$B%;%-%e%j%F%#%[!<%k(B memo - 2002.06

Last modified: Wed Feb 26 18:52:09 2003 +0900 (JST)


$B"#(B 2002.06.28

$B"#(B $BDI5-(B

$B!!(B2002.06.27 $B$N(B Pine Internet Security Advisory PINE-CERT-20020601: Remote buffer overflow in resolver code of libc $B$K$^$?DI5-$7$?!#(B bind 9 $B$rMxMQ$7$?2sHrJ}K!!#(B JPCERT/CC $BCm0U4-5/!#(B

$B"#(B Cisco Security Advisory: Scanning for SSH Can Cause a Crash
(bugtraq, Fri, 28 Jun 2002 01:00:00 +0900)

$B!!(BCISCO IOS$B!"(BPIX Firewall$B!"(BCatOS $B$,F0:n$9$k(B Catalyst 6000$B!"(BCisco 11000 Content Service Switch $B$KCisco Security Advisory: Multiple SSH Vulnerabilities $B$rE,MQ$7$?>l9g$K!"967bSSH CRC32 attack $B$r9T$&$H!"(BSSH $B%b%8%e!<%k$,(B CPU $B$r?)$$$^$/$C$F(B DoS $B>uBV$K$J$C$F$7$^$C$?$j!"$"$k$$$O(B reboot $B$7$F$7$^$C$?$j$9$k!#(B

$B!!(Bpatch $B$,$"$C$?$j$J$+$C$?$j$9$k$h$&$J$N$G!"$4MxMQ$N(B IOS $BEy$N%P!<%8%g%s$r$*3N$+$a$N>e$4BP1~$r!#(B

$B"#(B Acrobat reader 4.05/5.05 temp file insecurity
(bugtraq)

$B!!%U%!%$%k$N$D$/$jJ}$K$$$m$$$m$HLdBj$,$"$k$h$&$G!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.27 $B$N(B Pine Internet Security Advisory PINE-CERT-20020601: Remote buffer overflow in resolver code of libc $B$KDI5-$7$?!#(BNetBSD Advisory$B!"(Bbind 4.9.9/8.2.6/8.3.3 $BEP>l!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.27 $B$N(B CERT Advisory CA-2002-18 OpenSSH Vulnerabilities in Challenge Response Handling $B$KDI5-$7$?!#(BNetBSD, Kondara, RedHat $B$+$i$N(B Advisory$B!#(B


$B"#(B 2002.06.27

$B"#(B Pine Internet Security Advisory PINE-CERT-20020601: Remote buffer overflow in resolver code of libc
(freebsd-security ML, Wed, 26 Jun 2002 23:55:42 +0900)

$B!!(BFreeBSD, OpenBSD, NetBSD $B$K4^$^$l$k(B DNS resolver $B%3!<%I$K(B buffer overflow $B$9$k

$B!!(Blibc $B$rF~$l$+$($?$"$H$G!"(Bstatic link $B$5$l$F$$$k%3%^%s%I$O:n$j$J$*$9I,MW$,$"$k!#(B

$B!!(BNetBSD$B$N(Blibc$B$K%j%b!<%H$+$i$N%P%C%U%!%*!<%P!<%i%s$N4m81@-(B ($BB>(BUNIX$B$b(B) (slashdot.jp) $B$N(B $B$3$N5-;v(B $B$K$h$k$H!"(Bglibc $B$K$bF1$8LdBj$,$"$k$i$7$$!#(B

2002.06.28 $BDI5-(B:

2002.06.28 $BDI5-(B part 2:

$B!!$^$@$^$@>u67$O3HBg$7$=$&$G$9!#(B

2002.07.01 $BDI5-(B:

$B!!(Bsendmail $BOC$O0c$&OC$G$"$k$3$H$,L@3N$K$J$C$?$N$G5-=R$r%3%a%s%H%"%&%H$7$?!#(B

2002.07.02 $BDI5-(B:

2002.07.12 $BDI5-(B:

$B!!(BCA-2002-19 $B$,99?7$5$l$F$$$^$9!#(B

2002.07.23 $BDI5-(B:

2002.08.01 $BDI5-(B:

2002.08.29 $BDI5-(B:

$B!!(BDNS resolver$B$N@H$B!#(B resolver $BF~$l$+$($,I,MW!#(B

2002.10.02 $BDI5-(B:

$B!!(B
GNU glibc Information for VU#738331$B!#(B

2002-09-04 Roland McGrath <roland@redhat.com>

* resolv/nss_dns/dns-network.c (MAXPACKET): Increase minimum value from 1024 to 65536, to avoid buffer overrun.

$B$H$$$&$N$,2C$o$C$F$k$s$G$9$M!#(B

2002.12.26 $BDI5-(B:

$B!!(BJP1/Agent for Process Management$B$K4X$9$k%;%-%e%j%F%#LdBj$X$NBP1~(B$B!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.19 $B$N(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$KDI5-$7$?!#(BOracle$B!"(BIBM $B$N(B patch $B=P$^$7$?!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.13 $B$N(B MS02-029: $B%j%b!<%H%"%/%;%9%5!<%S%9$NEEOCD"$NL$%A%'%C%/$N%P%C%U%!$K$h$j%3!<%I$, $B$KDI5-$7$?!#(BMS02-029 patch $B$rE,MQ$9$k$H!"(BVPN $BMxMQ;~$K(B administrator $B8"8B$,I,MW$K$J$k$H$$$&I{:nMQ$,$"$k$=$&$@!#(B

$B"#(B $B%W%m%U%!%$%k%5!<%S%9$NL$%A%'%C%/$N%P%C%U%!$K$h$j(B Commerce Server $B$G%3!<%I$,
(Microsoft, Thu, 27 Jun 2002 10:35:13 +0900)

$B!!(BCommerce Server 2000/2002 $B$K(B 4 $B$D$N

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B 2002 $BG/(B 6 $B7n(B 26 $BF|(B Windows Media Player $BMQ$NN_@QE*$J=$@5%W%m%0%i%`(B (Q320920) (MS02-032)
(Microsoft, Thu, 27 Jun 2002 10:31:01 +0900)

$B!!(BWindows Media Player 6.4/7.1, Media Player for Windows XP $B$N!VN_@QE*$J=$@5%W%m%0%i%`!W!#4{CN$N!"0J2<$N(B 3 $B$D$NLdBj$,=$@5$5$l$k(B:

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

2002.07.26 $BDI5-(B:

$B!!(Bpatch $B$,:F%j%j!<%9$5$l$F$$$k!#(B $BN_@QE*=$@5%W%m%0%i%`$J$O$:$@$C$?$N$K!"(BMS01-056 $B$G=$@5$7$?%U%!%$%k$,7g$1$F$$$?LOMM!#@N(B MS01-056 $B$rE,MQ$7$?$3$H$,$"$C$??M$K$O4X78$J$$$,!"(B $B:G6a(B Windows $B$r?75,%$%s%9%H!<%k$7$?>l9g$J$I!"2a5n$K(B MS01-056 $B$rE,MQ$7$F$$$J$$?M$O!":F%Q%C%1!<%8$5$l$??7(B MS02-032 $B=$@5%W%m%0%i%`$r:FE,MQ$7$h$&!#(B

$B"#(B Excel for Windows $B$*$h$S(B Word for Windows $BMQ$NN_@QE*$J=$@5%W%m%0%i%`(B (Q324458) (MS02-031)
(NTBUGTRAQ, 20 Jun 2002 06:40:44 +0900)

$B!!(BExcel 2000/XP$B!"(BWord XP $BMQ$N!VN_@QE*$J=$@5%W%m%0%i%`!W!#4{CN$NLdBj$NB>$K(B 4 $B$D$NLdBj$,=$@5$5$l$F$$$k!#!V(BHTML $B%9%/%j%W%HExcel XP xml stylesheet problems (Georgi Guninski security advisory #55, 2002) $B$NOC(B (CAN-2002-0618)$B!#(B $B!V!V(BWord $B$N:9$79~$_0u:~5!G=!W$N@HA variant of "Word Mail Merge" vulnerability $B$NOC(B (CAN-2002-0619)$B!#(B

$B!!(Bpatch $B$,=P$F$$$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B CERT Advisory CA-2002-18 OpenSSH Vulnerabilities in Challenge Response Handling
(CERT/CC, June 26, 2002 23:31:29 (UTC-0400))

