$B%;%-%e%j%F%#%[!<%k(B memo

Last modified: Wed Feb 8 17:48:21 2012 +0900 (JST)
$BC;=L(B URL: http://goo.gl/pwSG$B!!(BQR $B%3!<%I(B: http://goo.gl/pwSG.qr


$B!!(BSecurity Watch $B$5$s$,E9$8$^$$$5$l$F$7$^$C$?$N$G!"(B $B8D?M$GDI$$$+$1$F$_$k%F%9%H$G$9!#(B $BHwK:O?$H$7$F=q$$$F$*$/$D$b$j$J$N$G!"(B Security Watch $B$5$s$N$h$&$J>\:Y$J$b$N$G$O$"$j$^$;$s!#(B $B4pK\E*$J%?!<%2%C%H$O(B UNIX$B!"(BWindows$B!"(BMac OS (priority $B=g(B) $B$H$7$^$9!#(B $B$^$?!"$3$N%Z!<%8$NFbMF$O$I$N%Z!<%8$K$bA}$7$FL5J]>Z$G$"$k$3$H$r@k8@$7$F$*$-$^$9!#A4$F$N>pJs$,=8$^$C$F$$$k$o$1$b$"$j$^$;$s!#(B

$B!!$3$3$K:\$;$k>pJs$K$D$$$F$O!"2DG=$J8B$j(B 1 $BpJs8;$X$N%j%s%/$r:n@.$7$F$*$-$^$9!#(B $B3F<+$G(B 1 $BpJs8;$NFbMF$r3NG'$7$F$/$@$5$$!#(B $B$3$N%Z!<%8$NFbMF$r$/$l$0$l$b1-0{$_$K$7$J$$$h$&$K!#(B $B4V0c$$$rH/8+$5$l$?J}!"5-:\$5$l$F$$$J$$>pJs$r$4B8CN$NJ}!"$<$R(B$B$*$7$($F$/$@$5$$(B$B!#$h$m$7$/$*4j$$$$$?$7$^$9!#(B

$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B!!(B[ $BDjHV>pJs8;(B ] $B!!2a5n$N5-;v(B: 2012 | 2011 | 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[SCAN Security Wire NP Prize 2001]

$B!V(BScan Security Wire$B!W(B $BSCAN Security Wire NP Prize 2001 $B$r^(B$B$7$^$7$?!#(B

$B!!(B

$B!V%M%C%H%i%s%J!o=,^$r!"%Y%9%H!&%*%V!&>o=,^$r^$7$^$7$?!#(B


www.iraqbodycount.org www.iraqbodycount.org

$BI|4)%j%/%(%9%H
$B%8%'%$%`%:(B.$B#F(B.$B%@%K%,%s!V(B $B?7!&@oAh$N%F%/%N%m%8!<(B$B!W(B($B8=:_(B45$BI<(B)
$BCf;3?.90!V(B$B%=%U%H%&%'%"$NK!E*J]8n(B$B!W(B ($B8=:_(B119$BI<(B) ($B%*%s%G%^%s%I9XF~2D(B)
$BN&0f;0O:Lu!&JT!V(B$B%Y%H%J%`5"4TJ<$N>Z8@(B$B!W(B ($B8=:_(B109$BI<(B)
$BNS9nL@!V(B$B%+%U%+%9$N>.$5$J9q!!%A%'%A%'%sFHN)1?F0;OKv(B$B!W(B ($B8=:_(B172$BI<(B)
$B2f$i9_Iz$;$:!]%5%$%Q%s6L:U@o$N685$$H?? ($B8=:_(B136$BI<(B)

