$B%;%-%e%j%F%#%[!<%k(B memo

Last modified: Tue Sep 7 17:29:49 2010 +0900 (JST)


$B!!(BSecurity Watch $B$5$s$,E9$8$^$$$5$l$F$7$^$C$?$N$G!"(B $B8D?M$GDI$$$+$1$F$_$k%F%9%H$G$9!#(B $BHwK:O?$H$7$F=q$$$F$*$/$D$b$j$J$N$G!"(B Security Watch $B$5$s$N$h$&$J>\:Y$J$b$N$G$O$"$j$^$;$s!#(B $B4pK\E*$J%?!<%2%C%H$O(B UNIX$B!"(BWindows$B!"(BMac OS (priority $B=g(B) $B$H$7$^$9!#(B $B$^$?!"$3$N%Z!<%8$NFbMF$O$I$N%Z!<%8$K$bA}$7$FL5J]>Z$G$"$k$3$H$r@k8@$7$F$*$-$^$9!#A4$F$N>pJs$,=8$^$C$F$$$k$o$1$b$"$j$^$;$s!#(B

$B!!$3$3$K:\$;$k>pJs$K$D$$$F$O!"2DG=$J8B$j(B 1 $BpJs8;$X$N%j%s%/$r:n@.$7$F$*$-$^$9!#(B $B3F<+$G(B 1 $BpJs8;$NFbMF$r3NG'$7$F$/$@$5$$!#(B $B$3$N%Z!<%8$NFbMF$r$/$l$0$l$b1-0{$_$K$7$J$$$h$&$K!#(B $B4V0c$$$rH/8+$5$l$?J}!"5-:\$5$l$F$$$J$$>pJs$r$4B8CN$NJ}!"$<$R(B$B$*$7$($F$/$@$5$$(B$B!#$h$m$7$/$*4j$$$$$?$7$^$9!#(B

$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B!!(B[ $BDjHV>pJs8;(B ] $B!!2a5n$N5-;v(B: 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[SCAN Security Wire NP Prize 2001]

$B!V(BScan Security Wire$B!W(B $BSCAN Security Wire NP Prize 2001 $B$r^(B$B$7$^$7$?!#(B

$B!!(B

$B!V%M%C%H%i%s%J!o=,^$r!"%Y%9%H!&%*%V!&>o=,^$r^$7$^$7$?!#(B


www.iraqbodycount.org www.iraqbodycount.org

$BI|4)%j%/%(%9%H
$B%8%'%$%`%:(B.$B#F(B.$B%@%K%,%s!V(B $B?7!&@oAh$N%F%/%N%m%8!<(B$B!W(B($B8=:_(B44$BI<(B)
$BCf;3?.90!V(B$B%=%U%H%&%'%"$NK!E*J]8n(B$B!W(B ($B8=:_(B119$BI<(B) ($B%*%s%G%^%s%I9XF~2D(B)
$B%j%G%k!&%O!<%H!V(B$B@oN,O@!!4V@\E*%"%W%m!<%A(B$B!W(B ($B?7Lu=P$^$7$?(B: $B>e(B $B2<(B)
$BN&0f;0O:Lu!&JT!V(B$B%Y%H%J%`5"4TJ<$N>Z8@(B$B!W(B ($B8=:_(B108$BI<(B)
$BNS9nL@!V(B$B%+%U%+%9$N>.$5$J9q!!%A%'%A%'%sFHN)1?F0;OKv(B$B!W(B ($B8=:_(B176$BI<(B)

