Yuri avatarYuri2017-05-17
推推
Tracy avatarTracy2017-05-20
原PO辛苦啦,這篇比前一篇來的實用
Daniel avatarDaniel2017-05-23
前面的推文是什麼情形..
Bethany avatarBethany2017-05-24
推 很有用的情報文
Zora avatarZora2017-05-26
本來是原文純複製貼上
Emily avatarEmily2017-05-28
前面想帶風向?
Una avatarUna2017-05-30
我莫名奇妙被噓,明明這是比較重要的資訊....
Agnes avatarAgnes2017-06-02
推回來,明明前面那篇才沒用,這篇很多資訊。
Hamiltion avatarHamiltion2017-06-06
幫推
Kristin avatarKristin2017-06-09
幫推 有翻譯了
Dinah avatarDinah2017-06-10
上面是在噓什麼?
Steve avatarSteve2017-06-12
謝謝分享
John avatarJohn2017-06-14
隨便都比一堆廢文好
Rachel avatarRachel2017-06-16
推補翻譯
Kumar avatarKumar2017-06-18
Jake avatarJake2017-06-18
推翻譯
Zanna avatarZanna2017-06-23
Audriana avatarAudriana2017-06-25
前面那篇什麼都沒提到 這篇內容都有 有啥好虛..
Barb Cronin avatarBarb Cronin2017-06-28
Steve avatarSteve2017-07-01
推好心翻譯
James avatarJames2017-07-04
噓的人是因爲一開始沒翻譯,看不懂才噓的吧
Olga avatarOlga2017-07-06
看了噓的幾樓,真是笑死我了,原來腦袋可以這樣用
Callum avatarCallum2017-07-08
原po一開始只有將英文全部貼上,翻譯是後來才加的
Doris avatarDoris2017-07-08
推推
Franklin avatarFranklin2017-07-10
一開始就算只有英文 至少有付官方連結
我想不管怎樣都比截圖好
Susan avatarSusan2017-07-14
語言不合
Thomas avatarThomas2017-07-18
Sandy avatarSandy2017-07-22
再推一次 前面噓的真的很有趣
Barb Cronin avatarBarb Cronin2017-07-27
Connor avatarConnor2017-07-28
補血。上面不知道在噓什麼
Lauren avatarLauren2017-07-31
幫補血
Hazel avatarHazel2017-08-04
幫補血,原PO別介意,就是有一堆沒知識的秀下限
Candice avatarCandice2017-08-05
Jake avatarJake2017-08-08
?噓啥
Xanthe avatarXanthe2017-08-13
Ursula avatarUrsula2017-08-14
補血
Mary avatarMary2017-08-15
辛苦原PO。
Madame avatarMadame2017-08-19
推 前面的噓文很有事
Rachel avatarRachel2017-08-21
Rosalind avatarRosalind2017-08-24
幫補一發
Rachel avatarRachel2017-08-24
補血
Elvira avatarElvira2017-08-26
Lily avatarLily2017-08-27
Suhail Hany avatarSuhail Hany2017-08-30
前面的還好嗎...?這明明很有用啊
Ethan avatarEthan2017-09-04
一堆玻璃心看不懂亂噓,上一篇怎不噓?助推一個
Lauren avatarLauren2017-09-07
怪了 國民教育沒教英文嗎?
Lauren avatarLauren2017-09-08
補血
Elma avatarElma2017-09-10
前面都玻璃心喔 幫補
Zanna avatarZanna2017-09-11
補血
John avatarJohn2017-09-14
﴿
Oscar avatarOscar2017-09-14
推推
Irma avatarIrma2017-09-18
補血 推
Madame avatarMadame2017-09-23
前面的噓文有什麼事
Blanche avatarBlanche2017-09-27
第一篇那樣才誇張吧
Carol avatarCarol2017-09-28
從古至今語言是造成戰爭的重要關鍵XD
Kyle avatarKyle2017-09-30
笑看那些英文不好亂炮的
Adele avatarAdele2017-10-01
前面那些人亂噓在秀下限?自己看不懂就亂噓別人廠廠
Anonymous avatarAnonymous2017-10-03
補推
Erin avatarErin2017-10-07
覺得很有幫助阿
Erin avatarErin2017-10-08
OuO 好兇
Odelette avatarOdelette2017-10-09
噓文的人,你們還好嗎?
Odelette avatarOdelette2017-10-10
滿好的
Caitlin avatarCaitlin2017-10-11
這篇充實多了,感謝原po分享
Carolina Franco avatarCarolina Franco2017-10-12
因為前面的看不懂英文 哈哈
Ethan avatarEthan2017-10-14
一堆看不懂英文在悲憤噓文
Eartha avatarEartha2017-10-19
蠻好的文啊
Elizabeth avatarElizabeth2017-10-19
英文都看不懂,一定是9.2