$B!!(BRe: Upcoming OpenSSH vulnerability $B$NOC$G$9$,!"$"$i$?$a$F!#(B

$B!!(BOpenSSH 2.3.1p1 $B!A(B 3.3 $B$^$G$K(B 2 $B$D$N

$B!!BP1~$9$k$K$O!"(BOpenSSH 3.4 $B0J>e$K0\9T$9$k$+!"$"$k$$$O(B Revised OpenSSH Security Advisory (adv.iss) $B$K<($5$l$F$$$k(B patch $B$rE,MQ$9$k!#(BOpenSSH 3.3 $B0J9_$G%G%U%)%k%HM-8z$H$J$C$F$$$k(B privilege separation $B5!G=$rMxMQ$9$k$H!">-MhH/@8$9$k$+$b$7$l$J$$LdBj$KBP$7$F$b:G>.8B$NHo32$G:Q$`2DG=@-$,9b$$$N$G!"(Bpatch $BE,MQ$G$O$J$/(B OpenSSH 3.4 $B0J9_$G$N0\9T$,K>$^$7$$!#$?$@$7!"(Bprivilege separation $B5!G=$,MxMQ$G$-$J$$(B OS $B$b$"$k$h$&$@!#(B

$B!!0\9T$"$k$$$O(B patch $B$rE,MQ$9$k$^$G$N2sHr:v$,$$$/$D$+B8:_$9$k!#(B

$B!!(Bpatch, fix package $BEy(B:

$B!!4XO">pJs(B:

2002.06.28 $BDI5-(B:

$B!!(BVulnerability Note VU#369347: OpenSSH vulnerabilities in challenge response handling $B$b;2>H!#(B

2002.07.01 $BDI5-(B:

2002.07.05 $BDI5-(B:


$B"#(B 2002.06.26

$B"#(B sendmail 8.12.5
(installer ML, Wed, 26 Jun 2002 14:25:06 +0900)

$B!!(Bsendmail 8.12.5 $B=P$F$$$^$9!#(B

SECURITY: The DNS map can cause a buffer overflow if the user specifies a dns map using TXT records in the configuration file and a rogue DNS server is queried. None of the sendmail supplied configuration files use this option hence they are not vulnerable. Problem noted independently by Joost Pol of PINE Internet and Anton Rang of Sun Microsystems.

$B$@$=$&$G$9!#(B

2003.02.26 $BDI5-(B:

$B!!(BCVE: CAN-2002-0906$B!#(B

$B"#(B $BO":\!'4IM}
(@IT, 2002.06.26)

$B!!(BJPCERT/CC $B$K$h$kO":\$NBh(B 1 $B2s!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.24 $B$N(B $B%;%-%e%j%F%#>e$N@H $B$KDI5-$7$?!#(BWinbiff $B$NBP:vHGEP>l!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.25 $B$N(B Re: Upcoming OpenSSH vulnerability $B$KDI5-$7$?!#(BDebian $B>pJs99?7!"(BOpenSSH 3.4 $BEP>lM=9p!#(B


$B"#(B 2002.06.25

$B"#(B $B%W%i%$%P%7!<%^!<%/OC(B
(memo ML)

$B!!(B$B:bCDK!?MF|K\>pJs=hM}3+H/6(2q%W%i%$%P%7!<%^!<%/;vL36I(B$B!#(B $B%W%i%$%P%7!<%^!<%/;HMQ5vBz;v6H$B!#(B

$B"#(B SecurIT-Advisory 2001-001: $B%/%m%9%5%$%H%9%/%j%W%F%#%s%0@Hu$H2r7h:v(B
(SecurIT, 2002.06.25)

$B!!(B1 $BG/$r7P$F$h$&$d$/8x3+!"$@$=$&$G$9!#(B

$B"#(B $BDI5-(B

$B!!(B2002.02.20 $B$N(B [memo:2996] $B!V(BVAIO$B!W$N=P2Y;~@_Dj$G?.Mj:Q$_%5%$%H$KFCDj%5%$%H$,EPO?$5$l$F$$$kLdBj(B $BD{@5(B $B$KDI5-$7$?!#9bLZ$5$s$K$h$k%U%)%m!<5-;v$rDI5-!#?7%b%8%e!<%k3+H/$K$h$j!"LdBj$N%5%$%H$O?.Mj:Q$_%5%$%H%>!<%s$+$i30$;$k$h$&$K$J$C$?LOMM!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.14 $B$N(B Web$B3+H/ $B$KDI5-$7$?!#9V1i;qNA$N8x3+$H(B INTERNET Watch $B5-;v$X$N%U%)%m!

$B"#(B $BAmL3>J(B $BEE;R?=@A!&FO=P%7%9%F%`$N>^L#4|8B(B
(memo ML)

$B!!(B[memo:3933] $B$*$h$S(B [memo:4255] $B$K$h$k$H!"(B$BAmL3>J!'EE;R?=@A!&FO=P%7%9%F%`(B $B$N%;%-%e%j%F%#E*$J$G$9!#(B

$B"#(B Internet Security Systems Security Alert Summary AS02-25
(ISS, 2002.06.24)

$B!!(BISS Security Alert Summary AS02-25 $B$G$9!#(B

$B"#(B Microsoft SQL Server $B4XO"(B
(various)

$B"#(B $BDI5-(B

$B!!(B2002.06.19 $B$N(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$KDI5-$7$?!#(BApache 1.3.x $BMQ$N(B official $B$J8DJL(B patch $BEP>l!"B>!#(B

$B"#(B $B>pJs%;%-%e%j%F%#%$%s%7%G%s%H$K78$kD4::(B
([connect24h:4235], Tue, 18 Jun 2002 13:26:56 +0900)

$B!!Ho323[$C$F!"9b$/$7$h$&$H;W$C$?$i$$$/$i$G$b9b$/$J$k$7$J$"!#$*$^$1$K!"?t;z$@$1FH$jJb$-$9$k$7!#%_%H%K%C%/;a$N$H$-$J$s$F!"!D!D!#(B

$B"#(B WindowsXP$B$N(B5/30$BLdBj$r9M$($k%Z!<%8(B
(slashdot.jp, Tuesday June 25, @02:45AM)

$B!!LdBj$,H/@8$9$k$N$O(B Warez $B$b$N!"$i$7$$!#$3$l$,K\Ev$J$i!"JQ$@$H8@$C$F$$$??M$O$_$J(B Warez $B;H$$$J$o$1$G!"$J$+$J$+%"%l%2!#(B

$B!!$1$C$-$g$/:#$@$K%$%s%9%H!<%k$G$-$F$J$$$7!D!D(B > XP$B!#F~

2002.09.19 $BDI5-(B:

$B!!(BFAQ $B$,99?7$5$l!"!V(BQ.$B$$$h$$$h(BWindowsXP$B$N(BSP1$B$,EP>l$7$^$7$?$,!"$3$N(BSP1$B$K$O%;%-%e%j%F%#%+%?%m%0$,L58z$K$J$i$J$$(BNT5INF.CA_$B$,F~$C$F$$$k$h$&$G$9!#(B $B$b$7$+$7$F$3$N%U%!%$%k$r;H$($P#57n(B30$BF|LdBj$O2sHr$G$-$k$N$G$O!)(B$B!W(B $B$,DI2C$5$l$F$$$k!#$&!<$`!D!D!#(B

$B!!F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B mod_ssl$B$N%P%/%U%#%C%/%9HG(B2.8.10-1.3.26$B$,%j%j!<%9(B
(memo ML, Tue, 25 Jun 2002 07:39:28 +0900)

$B!!(B[memo:4304] $B$NOC$N(B fix $B$,F~$C$F$$$k$H;W$$$^$9!#(B

2002.07.10 $BDI5-(B:

$B"#(B CISCO $B4XO"(B
(various)

$B"#(B UNIX fixes
(various)

SGI IRIX
TurboLinux
Kondara MNU/Linux
Sun Cobalt RaQ 4

$B"#(B $B!V(BMicrosoft(R) Software Update Services$B!WF|K\8lHG$r(B 6$B7n(B24$BF|!J7n!K$h$jDs6!3+;O(B
(PC Watch, 2002.06.24)

$B!!(BSUS $B$K$D$$$F$O(B SQL Server $B%f!<%6!<%0%k!<%W(B (PASSJ) $B$N(B $B%;%-%e%j%F%#J,2J2q(B ML $B$KM-MQ$J>pJs$,$"$k$h$&$G$9!#(B

$B"#(B Re: Upcoming OpenSSH vulnerability
(openssh-unix-announce ML, Tue, 25 Jun 2002 06:06:31 +0900)

$B!!:G?7(B 3.3 $B$r4^$`(B OpenSSH $B$K\:YITL@(B: $B8xI=$OMh=5(B) $B$KLdBj$,$"$j!"(Bremote $B$+$i(B exploit $B2DG=$JLOMM!#$?$@$7!"(BOpenSSH 3.3 $B$G(B UsePrivilegeSeparation yes $B$7$F$$$k>l9g!"