RSS $B$KBP1~$7$F$_$^$7$?!#(B $B>.%M%?$O4^$^$l$F$$$^$;$s!#!V@/<#$M$?%&%<%'!W$H$$$&?M$O(B RSS $B%Y!<%9$GFI$`$H9,$;$K$J$l$k$G$7$g$&(B ($B%&%6$/$J$$?M$O(B $B$3$C$A$N(B RSS $B$,$h$$$+$b$7$l$^$;$s(B)$B!#(B RSS 1.0 $B$G$9$N$G!"$"$/$^$G(B RDF Site Summary $B$G$9!#(B $B8=:_$O(B Really Simple Syndication $B$K$OBP1~$7$F$$$^$;$s!#(B
$B:#$9$0(B Really Simple Syndication $B$,$[$7$$?M$O!"$N$$$s$5$s$K$h$k(B Web $B%5%$%H$N(B RSS $B$r>! $B$r;2>H$7$F$/$@$5$$!#(B($B$N$$$s$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)

$B<BMQ(B SSH $BBh(B2$BHG(B: $B%;%-%e%
2 $B:~$,=P$^$7$?!#(B$B%*%i%$%j!<$GCmJ8$7(B$B!"Hw9MMw$K!VI,$:(B2$B:~$G$"$k$3$H!W$H=q$/$H(B 2 $B:~$r3N

2010.09.06 20:00$B!A(B22:00$B!"$3$N(B web $B%Z!<%8$O1\Mw$G$-$J$/$J$j$^$9!#(B [$B>\:Y(B]

$B"#(B 2010.09.06


$B"#(B 2010.09.05

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 8 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!$$$^$4$mDI5-!#(B

MS10-047 - $B=EMW(B: Windows $B%+!<%M%k$N@H:3J$5$l$k(B (981852)

$B!!(BWindows XP 32bit / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B Windows $B%+!<%M%k$K(B 3 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$d(B DoS $B967b$,2DG=!#(B Windows XP 64bit / Server 2003 $B$K$O$3$N7g4Y$O$J$$!#(B

  • Windows $B%+!<%M%k$N%G!<%?=i4|2=$N@HCVE-2010-1888

    Windows XP 32bit $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Exploitability Index: 1

  • $B%+!<%M%k$N%@%V%k(B $B%U%j!<$N@HCVE-2010-1889

    Windows Vista / Server 2008 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Exploitability Index: 2

  • Windows $B%+!<%M%k(B $B$NITE,@Z$J8!>Z$N@HCVE-2010-1890

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(B local user $B$K$h$k(B DoS $B967b$,2DG=!#(B Exploitability Index: N/A

MS10-048 - $B=EMW(B: Windows $B%+!<%M%k%b!<%I(B $B%I%i%$%P!<$N@H:3J$5$l$k(B (2160329)

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B%+!<%M%k%b!<%I%I%i%$%P$K(B 5 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$d(B DoS $B967b$,2DG=!#(B

  • Win32k $B$N6-3&%A%'%C%/$N@HCVE-2010-1887

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k(B DoS $B967b$,2DG=!#(B Exploitability Index: N/A

  • Win32k $B$NNc30=hM}$N@HCVE-2010-1894

    Windows XP / Server 2003 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%W!<%k(B $B%*!<%P!<%U%m!<$N@HCVE-2010-1895

    Windows XP / Server 2003 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%f!<%6!Z$N@HCVE-2010-1896

    Windows XP / Server 2003 / Vista / Server 2008 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%&%#%s%I%&:n@.$N@HCVE-2010-1897

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

$B!!4XO"(B: MS10-048 an explanation of the Defense in Depth fixes (Microsoft Security Research & Defense, 2010.08.10)

MS10-049 - $B6[5^(B: SChannel $B$N@H

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B$N(B Secure Channel (SChannel) $B$K(B 2 $B$D$N7g4Y$,$"$j!"$J$j$9$^$7$dG$0U$N%3!<%I$N7$/!#(B

MS10-050 - $B=EMW(B: Windows $B%`!<%S!<(B $B%a!<%+!<$N@H

MS10-051 - $B6[5^(B: Microsoft XML $B%3%"(B $B%5!<%S%9$N@H

MS10-052 - $B6[5^(B: Microsoft MPEG Layer-3 $B%3!<%G%C%/$N@H

MS10-053 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (2183461)