RSS $B$KBP1~$7$F$_$^$7$?!#(B $B>.%M%?$O4^$^$l$F$$$^$;$s!#!V@/<#$M$?%&%<%'!W$H$$$&?M$O(B RSS $B%Y!<%9$GFI$`$H9,$;$K$J$l$k$G$7$g$&(B ($B%&%6$/$J$$?M$O(B $B$3$C$A$N(B RSS $B$,$h$$$+$b$7$l$^$;$s(B)$B!#(B RSS 1.0 $B$G$9$N$G!"$"$/$^$G(B RDF Site Summary $B$G$9!#(B $B8=:_$O(B Really Simple Syndication $B$K$OBP1~$7$F$$$^$;$s!#(B
$B:#$9$0(B Really Simple Syndication $B$,$[$7$$?M$O!"$N$$$s$5$s$K$h$k(B Web $B%5%$%H$N(B RSS $B$r>! $B$r;2>H$7$F$/$@$5$$!#(B($B$N$$$s$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)

$B<BMQ(B SSH $BBh(B2$BHG(B: $B%;%-%e%
2 $B:~$,=P$^$7$?!#(B$B%*%i%$%j!<$GCmJ8$7(B$B!"Hw9MMw$K!VI,$:(B2$B:~$G$"$k$3$H!W$H=q$/$H(B 2 $B:~$r3N

$B"#(B 2012.02.08

$B"#(B $B$$$m$$$m(B (2012.02.08)
(various)

$B"#(B RealNetworks, Inc.$B!"%;%-%e%j%F%#@H
(RealNetworks, 2012.02.06)

$B!!(BWindows $BMQ$*$h$S(B Mac $BMQ$N(B RealPlayer $B$K!"G$0U$N%3!<%I$N7$/7g4Y!#(B Windows $BMQ(B RealPlayer 15.02.71$B!"(BMac $BMQ(B RealPlayer 12.0.0.1703 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B Ghost Domain Names: Revoked Yet Still Resolvable
(ISC, 2012.02.07)

$B!!(BBIND 9 $B$K7g4Y!#%I%a%$%s$,%l%8%9%H%j$+$i:o=|$5$l$F$b(B cache $B$5$lB3$1$F$7$^$&!#(BCVE-2012-1033

$B!!2sHrJ}K!$J$7!#(Bpatch $B$O8=:_%F%9%HCf!#(B


$B"#(B 2012.02.07

$B"#(B $BDI5-(B

Critical PHP Remote Vulnerability Introduced in Fix for PHP Hashtable Collision DOS

$B!!(BDebian $BMQ(B fix$B!"(Blenny $BMQ$N%Q%C%1!<%8$bMQ0U$5$l$?;v$rDI5-!#(BScientific Linux $B=P$?$N$G=$@5!#(B FreeBSD ports $B$,(B 5.3.10 $B$K$J$C$?$N$G=$@5!#(B

About the security content of OS X Lion v10.7.3 and Security Update 2012-001

$B!!(BMac OS X 10.6.8 $BMQ$KIT6q9g$,H/@8$7!"=P$7D>$7$K$J$C$F$$$?!#(B Rosetta $B$GIT6q9g$,H/@8$7$?LOMM!#(B ImageIO $B4XO"$N%;%-%e%j%F%#=$@5$r:o=|$7$?$=$&$@!#(BCVE-2011-0241 $B$,$=$l$_$?$$!#(B Lion $BMQ(B (10.7.3) $B$K$OLdBj$J$7!#(B

PHP 5.3.9 Released!

$B!!(Blibxslt $B$N7o(B Bug #54446 - Arbitrary file creation via libxslt 'output' extension (PHP.net) (CVE-2012-0057) $B$b(B PHP 5.3.9 $B$G=$@5$5$l$F$$$k!#(B

Microsoft 2012 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS12-006 SSL/TLS $B$N@H\$7$$2r@b(B ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2012.01.29)


$B"#(B 2012.02.06

$B"#(B $BDI5-(B

$B"#(B $B$$$m$$$m(B (2012.02.06)
(various)


$B"#(B 2012.02.05


$B"#(B 2012.02.03

$B"#(B $BDI5-(B

Microsoft 2012 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BWindows Media Player$B$N(BMIDI$B%U%!%$%k=hM}$K$*$1$k@HZ%l%]!<%H(B (NTT$B%G!<%?@hC<5;=Q(B, 2012.01.30)