2002.06.26 $BDI5-(B:

2002.06.27 $BDI5-(B:

$B!!$D$E$-$O(B CERT Advisory CA-2002-18 OpenSSH Vulnerabilities in Challenge Response Handling $B$G!#(B


$B"#(B 2002.06.24

$B"#(B $BDI5-(B

$B!!(B2002.06.19 $B$N(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$KDI5-$7$?!#(BTurboLinux, Kondara, Debian $B$+$i(B fix package $BEP>l!#(B IBM, Oracle $B$N>pJs!#(B eEye $BEy$N

$B"#(B [memo:4294] Becky! 1.26.08$B0JA0$*$h$S(B2.00.08$B0JA0$K!"E:IU%U%!%$%k$,6/@)5/F0$5$l$k%;%-%e%j%F%#%[!<%k(B
(memo ML, Mon, 24 Jun 2002 10:28:09 +0900)

$B!!(B[memo:3953] Windows$BHG(BPostPet$B$K!"E:IU%U%!%$%k$,6/@)5/F0$5$l$k%;%-%e%j%F%#%[!<%k(B $B$HF1MM$K!"(BBecky!2 2.00.08 $B0JA0!"(BBecky! 1.26.08 $B0JA0$K$*$$$F$b!"E:IU%U%!%$%k$,E83+$5$l$k0LCV$,40A48GDj!"$"$k$$$OMF0W$K?dB,$G$-$k$?$a$K!"F1MM$N967b$rl9g$O967b$r2sHr$G$-$k!#(B 1.26.09 $B0J9_!"(B2.00.09 $B0J9_$G$O=$@5$5$l$F$$$k$N$G(B upgrade $B$9$l$P$h$$!#(B

$B!!(BBecky! $B$K$D$$$F$O!"(B$B%a!<%kK\J8$HE:IU%U%!%$%k$rJ,N%2DG=$K$7$?!V(BBecky! Internet Mail$B!W$N:G?7HG(B ($BAk$NEN(B) $B$H$$$&OC$b=P$F$$$k!#(B

$B"#(B $B%;%-%e%j%F%#>e$N@H
($B%?%l%3%_(B, Mon, 24 Jun 2002 12:26:17 +0900)

$B!!(BMAIL Direct$B!"(BHyperEdit$B!"(BKenm3 for Windows$B!"(BNet/PAD$B!"(BWinbiff V2.30$B0J9_(B $B$J$I$KEc:\$5$l$F$$$k(B ActiveX $B%3%s%H%m!<%k!"(BEditX $B$N(B 1.22 $B0JA0$K\:Y$OITL@$@$,!"!V(B$B0-0U$N$"$k(BWeb$B%5%$%H$K%"%/%;%9$9$k$H!"(BInternet Explorer$B$N%G%U%)%k%H$N@_Dj$G$O!"%f!<%6!<$,5$$,IU$+$J$$$&$A$K(BPC$B$N%U%!%$%k$,=q$-49$($i$l$F$7$^$&2DG=@-$,$"(B$B!W$C$?$N$@$=$&$@!#(BActiveX $B%3%s%H%m!<%k$J$N$G!"(Bscript $B7PM3$G%"%l%2$K$J$k!"$H$$$&O)@~$@$m$&$+!#(B

$B!!(BEditX 1.23 $B$G=$@5$5$l$F$$$k$N$GF~$l$+$($k!#>e5-(B EditX $BMxMQ%"%W%j$N(B web page $B$K$O(B EditX $B$K4X$9$k7Y9p$OB8:_$7$J$$$h$&$@!#(BWinBiff 2.3.4.8 $B$K$O(B EditX 1.2.1.0 $B$,4^$^$l$F$$$k$h$&$@!#(B

$B!!F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2002.06.26 $BDI5-(B:

$B!!(BWinbiff $B$NBP:vHGEP>l(B: Winbiff$B%f!<%6!<$N3'MM$X=EMW$J$*CN$i$;(B$B!#(BWinbiff V2.30 $B0J9_$N(B EditX $B$"$jHG$rMxMQ$7$F$$$k>l9g$KLdBj$K$J$k!"$H$5$l$F$$$k!#!V=$@5$7$?(B EditX $B$r:-Jq$7$?(B Winbiff $B%$%s%9%H!<%i!l$7$?$N$G!"$3$l$rMxMQ$7$F:F%$%s%9%H!<%k$9$l$P$h$$!#(B Winbiff V2.41 beta $B$K$D$$$F$b!"(Bbeta6 $B$G=$@5HG(B EditX $B$,F1:-$5$l$F$$$k!#(BIKEGAMI $B$5$s!"K'2l$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B IDS$B$NF3F~$K$h$kIT@5?/F~$N8!CN$H%M%C%H%o!<%/4IM}(B $BBh(B2$B2s!'(BSnort$B$rF3F~$9$k!!$=$N(B2
(ZDNet, 2002$BG/(B6$B7n(B18$BF|(B)

$B!!(BSnortSnarf$B!"(BRazorBack $B$N%$%s%9%H!<%k$H%k!<%k%;%C%H$N%A%e!<%K%s%0!#(B


$B"#(B 2002.06.21

$B"#(B Microsoft Software Update Services
(pml-security ML, Fri, 21 Jun 2002 17:48:50 +0900)

$B!!=P$^$7$?!#$_$s$J$G;n$7$^$7$g$&!#$C$F2K$,!D!D!#(B

$B"#(B Internet Security Systems Security Alert Summary AS02-24
(ISS, 2002.06.17)

$B!!(BISS Security Alert Summary AS02-24 $B$G$9!#(B

$B"#(B [pml-security,00435] CAPICOM : $B0E9f2=!"%O%C%7%e$,4JC1$K07$($k%3%s%]!<%M%s%H(B
(pml-security, Thu, 20 Jun 2002 18:44:52 +0900)

$B!!3N$+$KJXMx$=$&$G$9!#(B

$B"#(B Apache Tomcat $B4XO"(B
(bugtraq)

$B!!(BWindows 2000 $B>e$N(B Apache Tomcat 4.0.3 $B$K(B 2 $B$D$NLdBj!#(B $BJ*M}%Q%9L>$,O*8+$7$F$7$^$&B>!"(BDoS $B967b$re$N(B 4.1.3 beta $B$G$O=$@5$5$l$F$$$k$H$$$&!#(B

$B"#(B $B=;4p%M%C%H4XO"(B
(various)

$B!!$$$h$$$h2TF/$+$=$l$H$b1d4|$+!#$I$&$9$k$I$&$J$k=;4p%M%C%H!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.19 $B$N(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$KDI5-$7$?!#(B Vine Linux 2.1$B!"(BMiracle Linux $BMQ(B fix package$B!"(Bapache-ssl $B$N(B 1.3.26 $BBP1~HGEP>l!#(B


$B"#(B 2002.06.20

$B"#(B $BDI5-(B

$B!!(B2002.06.19 $B$N(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$KDI5-$7$?!#(Bexploit $B$5$C$=$/EP>l!#(BApache 1.x $B$KBP$7$F!"(B32bit UNIX $B$G$b!"30It$+$iG$0U$N%3!<%I$rZ$5$l$?!#$($i$$$3$C$A$c!#(B fix patch/package $B$bB3!9$HEP>lCf!#(B


$B"#(B 2002.06.19

$B"#(B $BDI5-(B

$B!!(B2002.05.10 $B$N(B MSN $B%A%c%C%H%3%s%H%m!<%k$NL$%A%'%C%/$N%P%C%U%!$K$h$j%3!<%I$, $B$KDI5-$7$?!#(Bbulletin $B$,99?7$5$l!"(BMSN $B%A%c%C%H(B $B%3%s%H%m!<%k$d(B MSN Messenger$B!"(BExchange Instant Messenger $B$N%"%C%W%G!<%HHG$,EP>l$7$F$$$k!#(B

$B"#(B Zope Hotfix 2002-06-14 Alert
(TechStyle Newsletter:2002-06-18, Wed, 19 Jun 2002 01:13:23 +0900)

$B!!(BZope 2.4.0$B!A(B2.5.1 $B$K%f!<%6$,(B catalog index $B$NG$0U$N%a%=%C%I$r(B call $B$G$-$F$7$^$&!#(B