$B!!(BIE 6 / 7 / 8 $B$K(B 6 $B$D$N7g4Y$,$"$j!">pJsO31L$dG$0U$N%3!<%I$N7$/!#(B

  • $B%$$Y%s%H(B $B%O%s%I%i!<$N%/%m%9(B $B%I%a%$%s$N@HCVE-2010-1258

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$7!"$+$D!V%^%&%9$r;HMQ$7$F%V%i%&%6!<%&%#%s%I%&$HBPOC$9$k!W$H>pJsO31L$,H/@8!#(B Exploitability Index: 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2556

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2557

    IE 6 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B6%9g>uBV$N%a%b%jGKB;$N@HCVE-2010-2558

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2559

    IE 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • HTML $B%l%$%"%&%H$N%a%b%jGKB;$N@HCVE-2010-2560

    IE 6 / 7 / $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

MS10-054 - $B6[5^(B: SMB $B%5!<%P!<$N@H

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BSMB $B%W%m%H%3%k

  • SMB $B$N%W!<%k(B $B%*!<%P!<%U%m!<$N@HCVE-2010-2550

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BSMB $B%W%m%H%3%kl9g$OG'>Z$OITMW!#(B Windows Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$G$O!"!V%Q%9%o!<%I%Y!<%9$N6&M-$,L58z!W$G$"$l$PG'>Z$OITMW!"$=$&$G$J$1$l$PG'>Z$,I,MW!#(B Exploitability Index: 2

    $B4XO"(B: MS10-054: Exploitability Details for the SMB Server Update (Microsoft Security Research & Defense, 2010.08.10)

  • SMB $B$NJQ?t$N8!>Z$N@HCVE-2010-2551

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B SMB $B%W%m%H%3%k

  • SMB $B$N%9%?%C%/>CHq$N@HCVE-2010-2552

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B SMB $B%W%m%H%3%k

MS10-055 - $B6[5^(B: Cinepak Codec $B$N@H

MS10-056 - $B6[5^(B: Microsoft Office Word $B$N@H

$B!!(BMicrosoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWorks 9 $B$K(B 4 $B$D$N7g4Y!#(B

  • Word $B$N%l%3!<%I$N2r@O$N@HCVE-2010-1900

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWorks 9 $B$K7g4Y!#(B Word $B%U%!%$%k$N=hM}$K7g4Y$,$"$j!"(B $B96N,(B Word $B%U%!%$%k$r3+$/$HG$0U$N%3!<%I$,

  • Word $B$N(B RTF $B7A<0$N2r@O%(%s%8%s$N%a%b%jGKB;$N@HCVE-2010-1901

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(B RTF $B7A<0%G!<%?$N2r@O$K7g4Y$,$"$j!"96N,(B RTF $B7A<0%G!<%?$K$h$C$FG$0U$N%3!<%I$,

  • Word $B$N(B RTF $B7A<0$N2r@O$N%P%C%U%!!<(B $B%*!<%P!<%U%m!<$N@HCVE-2010-1902

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(B RTF $B7A<0%G!<%?$N2r@O$K7g4Y$,$"$j!"96N,(B RTF $B7A<0%G!<%?$K$h$C$FG$0U$N%3!<%I$,

  • Word HTML $B%j%s%/%*%V%8%'%/%H$N%a%b%jGKB;$N@HCVE-2010-1903

    Microsoft Word 2002 (XP) / 2003$B!"(BWord Viewer $B$K7g4Y!#(B Word $B%U%!%$%k$N=hM}$K7g4Y$,$"$j!"96N,(B Word $B%U%!%$%k$r3+$/$HG$0U$N%3!<%I$,

MS10-057 - $B=EMW(B: Microsoft Office Excel $B$N@H

MS10-058 - $B=EMW(B: TCP/IP $B$N@H:3J$5$l$k(B (978886)

$B!!(BWindows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B TCP/IP $Be>:$,2DG=!#(B