Critical PHP Remote Vulnerability Introduced in Fix for PHP Hashtable Collision DOS

$B!!$3$N7g4Y$O(B PHP 5.3.10 $B$G=$@5$5$l$?$=$&$G$9!#4XO"(B:

About the security content of OS X Lion v10.7.3 and Security Update 2012-001

Effective DoS attacks against Web Application Plattforms ? #hashDoS [UPDATE2]

$B!!(BOracle $BJ}LL(B (WebLogic, iPlanet, Containers for J2EE):

$B"#(B Bugzilla 4.2rc1, 4.0.3, 3.6.7, and 3.4.13 Security Advisory
(Bugzilla, 2012.01.31)

$B!!(BBugzilla 4.2rc1 / 4.0.3 / 3.6.7 / 3.4.1 $BEP>l!#Hs(B ASCII $BJ8;z$r4^$`EE;R%a!<%k%"%I%l%9$r@5$7$/GS=|$G$-$F$$$J$+$C$?7g4Y(B CVE-2012-0448 $B$H(B Cross-Site Request Forgery $B$J7g4Y(B CVE-2012-0440 $B$N=$@5$,4^$^$l$k!#(B


$B"#(B 2012.02.02

$B"#(B Critical PHP Remote Vulnerability Introduced in Fix for PHP Hashtable Collision DOS
(thexploit.com, 2012.02.01)

$B!!(BEffective DoS attacks against Web Application Plattforms ? #hashDoS [UPDATE2] $B$NBP1~$N$?$a$K(B PHP 5.3.9 $B$KDI2C$5$l$?%3!<%I$K!"(Bremote $B$+$i$N%3!<%I$N7$/JL$N7g4Y$,$"$k$H$$$&;XE&!#(B CVE-2012-0830

2012.02.03 $BDI5-(B:

$B!!$3$N7g4Y$O(B PHP 5.3.10 $B$G=$@5$5$l$?$=$&$G$9!#4XO"(B:

2012.02.07 $BDI5-(B:

$B!!(BDebian $BMQ(B fix$B!"(Blenny $BMQ$N%Q%C%1!<%8$bMQ0U$5$l$?;v$rDI5-!#(B Scientific Linux $B=P$?$N$G=$@5!#(B FreeBSD ports $B$,(B 5.3.10 $B$K$J$C$?$N$G=$@5!#(B

$B"#(B About the security content of OS X Lion v10.7.3 and Security Update 2012-001
(Apple, 2012.02.01)

$B!!(BMac OS X 10.7.3 $B$*$h$S!"(B10.6.8 $BMQ%;%-%e%j%F%#99?7(B 2012-001 $B=P$F$^$9!#(B $B=$@5$5$l$?%;%-%e%j%F%#7g4Y$O(B 49 $B

$B!!(BCVE-2010-1637 CVE-2010-2813 CVE-2010-4554 CVE-2010-4555 CVE-2011-0200 CVE-2011-0241 CVE-2011-1148 CVE-2011-1167 CVE-2011-1657 CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 CVE-2011-1938 CVE-2011-2023 CVE-2011-2192 CVE-2011-2202 CVE-2011-2204 CVE-2011-2483 CVE-2011-2895 CVE-2011-2937 CVE-2011-3182 CVE-2011-3189 CVE-2011-3246 CVE-2011-3248 CVE-2011-3249 CVE-2011-3250 CVE-2011-3252 CVE-2011-3256 CVE-2011-3267 CVE-2011-3268 CVE-2011-3328 CVE-2011-3348 CVE-2011-3389 CVE-2011-3422 CVE-2011-3441 CVE-2011-3444 CVE-2011-3446 CVE-2011-3447 CVE-2011-3448 CVE-2011-3449 CVE-2011-3450 CVE-2011-3452 CVE-2011-3453 CVE-2011-3457 CVE-2011-3458 CVE-2011-3459 CVE-2011-3460 CVE-2011-3462 CVE-2011-3463

2012.02.03 $BDI5-(B:

$B!!4XO"(B:

2012.02.07 $BDI5-(B:

$B!!(BMac OS X 10.6.8 $BMQ$KIT6q9g$,H/@8$7!"=P$7D>$7$K$J$C$F$$$?!#(B Rosetta $B$GIT6q9g$,H/@8$7$?LOMM!#(B ImageIO $B4XO"$N%;%-%e%j%F%#=$@5$r:o=|$7$?$=$&$@!#(B CVE-2011-0241 $B$,$=$l$_$?$$!#(B Lion $BMQ(B (10.7.3) $B$K$OLdBj$J$7!#(B

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2012.01.29)

$B!!(B Apache HTTP Server 2.2.22 Released (Apache, 2012.01.31)$B!#@5<0HG=P$^$7$?$N$G!"$_$J$5$s99?7$7$^$;$&!#(B


$B"#(B 2012.02.01

$B"#(B $B$$$m$$$m(B (2012.02.01)
(various)

$B"#(B $BDI5-(B

$B"#(B Firefox 10.0 / 10.0 ESR / 3.6.26$B!"(BThunderbird 10.0 / 10.0 ESR / 3.1.18$B!"(BSeaMonkey 2.7 $BEP>l(B
(mozilla.jp, 2012.02.01)

$B!!(BFirefox 10.0 / 10.0 ESR / 3.6.26$B!"(BThunderbird 10.0 / 10.0 ESR / 3.1.18$B!"(BSeaMonkey 2.7 $B=P$F$^$9!#(BESR $BHGEP>l$KH<$$!"(BFirefox 3.6 / Thunderbird 3.1 $B$O(B 2012.04.24 $B$G%5%]!<%H=*N;$@$=$&$G$9!#(B

$B!!%;%-%e%j%F%#=$@50lMw!#(B

SA $BHV9f(B $B=EMWEY(B $B35MW(B F 10.0 F 3.6.26 T 10.0 T 3.1.18 S 2.7 $BFC5-;v9`(B
MFSA 2012-01 $B:G9b(B $BMM!9$J%a%b%j0BA4@-$NLdBj(B (rv:10.0/ 1.9.2.26) X X X X X CVE-2012-0442 CVE-2012-0443
MFSA 2012-02 $BDc(B $B2aEY$K5vMF$5$l$F$$$?(B IPv6 $B%j%F%i%k9=J8$K$h$kLdBj(B X X F 7.0 / T 7.0 / S 2.4 $B$G=$@5:Q!#(BCVE-2011-3670
MFSA 2012-03 $B9b(B iframe $BMWAG$,(B name $BB0@-$rDL$8$FB>%I%a%$%s$+$iCV$-49$($i$l$k(B X X X CVE-2012-0445
MFSA 2012-04 $B:G9b(B nsDOMAttribute $B$N;R%N!<%I$r:o=|8e$b;2>H$G$-$F$7$^$&(B X X X X X CVE-2011-3659
MFSA 2012-05 $B:G9b(B $B?.Mj$G$-$J$$%*%V%8%'%/%H$r8F$S=P$7$?%U%l!<%`%9%/%j%W%H$,%;%-%e%j%F%#%A%'%C%/$r1*2s$9$k(B X X X CVE-2012-0446
MFSA 2012-06 $B9b(B $B%"%$%3%s2hA|$N%(%s%3!<%I;~$KDI2C$5$l$kL$=i4|2=%a%b%j$K$h$k>pJs$N8mI=<((B X X X CVE-2012-0447
MFSA 2012-07 $B:G9b(B Ogg Vorbis $B%U%!%$%k%G%3!<%I;~$N@x:_E*$J%a%b%jGK2u(B X X X X X CVE-2012-0444
MFSA 2012-08 $B:G9b(B $BIT@5$KKd$a9~$^$l$?(B XSLT $B%9%?%$%k%7!<%H$K$h$k%/%i%C%7%e(B X X X X X CVE-2012-0449

$B2a5n$N5-;v(B: 2012 | 2011 | 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[$B%;%-%e%j%F%#%[!<%k(B memo]