$B!!(BHotfix 2002-06-14 $B$G=$@5$5$l$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability
(CERT/CC, 2002.06.18)

$B!!(BApache 1.2.2 $B0J9_$N(B 1.2.x$B!"(B1.3.24 $B0JA0$N(B 1.3.x$B!"(B2.0.36 $B0JA0$N(B 2.0.x $B$K

$B!!(Bapache 1.3.26$B!"(B2.0.39 $B$G=$@5$5$l$F$$$k$N$GF~$l$+$($k!#(B1.2.x $BMQ$N(B fix $B$O$J$$$N$G!"(B1.3.26 $B$+(B 2.0.39 $B$X0\9T$9$k!#(B

$B!!$"$o$;$F(B mod_ssl $B$d(B PHP $B$b99?7$9$kI,MW$,$"$k(B ($B$+$b$7$l$J$$(B) $B$N$GCm0U$9$k(B [memo:4211]$B!#(B1.3.26 $BMQ$N(B mod_ssl $B$O!D!D(Bmod_ssl 2.8.9-1.3.26 $B$,EP>l$7$?$=$&$G$9(B [memo:4225]$B!#$J$s$+:.$s$G$k$C$]$$$N$G!";CDjE*$K(B http://www.st.ryukoku.ac.jp/~kjm/mod_ssl-2.8.9-1.3.26.tar.gz $B$K$bCV$$$F$*$-$^$9!#(B

$B!!4XO"(B:

2002.06.20 $BDI5-(B:

$B!!(BOpenBSD/i386 $BMQ$N(B exploit $BEP>l(B: Remote Apache 1.3.x Exploit$B!#(B $B%3!<%I$N%3%a%s%H$K$O!"(BSolaris 6-8 (sparc/x86)$B!"(BFreeBSD 4.3-4.5 (x86)$B!"(BLinux (GNU) 2.4 (x86) $B$G$b(B exploit $B$K@.8y$7$?!"$H$$$&!#!V(B32 bit UNIX $B$G$O(B exploit $B$G$-$J$$!W$H$$$&$N$OBg4V0c$$$@$C$?LOMM(B ($B%/%i!<%/$NBh0lK!B'(B$B$+(B?!)$B!#(BCERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability $B$b2~D{$5$l!"(B

For Apache versions 1.3 through 1.3.24 inclusive, this vulnerability may allow the execution of arbitrary code by remote attackers. Several sources have reported that this vulnerability can be used by intruders to execute arbitrary code on Windows platforms. Additionally, the Apache Software Foundation has reported that a similar attack may allow the execution of arbitrary code on 64-bit UNIX systems.

$B$,(B

For Apache versions 1.2.2 through 1.3.24 inclusive, this vulnerability may allow the execution of arbitrary code by remote attackers. Exploits are publicly available that claim to allow the execution of arbitrary code.

$B$K$J$C$F$$$k!#$($i$$$3$C$A$c!#(B

$B!!(Bfix patch/package $B$bB3!9$HEP>lCf(B:

$B!!7Y9p(B:

2002.06.21 $BDI5-(B:

$B!!$h$7$`$i$5$s!"(BFujii $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2002.06.24 $BDI5-(B:

$B!!(Bpatch/package $B>pJs(B:

$B!!(Bfix package/patch $B$N$&$A!"(BRedHat$B!"(BDebian$B!"(BVine 2.1.x$B!"(BOpenBSD $B$O(B 1.3.26 $B$G$O$J$$$G$9!#(B $B0lJ}!"(BVine 2.5$B!"(BTurbo$B!"(BMiracle$B!"(BKondara$B!"(BFreeBSD ports $B$O(B 1.3.26 $B$K$J$C$F$$$^$9!#(B

$B!!(BExploit:

$B!!2r@b(B:

$B!!

$B!!(BApache $BJ]8n%D!<%k(B:

$B!!$=$NB>(B:

2002.06.25 $BDI5-(B:

$B!!(Bpatch/package $B>pJs(B:

$B!!$=$NB>(B:

2002.06.27 $BDI5-(B:

$B!!(BOracle$B!"(BIBM $B$N(B patch $B=P$^$7$?(B:

2002.07.01 $BDI5-(B:

2002.07.10 $BDI5-(B:

2002.07.11 $BDI5-(B:

$B!!(BNEC $B$N(B .Gate $B%5!<%S%9(B $B$N(B fix $BOC$r:\$;$o$9$l$F$$$?$h$&$J$N$GDI5-!#(B

$B"#(B [memo:4210] Samba 2.2.4 $B$N@H
(memo ML, Wed, 19 Jun 2002 12:45:13 +0900)

$B!!(BTechStyle Newsletter:2002-06-18 $B$G$b!V(BSamba 2.2.4$B$K%P%C%U%!%*!<%P!<%U%m!<$r0z$-5/$3$5$l$k%P%0!W$H$7$FJs$8$i$l$F$$$?LdBj$G$9$,!"(B[memo:4210] $B$rFI$`8B$j!"FCr7o$G$7$+H/@8$7$J$$$h$&$G$9!#(B [sugj-tech:4724] Security Advisory for Samba 2.2.4< $B0J2<$N%9%l%C%I$b;2>H!#(B

$B"#(B Systrace - Interactive Policy Generation for System Calls
(netbsd ML, Tue, 18 Jun 2002 13:23:08 +0900)

$B!!%"%W%j%1!<%7%g%sKh$K!"(Bsystem call $B$N%"%/%;%9%]%j%7!<$r@_Dj$G$-$k5!9=!"$+$J!#(B OpenBSD $B$H(B NetBSD $B$GF0:n$7!"(BNetBSD-current $B$K$OAH$_$3$^$l$F$$$k$=$&$G$9!#(B GNU/Linux $B$X$N0\?":n6H$,3+;O$5$l$F$$$k$=$&$G$9!#(B


$B"#(B 2002.06.17

$B"#(B $BDI5-(B

$B!!(B2002.05.24 $B$N(B [memo:3953] Windows$BHG(BPostPet$B$K!"E:IU%U%!%$%k$,6/@)5/F0$5$l$k%;%-%e%j%F%#%[!<%k(B $B$KDI5-$7$?!#(BPostPet$B$N%;%-%e%j%F%#$K4X$9$k=EMW$J$*CN$i$;(B $B$,99?7$5$l$F$$$k!#?7$?$K(B PostPet DX 1.2 $B0JA0$d!V$*;n$7HG!W$K4X$7$F$bBP1~J}K!$,5-:\$5$l$F$$$k!#(B

$B"#(B $B!VFCDjEE;R%a!<%kAw?.E,@52=K!!W$N;\9TF|$b(B7$B7n(B1$BF|(B
($BKhF|(B, 2002.06.13)

$B!!>rJ8$O!"$?$H$($P(B $BEE;R%a!<%k$K$h$k0lJ}E*$J>&6H9-9p$NAw$j$D$1!J$$$o$f$kLBOG%a!<%k!K$K4X$9$k?7$?$JI=<(5AL3$K$D$$$F(B $B$+$i!#(B

$B"#(B Microsoft TechNet $B%I%-%e%a%s%H(B
(Microsoft, 2002/6/12)

$B!!=P$F$^$9!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.06 $B$N(B Buffer overflow in MSIE gopher code $B$KDI5-$7$?!#(BProxy Server 2.0$B!"(BISA Server 2000 $BMQ(B patch $BEP>l!#$7$+$7!"(BIE $BMQ$O$^$@!#(B $B$NOC!#(B

$B"#(B UNIX fixes
(various)

TurboLinux
VineLinux
Miracle Linux

$B"#(B $B4k6H$N%;%-%e%j%F%#!&%$%s%7%G%s%HBP1~$r7h$a$k(B3$B$D$NMW0x(B
($BF|7P(B IT Pro, 2002.06.14)

$B!!$"$k$$$O!"%9!<%Q!