  • IPv6 $B$N%a%b%jGKB;$N@HCVE-2010-1892

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B IPv6 $B

  • Windows $B%M%C%H%o!<%-%s%0$N@0?t$N%*!<%P!<%U%m!<$N@HCVE-2010-1893

    Windows Vista SP1 / Server 2008 gold / 7 / Server 2008 $B$K7g4Y!#(B $BF~NO%P%C%U%!!<$N=hM}$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Vista SP2 / Server SP2 $B$K$O$3$N7g4Y$O$J$$!#(B Exploitability Index: 1

MS10-059 - $B=EMW(B: $B%5!<%S%9$N%H%l!<%95!G=$N@H:3J$5$l$k(B (982799)

$B!!(BWindows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B $B%5!<%S%9$N%H%l!<%95!G=$K(B 2 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B

  • $B%l%8%9%H%j(B $B%-!<$N(B ACL $B$N%H%l!<%9$N@HCVE-2010-2554

    $B%f!<%6$,!V%5!<%S%9$N%H%l!<%95!G=$N%l%8%9%H%j(B $B%-!<$KIT@53N$J%"%/%;%9@)8f%j%9%H(B (ACL) $B$rG[CV$7$?>l9g!W$K!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B Exploitability Index: N/A

  • $B%H%l!<%9$N%a%b%jGKB;$N@HCVE-2010-2555

    $B%l%8%9%H%j$N=hM}$K7g4Y$,$"$j!"D9Bg$J%l%8%9%H%j$K$h$C$F8"8B>e>:$,2DG=!#(B Exploitability Index: 1

MS10-060 - $B6[5^(B: Microsoft .NET $B6&DL8@8l%i%s%?%$%`$*$h$S(B Microsoft Silverlight $B$N@H

$B!!(B.NET Framework 2.0 / 3.5$B!"(BSilverlight 2 / 3 $B$K(B 2 $B$D$N7g4Y!#(B

  • Microsoft Silverlight $B$N%a%b%jGKB;$N@HCVE-2010-0019

    Silverlight 3 $B$K7g4Y!#%]%$%s%?$N=hM}$K7g4Y$,$"$j!"(B $B96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • Microsoft Silverlight $B$*$h$S(B Microsoft .NET Framework CLR $B$N2>A[%a%=%C%I$N0QG$$N@HCVE-2010-1898

    .NET Framework 2.0 / 3.5$B!"(BSilverlight 2 / 3 $B$K7g4Y$,$"$j!"(B $B96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

Renegotiating TLS

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$O!"(B MS10-049 - $B6[5^(B: SChannel $B$N@H $B$rE,MQ$9$k$3$H$G!"(BRFC5746 $B$KBP1~$9$k!#(B


$B"#(B 2010.09.03

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 6 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(B$B%^%$%/%m%=%U%H&IJ$X$N1F6A$K$D$$$F(B ($BIY;N%<%m%C%/%9(B, 2010.09.01 $B99?7(B)$B!#(BApeosWare $BB&$G$NBP1~$,$h$&$d$/40N;!#(B


$B"#(B 2010.09.02

$B"#(B About the security content of iTunes 10
(Apple, 2010.09.02)

$B!!(BWindows $BHG$N(B iTunes 10 $B$K$O!"(BSafari 5.0.1 $B$G=$@5$5$l$?(B WebKit $B$N=$@5$,4^$^$l$F$$$k$=$&$G$9!#(B


$B"#(B 2010.09.01

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2269637) $B0BA4$G$J$$%i%$%V%i%j$N%m!<%I$K$h$j!"%j%b!<%H$G%3!<%I$,

$B!!4XO"(B:

$B"#(B $B$$$m$$$m(B (2010.09.01)
(various)


$B2a5n$N5-;v(B: 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[$B%;%-%e%j%F%#%[!<%k(B memo]
[$B;d$K$D$$$F(B]