$B"#(B $B9b$$>pJs@8B8G=NO$r
($B>pJs=hM}3X2qO@J8;o(B Vol.43 No.6, 2002 June)

$B!!>pJs=hM}3X2qO@J8;o(B Vol.43 No.6 $B$K=P$F$$$k$N$O!V%7%9%F%`!&%3!<%k$KBP$9$k%i%C%Q(B/$B%j%U%!%l%s%9!&%b%K%?(B SysGuard $B$N@_7W$He$N(B link $B$OCx

$B"#(B $BDI5-(B

$B!!(B2002.06.03 $B$N(B SRT Security Advisory (SRT2002-04-31-1159): Mnews $B$KDI5-$7$?!#(Bports/security/libparanoia $B$r%j%s%/$7$F$*Cc$rBy$7$F$_$k%F%9%H!#(B

$B"#(B MS$B!"8m$C$F%&%$%k%9F~$j3+H/%D!<%k$r%j%j!<%9(B
(ZDNet, 2002.06.17)

$B!!$$$m$$$m$H%4%?%/$rJB$Y$F$$$k$h$&$@$,!"%7%c%l$K$J$i$s$@$m$&!#:G?7$N(B virus $B$KKA$5$l$F$$$?$J$i$H$b$+$/!"(BNimda $B$H$O!#!V4Z9q$NB&$KH4$17j$,$"$C$?$?$a!W(B? $B%@%V%k%A%'%C%/$H$$$&35G0$O$J$$$N$+(B?!

$B!V(BMicrosoft$B$ODL>o(B ($BCfN,(B) $B%^%9%?!<%W%m%0%i%`$KE}9g$9$k$9$Y$F$N%U%!%$%k$r%9%-%c%s$7$F$$$k$H$$$&!#$@$,:#2s$N>l9g!"%9%-%c%s$5$l$?$N$O:G=i$+$iE}9g$9$kM=Dj$@$C$?%U%!%$%k$N$_!#!W(B

$B86B'$r6J$2$k$H$3$&$J$k$H$$$&8+K\!"$+!#9b!9?t;~4V$N%A%'%C%/$rBU$C$?$?$a$K@8$8$?B;32$O$$$/$i$@$m$&!#(B

$B!!(BMicrosoft official: PRB: Inert Virus Found in Korean Language Version of Visual Studio .NET (Q323302)

$B!!F|K\$N(B MSDN $B;vL36I$+$i$b!"(BMSDN subscriber $B$KBP$7$F%a!<%k$GO"Mm$,9T$C$F$$$kLOMM!#4X$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2002.06.14

$B"#(B +ALERT+ BACKDOOR IN MSN666 SNIFFER FOR SNIFFING MSN +ALERT+
(bugtraq, Fri, 14 Jun 2002 08:42:57 +0900)

$B!!(BSensitive IM Security - MSN Message Sniffing $B$G!V@bL@!W$5$l$F$$$k(B msn666 $B%9%K%C%U%!$O%P%C%/%I%"$@!"$H$$$&;XE&!#(B

$B"#(B Oracle Reports Server $B$N@x:_E*$J%;%-%e%j%F%#$N@H
(bugtraq, Wed, 12 Jun 2002 23:09:22 +0900)

$B!!(BOracle Developer R6i Patch9 $B0JA0!"(BOracle9iAS Enterprise Edition $B$N(B Reports Services $B$,(B Developer R6i Patch9 $B0JA0$N>l9g$KR6i Patch10 $B$G=$@5(B$B$5$l$?$H$$$&!#(B

$B!!4XO"(B: Oracle Reports Server Buffer Overflow (#NISR12062002B) (NGSSoftware)$B!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.06 $B$N(B Buffer overflow in MSIE gopher code $B$KDI5-$7$?!#(BFlawed workaround in MS02-027 -- gopher can run on _any_ port, not just 70 $B$NOC!#(B

$B"#(B Web$B3+H/
(INTERNET Watch, 2002.06.13)

$B!!!X%;%-%e%j%F%#!<$H$$$&H/A[$r>o$K;}$F!Y!#$*$C$7$c$kDL$j$J$N$G$9$,!"4JC1$K$G$-$l$P6lO+$O$J$$$o$1$G!D!D!#MW$O%]%j%7!<$@$+$i!"$d$C$Q$jAH?%%H%C%W$N0U<1$,LdBj$K$J$k$h$&$J5$$,!#(BMicrosoft $B$,6lO+$7$F$$$k$h$&$K!"%]%j%7!<$rDj$a$?$H$7$F$b!"$=$NJ}8~$KBI$,8~$/$^$G$O;~4V$,$+$+$j$^$9$7!#(B

$B!!8D?M>pJsJ]8nK!0FJ}LL!"8=pJs$NN.=P$,8e$rCG$?$J$$8=>u$G!"!V:#2sBP>]$H$7$J$1$l$P$J$i$J$$$N$O!"2?==K|7o$b$N8D?M>pJs$rJ]M-$9$kLr=j$dBg4k6H$G$"$k$Y$-$@!W$H$$$&$N$O@bF@NO$"$k$N$+$J!#(B $B$A$J$_$K(B memo ML $B$N(B subscriber $B$b(B 5000 $B?M1[$($A$c$C$F$k$s$G!"!D!D!#(B

2002.06.25 $BDI5-(B:

$B!!9V1i;qNA$,(B$B9bLZ$5$s$N(B web $B%Z!<%8(B$B$G8x3+$5$l$F$$$^$9!#$^$?!"(B[memo:4175] $B$K(B INTERNET Watch $B5-;v$X$N%U%)%m!<$,$"$j$^$9!#(B

$B"#(B SNS Advisory No.54 Active! mail Executing the Script upon the Opening of a Mail Message Vulnerability
(bugtraq, Thu, 13 Jun 2002 14:31:43 +0900)

$B!!(BActive! mail 1.422, 2.0 $B$K

$B!!(BActive! mail 2.0.1.1 $B$G=$@5$5$l$F$$$k$=$&$@!#(B

$B"#(B Microsoft SharePoint Portal Server $BMQ$N%"%s%A%&%$%k%9(B $B%=%j%e!<%7%g%s$K4X$9$k%^%$%/%m%=%U%H$N8+2r(B
($B?7Ce%5%]!<%H5;=Q>pJs(B, 2002.06.14)

$B!!$^$??7$7$$(B API $B$D$/$C$?$C$F$3$H(B? Microsoft $BE*$K$O!V$H$/$$$o$6!W$J$s$@$m$1$I!"(B3rd party $B$O$=$l$G$O$d$C$H$l$s$@$m$&!#:G=i$+$i%^%H%b$J(B API $B$rMQ0U$7%J%$%H!#(B

$B"#(B $B!V4m81EY!aDc!W$N(BJPEG$B%&%$%k%9$KIT5H$JM=46(B
(ZDNet, 2002.06.14)

$B!!(Bloader $B$H(B data $B$KJ,N%$5$l$F$$$k!"$C$F%3%H$G$7$g$&$+!#(B


$B"#(B 2002.06.13

$B"#(B MS02-030: SQLXML $B$NL$%A%'%C%/$N%P%C%U%!$K$h$j%3!<%I$,
(Microsoft, 2002.06.13)

$B!!(BSQL Server 2000 $B$K4^$^$l$k!"$"$k$$$OJLES

$B!!>\:Y(B: wp-02-0007: Microsoft SQLXML ISAPI Overflow and Cross Site Scripting (westpoint)

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$?$@$7!"MxMQ$7$F$$$k(B SQLXML $B$KBP1~$7$?(B patch $B$rE,MQ$9$k$3$H!#(B

$B"#(B MS02-029: $B%j%b!<%H%"%/%;%9%5!<%S%9$NEEOCD"$NL$%A%'%C%/$N%P%C%U%!$K$h$j%3!<%I$,
(Microsoft, 2002.06.13)

$B!!(BWindows NT 4.0, 2000, XP $B$K

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

2002.06.14 $BDI5-(B:

$B!!>\:Y(B: Microsoft RASAPI32.DLL (NGSSoftware)$B!#(B

2002.06.27 $BDI5-(B:

$B!!(BMS02-029 patch $B$rE,MQ$9$k$H!"(BVPN $BMxMQ;~$K(B administrator $B8"8B$,I,MW$K$J$k>l9g$,$"$k$H$$$&I{:nMQ$,$"$k$=$&$@(B: VPN Connections May Require Administrator Permissions After You Apply MS02-029 (Q318138) (Q324908)$B!#(BMS02-029 $B$K$b$3$N7o$K4X$9$kCm5-$,DI2C$5$l$F$$$k!#(B

2002.07.10 $BDI5-(B:

$B!!(B2002.07.04 $BIU$1$G!"(BVPN $BMxMQ;~$G$bLdBj$,H/@8$7$J$$=$@5%W%m%0%i%`$,EP>l$7$F$$$k!#(B

$B"#(B MS02-028: HTR $B$N%A%c%s%/$5$l$?%(%s%3!<%I$N%R!<%W(B $B%*!<%P!<%i%s$K$h$j(B Web $B%5!<%P!<$N%;%-%e%j%F%#$,?/32$5$l$k(B (Q321599)
(Microsoft, 2002.06.13)

$B!!(BIIS 4.0, 5.0 $B$KMS02-018 $B$G=$@5$5$l$?!V(BActive Server Page $B$K$h$k%A%c%s%/$5$l$?%(%s%3!<%I%j%/%(%9%H$G$N(B heap overflow$B!WLdBj$NN`;wIJ$,(B .HTR $B$r=hM}$9$k(B ISAPI $B%(%/%9%F%s%7%g%s$K$bB8:_$7$?!#$3$l$r0-MQ$9$k$H!"967b

[*] advisory $B$K$OL@5-$5$l$F$$$J$$$N$@$,!"(BIIS 4.0 $B$G$b(B local SYSTEM $B$G$J$$(B$B8"8B$G

$B!!2sHrJ}K!$H$7$F$O!"(B.HTR $B$rL58z$K$9$k!#$"$k$$$O(B URLScan $B$K$h$C$F%A%c%s%/$5$l$?%(%s%3!<%I%j%/%(%9%H$rGS=|$9$k!#BP1~$9$k$K$O(B patch $B$rE,MQ$9$k!#(B

$B!!:#2s$N(B patch $B$O!VN_@QE*(B patch$B!W(B$B$G$O$J$$(B$B$N$G!":G?7$NN_@QE*(B patch (MS02-018) $B$rE,MQ$7$?>e$G(B MS02-028 patch $B$rE,MQ$9$k$3$H!#(B

$B!!>\:Y(B: ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612] (eEye)$B!#(BeEye $B$N(B SecureIIS $B$K$h$C$F$b$3$NLdBj$r2sHr$G$-$k!#(B


$B"#(B 2002.06.12

$B"#(B $BDI5-(B

$B!!(B2002.06.06 $B$N(B Buffer overflow in MSIE gopher code $B$KDI5-$7$?!#(B MS02-027 $BEP>l!#(BIE 5.01 / 5.5 / 6 $B$NB>$K!"(BProxy Server 2.0$B!"(BISA Server 2000 $B$K$b

$B"#(B remote DoS in Mozilla 1.0
(bugtraq, Mon, 10 Jun 2002 17:20:06 +0900)

$B!!(BUNIX $BHG(B Mozilla 1.0 $B0JA0$K$*$$$F!"%9%?%$%k%7!<%H$K(B body { font-size: 1666666px; } $B$H$+=q$$$F$*$/$H%"%l%2$J>u67$K$J$k!"$H$$$&OC!#(B $BMW$O%V%i%&%6%/%i%C%7%c!<$M$?$J$N$@$1$I!"(BX $B$rF;O"$l$K$7$F$/$l$k!"$H!#(B $BJT=8Cf$N%U%!%$%k$rJ]B8$7$F$+$i%F%9%H$7$^$7$g$&!#(B


$B"#(B 2002.06.11

$B"#(B [BUGZILLA] Security Advisory For Versions of Bugzilla 2.14 Prior To 2.14.2, 2.16 Prior To 2.16rc2
(bugtraq, Sat, 08 Jun 2002 15:50:12 +0900)

$B!!(Bbugzilla 2.14.1 $B0JA0!"(B2.15$B!"(B2.16rc1 $B$K$5$^$6$^$J

$B"#(B Header Based Exploitation: Web Statistical Software Threats
(pen-test ML, Sat, 08 Jun 2002 06:23:43 +0900)

$B!!(BReferer: $B$d(B User-Agent: $B$J$I$,1x@w$5$l$F$$$k$3$H$b$"$k$+$i!"$A$c$s$H=|@w$7$^$7$g$&!"$H$$$&OC!"$+$J!#(B

$B"#(B [FreeBSD-users-jp 69101] How to find hidden (super) user
(FreeBSD-users ML, Fri, 7 Jun 2002 23:37:41 +0900)

$B!!(BFreeBSD $B$N%Q%9%o!<%IG'>Z$G$O!"(B/etc/passwd $B$d(B /etc/master.passwd $B$,D>@\MxMQ$5$l$k$o$1$G$O$J$/!"(B/etc/passwd $B$d(B /etc/master.passwd $B$+$i@8@.$5$l$?%G!<%?%Y!<%9(B (/etc/pwd.db, /etc/spwd.db) $B$,MxMQ$5$l$k!#(B $B$3$N$?$a!"?75,$K%f!<%6$r:n@.$7%G!<%?%Y!<%9$r99?7$7$?8e$K(B /etc/passwd $B$d(B /etc/master.passwd $B$+$i3:Ev%f!<%6$r:o=|$7$F$*$/$H!"0l8+B8:_$7$J$$$,MxMQ2DG=$J%f!<%6$r:n@.$9$k$3$H$,$G$-$k!#(B $B$3$N$h$&$J%f!<%6$rH/8+$9$k$K$O$I$&$9$l$P$$$$$@$m$&$+!"$H$$$&OC!#(B

$B!!$3$l$KBP$7$F!"(B

$B$,<($5$l$F$$$k(B ($B$d$C$F$k;v$O$I$A$i$bF1$8(B)$B!#(B

$B!!%9%l%C%I<+BN$O$5$i$K(B toor $B$d(B WHEEL_SU $B$NOC$KH/E8$7$F$$$k!#(B

$B"#(B Bypassing JavaScript Filters ? the Flash! Attack
(netsecurity.ne.jp, 2002.06.07)

$B!!(BMacromedia Flash $B$,%5%]!<%H$9$k(B ActionScript $B$N(B getURL() $B$rMxMQ$7$F(B getURL($B!H(Bjavascript:alert(document.cookie)$B!I(B); $B$J$I$H@_Dj$7$F$*$-$D$D!"(B form $B$J$I$NF~NO$H$7$F$3$l$r(B embed $B$7$F$"$2$k$H(B cookie $B$,http://eyeonsecurity.net/advisories/flash-demo/ $B$K$"$k$=$&$@!#(B

$B!!$^$@(B Flash $B$X$N(B patch $B$O40@.$7$F$$$J$$LOMM!#(B

$B!!(BActionScript $B$J$s$F8@$o$l$k$H!"$I$&$b%"%/%7%g%s2>LL$rA[5/$7$F$7$^$C$F$$$1$J$$(B (^^;;)$B!#(B

$B"#(B Oracle9i TNS Listener $B$N@x:_E*$J(BDoS$B@H
(Oracle, 2002.06.10)

$B!!(BWindows NT4.0/2000 $BHG$N(B Oracle9i Database Release 9.0.1.x $B$KCHq$5$l!W!"(BDoS $B>uBV$K$J$C$F$7$^$&!#(B UNIX $BHG$J$I$NHs(B Windows $BHG$K$O$3$N

$B!!(B9.0.1.3.1 Patch3 $B$GBP1~(B$B$7$F$$$k!#(B

$B"#(B UNIX fixes
(various)

TurboLinux
Miracle Linux
Kondara MNU/Linux
RedHat
SGI IRIX

$B"#(B $B!V%;%-%e%j%F%#!&%[!<%k$r;XE&$5$l$?!W!=!=$=$N;~4k6H$O$I$&$9$k$Y$-$+(B
($BF|7P(B IT Pro, 2002.06.07)

$B!!Tea Room for Conference No.881$B!"$G$9$+$M$(!#(B

$B"#(B Linux$B0J30$N(BIPSec$B%9%?%C%/$H$NAj8_@\B3!N8eJT!O(B $B!](B Linux$B$G(BIPSec$B$r;H$*$&(B $B!](B
(@IT, 2002.06.11)

$B!!$$$h$$$h(B Windows $B$H$D$J$2$kOC!#(BWindows 2000 $B0J9_$N(B IPSec $B5!G=$H(B PGPnet (PGP 6.5.1 $B0J9_$K4^$^$l$F$$$k(B) $B$r

$B!!(BPGP 6.5.8ckt $BF|K\8lHG$O(B http://www.hizlab.net/pgp/ $B$+$iF~Mac$B>e$G$N(BIPSec$B$K$h$k%;%-%e%"$JDL?.$N$B!W$K>pJs$,$"$k!#(B

$B"#(B $BDI5-(B

$B!!(B2002.06.07 $B$N(B ASP.NET $B%o!<%+!<%W%m%;%9$KL$%A%'%C%/$N%P%C%U%!$,4^$^$l$k(B (Q322289) (MS02-026) $B$KDI5-$7$?!#(Badvisory $B$,2~D{$5$l!"(BVisual Studio .NET $B$r=*N;$7$F$+$i(B patch $B$rE,MQ$;$h!"$H$5$l$F$$$k!#(B

$B"#(B SecurityFocus.com Newsletter #147 2002-5-27->2002-5-31
(bugtraq-jp, Tue, 11 Jun 2002 11:52:47 +0900 )

$B!!(BSecurityFocus.com Newsletter $BBh(B 147 $B9fF|K\8lHG(B ($B%F%-%9%H(B)$B!#(B

$B"#(B Internet Security Systems Security Alert Summary AS02-23
(ISS, 2002.06.10)

$B!!(BISS Security Alert Summary AS02-23 $B$G$9!#(B

$B"#(B SQL Server 2000/MSDE 2000 Buffer Overflow Vulnerability
(incidents.org, 2002.06.06)

$B!!(BMS02-020 $B$r4^$`(B patch $BA4ItF~$j$N(B Microsoft SQL Server 2000$B!"(BMSDE 2000 $B$K


$B"#(B 2002.06.10


$B"#(B 2002.06.07

$B"#(B from memo ML
(memo ML)

$B"#(B $B$$$m$$$m(B
(various)

Kondara MNU/Linux
TurboLinux
VineLinux

2.1 $BMQ(B:

2.5 $BMQ(B:

SCO
SGI
$BIY;NDL(B PortalWorks
MIME::Tools
squid
slurp
SHOUTcast
BlackICE

$B"#(B Yahoo!$B%a%C%;%s%8%c!<$K%;%-%e%j%F%#!&%[!<%k!$$?$@$7F|K\8lHG$O1F6A$r
($BF|7P(B IT Pro, 2002.06.06)

$B!!(BCERT Advisory CA-2002-16 Multiple Vulnerabilities in Yahoo! Messenger $B$NOC!#(B $B:G?7$NF|K\8lHG(B Yahoo! Messenger $B$K$O$3$NLdBj$O$J$$$=$&$@!#(B

$B"#(B ASP.NET $B%o!<%+!<%W%m%;%9$KL$%A%'%C%/$N%P%C%U%!$,4^$^$l$k(B (Q322289) (MS02-026)
(Microsoft, Fri, 07 Jun 2002 09:47:56 +0900)

$B!!(BMicrosoft .NET Framework 1.0 $B$K4^$^$l$k(B ASP.NET $B$Kl9g!"$3$l$r(B remote $B$+$i967b$9$k$3$H$G!"F0:nCf$N(B web $B%Y!<%9%"%W%j%1!<%7%g%sA4$F$r:F5/F0$5$;$k$3$H$,$G$-$k$H$$$&!#(B $B$J$*(B StateServer $B%b!<%I$O%G%U%)%k%H$G$O$J$$!#$^$?(B StateServer $B%b!<%I$G$"$C$F$b(B cookie $B$rMxMQ$7$F$$$J$$>l9g$K$OLdBj$,$J$$!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B!!$7$+$7!"$5$C$=$/!"$G$9$+!#$$$d$O$d!#(B

2002.06.11 $BDI5-(B:

$B!!(Badvisory $B$,2~D{$5$l!"(BVisual Studio .NET $B$r=*N;$7$F$+$i(B patch $B$rE,MQ$;$h!"$H$5$l$F$$$k!#>\:Y$O(B INFO: Installation Issues with Silent Install of Security Bulletin MS02-026 (Q324292) $B;2>H!"$@$=$&$@!#(B

$B"#(B mod_encoding $B$N%;%-%e%j%F%#%[!<%k$K$D$$$F(B
([webdav-jp:0428], Fri, 07 Jun 2002 02:02:14 +0900)

$B!!(Bmod_encoding-20011026a, mod_encoding-20011211a $B$Kl9g!"$9$Y$F$N%U%!%$%k$O(B Apache $B]$H$J$k!#(B

$B!!(Bmod_encoding-20011211a-hotfix $B$G=$@5$5$l$F$$$k$N$GF~$l$+$($k!#(B $B$^$?(B mod_encoding-20011211a $B$X$N(B patch $B$,<($5$l$F$$$k!#(B

$B"#(B Microsoft Internet Explorer 'Folder View for FTP sites' Script Execution vulnerability
(bugtraq, Fri, 07 Jun 2002 00:33:44 +0900)

$B!!F|K\8lHG$,(B penetration technique research site $B$K$"$k$N$G$=$A$i$b;2>H!#(B

$B!!(BMSIE 5.5/6 $B$K%/%m%9%5%$%H%9%/%j%W%F%#%s%0@H

$B$NN>J}$,M-8z$N>l9g(B ($B%G%U%)%k%H$GN>J}M-8z(B)$B!"(BIE $B$N(B URL $B$H$7$F(B ftp://"><script>alert("Exploit")%3b</script>%20 $B$rF~NO$9$k$H!"$3$N%9%/%j%W%H$,%^%$%3%s%T%e!<%?%>!<%s8"8B$Ge$G0-$N8B$j$r$D$/$9$3$H$,$G$-$k!#(B

$B!!2sHr:v$H$7$F$O!">e5-$N$I$A$i$+$,L58z$G$"$l$P$h$$!#Mh$N(B Windows $B%U%!%k%@$r;H$&!W$H$9$k(B) $B$r@_Dj$7$F$$$k$N$G2sHr$G$-$F$$$?!#(B

$B!!H/8+G/$bA0$K$3$NLdBj$rH/8+$7(B MS $B$KJs9p$7$?$K$b$+$+$o$i$:!":#$@$K(B fix $B$5$l$F$$$J$$$N$@$=$&$@!#$@$a$8$c$s(B > MS$B!#(B

2002.08.04 $BDI5-(B:

$B!!(BWindows 2000 SP3 $B$G=$@5$5$l$F$$$k$=$&$G$9(B: Q316890: Embedded Java Scripting in FTP Sites May Run After Java Scripting Is Disabled$B!#(B (info from bugtraq)

2002.08.05 $BDI5-(B:

$B!!(BMozilla, Opera $B$G$bF1MM;vNc$,H/8+$5$l$?!#(B

2002.08.28 $BDI5-(B:

$B!!(BOpera 6.05 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B penetration technique research site 2002.08.28 01:18 $B;2>H!#(B $B$3$l$^$?O"Mm%J%7$@$=$&$G!#(B

$B"#(B $B$=$l$G!V8D?M>pJsJ]8n!W$r$I$&$9$k!)(B
($BF|7P(B IT Pro, 2002.06.05)

$B!J(B1$B!K8D?M>pJs$NHO0O$J$I!$$"$$$^$$$JE@$,B?$/

(2) $B$K$O$?$H$($P!"K\?MG'>ZpJs$NHO0O$d(B (3) $B$N3+<(HO0O$C$F$=$s$J$KITL@3N$@$m$&$+!#(B $BITL@3N$G$"$k$h$&$J%7%9%F%`$r1?MQ$7$F$$$kJ}$bLdBj$@$H;W$&$s$@$,!#(B

$B!!$C$F!"B>?M;v%b!<%I$G$O:Q$^$5$l$J$$$s$@$1$I!D!D!#(B

$B"#(B IDS$B$NF3F~$K$h$kIT@5?/F~$N8!CN$H%M%C%H%o!<%/4IM}(B: $BBh(B1$B2s(B snort $B$rF3F~$9$k(B $B$=$N(B1
(ZDNet, 2002.06.05)

$B!!(BUNIX $B>e$G!"$H$j$"$($:%$%s%9%H!<%k$7$FF0$+$9$H$3$m$^$G!#(B

$B"#(B IIS$B0BA4BP:v%,%$%I!JA0!K!=!=!!(BIIS$B$r0BA4$K;HMQ$9$k$?$a$NF3F~!&@_Dj
(@IT, 2002/05/30)

$B!!!V(B$B$B!W(B $B$$$k5-;v$J$N$G$4Cm0U!#(B

$B"#(B MSDN Online Columns: $B%P%C%U%!%*!<%P!<%i%s$r2r>C$;$h(B!
(Microsoft, May 28, 2002)

$B!!!V(B$B%W%m%0%i%^$N$?$a$N%;%-%e%j%F%#BP:v%F%/%K%C%/(B$B!W(B $BK.LuHG$bEP>l$7$?$=$&$G$9!#(B STPP $B%;%-%e%j%F%#BP:v%;%_%J!<(B $B2q>l$GGd$j=P$7$?$j$9$k$N$+$J$"!#(B


$B"#(B 2002.06.06

$B"#(B UNIX fixes
(various)

Sun
RedHat
IRIX

$B"#(B SECURITY.NNOV: Courier CPU exhaustion + bonus on imap-uw
(bugtraq, Sat, 01 Jun 2002 21:14:15 +0900)

$B!!(BCourier 0.38.1 $B$K(^^;)):

if (year < 1970) return (0);
if (year > 9999) return (0);

$B!!$^$?!"(Bimap-uw $B$K%G%6%$%s>e$NLdBj$,$"$j!"$3$l$rKI$4$&$H(B FAQ $B$K$"$k(B restrictBox $B$r@_Dj$7$?$H$7$F$bKI$.$-$l$:!"(B imaptools.tgz $B$r;H$&$H(B

imapget imap.host.name /etc/passwd > passwd

$B$N$h$&$K$7$F%U%!%$%k$r(B get $B$7$F$7$^$($k!"$H$$$&!#(B $B:G?7$N(B imap-2001a $B$G$b$3$N>u67$OH/@8$9$k$H$$$&!#(B

2002.07.18 $BDI5-(B:

$B!!(Bimap-uw 2002.RC2 $B$N(B docs/RELNOTES $B$K$O(B

The restrictBox option in env_unix.c sets "restricted box" functionality, which disables access to the root (leading "/"), access to other user's directories (leading "~"), and access to superior directories via "..".

$B$H$$$&5-=R$,$"$k$N$G!"$I$&$d$i=$@5$5$l$?LOMM!#(B

2002.08.01 $BDI5-(B:

$B"#(B Buffer overflow in MSIE gopher code
(bugtraq, Tue, 04 Jun 2002 22:07:34 +0900)

$B!!(BIE 5.5, 6.0 $B$K

$B!!2sHr:v$H$7$F;XE&

$B

$B!!

acl POISONED_URL url_regex -i "/usr/local/etc/squid/poisoned-url.list"
http_access deny POISONED_URL

$B$H$+$7$F$$$k$N$G!"(Bpoisoned-url.list $B$K(B ^gopher:// $B$HDI2C$7$F$*$$$?!#(B

$B!!(Bpatch $B$O$^$@$J$$!#4XO"(B:

2002.06.12 $BDI5-(B:

$B!!(BMS02-027: Gopher $B%W%m%H%3%k(B $B%O%s%I%i$NL$%A%'%C%/$N%P%C%U%!$K$h$j!"967b$B!#(BIE 5.01 / 5.5 / 6 $B$NB>$K!"(BProxy Server 2.0$B!"(BISA Server 2000 $B$K$b

2002.06.14 $BDI5-(B:

$B!!(BFlawed workaround in MS02-027 -- gopher can run on _any_ port, not just 70$B!#(B FAQ $B$N!V$3$N@H

2002.06.17 $BDI5-(B:

$B!!(BProxy Server 2.0$B!"(BISA Server 2000 $BMQ(B patch $BEP>l(B$B!#$7$+$7!"(BIE $BMQ$O$^$@!#(B

2002.08.29 $BDI5-(B:

$B!!(BInternet Explorer $BMQ$NN_@QE*$J=$@5%W%m%0%i%`(B (Q323759) (MS02-047) $B$G=$@5$5$l$?!#(B

$B"#(B $B2~$6$s$5$l$?%5%$%H$N(BOpenPort(TCP)$B%i%s%-%s%0!J(B2002.05.01-31$B!K(B
(penetration technique research site, 2002.06.05)

$B!!=P$F$^$9!#(BWindows $B7O$H(B Linux $B$O$[$\F1?t$G$9$M!#(B

$B"#(B IPA $BFO=P>u67(B: 2002.05
(IPA)

$B!!(B2002.05 $BJ,=P$F$^$9!#(B

$B!!(BAMaViS $B$+$i$N=PNO$r(B IPA $B%&%#%k%9FO=PMM<0(B $B$KJQ49$7$F<+F0$GAw$C$F$"$2$k$H4n$P$l$k$s$@$m$&$+!#(B $B$H=q$$$F$$$k4V$K$b(B [FreeBSD-net-jp 3728] $B$K(B Klez.H $B$,!D!D!#(B

$B"#(B BizTech Special: $B%;%-%e%j%F%#Am9g%=%j%e!<%7%g%s%5%$%H(B
($BF|7P(B BizTech)

$B!!$$$D$G$-$?$N$+$h$/$o$+$i$J$$$1$I!"$=$&$$$&%5%$%H$,$G$-$F$^$9!#(B $B%j%9%/%^%M%8%a%s%H:GA0@~(B $BBh(B 1 $B2s$NKAF,$NOC$O$D$^$j!"(BDoS $B>u67!"$J$o$1$G!#(B

$B"#(B JPCERT/CC Web$B99?7MzNr(B
(JPCERT/CC, 2002.06.06)

$B!!99?7$$$/$D$+!#(B

$B!!$U$H;W$C$F;n$7$F$_$?$N$G$9$,!"(Bhttps://www.jpcert.or.jp/ $B$H$$$&$N$O$J$$$_$?$$$G$9$M!#(B


$B"#(B 2002.06.05

$B"#(B [memo:4064] mytrip.net$B$N$J$j$9$^$7LdBj(B
(memo ML, Tue, 04 Jun 2002 00:28:19 +0900)

$B!!(B$BN9$NAk8}(B $B$K$^$?$b$dLdBj!#$"$kDxEY$N8D?M>pJs(B ($B2q0wEEOCHV9f!&;aL>!&@8G/7nF|!&<+Bp=;=j(B) $B$rGD0.$7$F$$$l$P!"2q0wHV9f$r[memo:3863] $B$HK\

$B!!$3$NLdBj$O$9$G$K=$@5$5$l$F$$$k$=$&$@$,!"B>;3$N@P$H$7$F<+%5%$%H$N8+D>$7$r$7$F$/$l$k$H$3$m$,$I$l$@$1$"$k$3$H$d$i!#$C$F!"B>?M;v%b!<%I$G$$$$$N$+(B? > $B26!#(B

$B"#(B CERT Advisory CA-2002-15 Denial-of-Service Vulnerability in ISC BIND 9
(CERT/CC, 2002.06.04)

$B!!(B9.2.1 $B$h$jA0$N(B bind 9 $B$K

$B!!(Bbind 9.2.1 $B$G=$@5$5$l$F$$$k$N$G(B bind 9 $BMxMQ

$B!!4XO"(B:

$B"#(B $B!ZFCJL4k2h![(B $BEE;R?=@A$NZ
(@IT, 2002.06.05)

$B!!$J$s$J$s$@$m$&$3$N5-;v$O!D!D!#(B

$B$7$+$7!"@h$[$I$NAmL3>J$N%;%-%e%j%F%#LdBj$r;XE&$7$?5-;v$rFI$s$G$_$k$H!"$=$b$=$b@/I\$O=EBg$J7g4Y$rJz$($F$$$kEE;R?=@A$N;v

$B!!$B$G$O$J$$(B$B$H8@$$$?$$$N$@$m$&$+!#(B

$B??56$NH=JL$K$D$$$F$$$&$J$i$P!"$+$D$FK\Ev$K$"$C$?Lk4V6b8K$N$J$j$9$^$7;v7o(B($BCm(B1)$B$J$I%j%"%k$N@$3&$G$b;v7o$NNc$O$"$k!#F1MM$KLk4V6b8K$O4m$J$$$H$$$&5-;v$r=q$/$N$@$m$&$+!)(B

$B!!!VLk4V6b8K!W$N??Z$G$-$J$$>l9g!"$=$l$O4m$J$$$HH=CG$9$Y$-$@$H;W$&$s$@$1$I!"0c$&$s$@$m$&$+!#(B $BH`$i$O!"$I$s$J5-;v$r=q$1$P$$$$$H8@$&$N$@$m$&$+!#(B


$B"#(B 2002.06.04

$B"#(B [memo:4027] Cookie$B$NI=<($H:o=|$r
(memo ML, Sun, 02 Jun 2002 14:34:09 +0900)

$B!!(Bcookie $B$r4JC1$KI=<(!&:o=|$9$kJ}K!!#$?$@$78B3&$b$"$k$N$GCm0U;v9`$r$h$/$*FI$_$N>e$GMxMQ$7$h$&!#(B $BD9Bg$J$b$N$K$D$$$F$O!"%"%I%l%9%P!<$KD>@\BG$A9~$`$h$j$b!"E,Ev$J!V$*5$$KF~$j!W(B(.url) $B%U%!%$%k$r$D$/$C$F$*$$$F!"$=$N%U%!%$%k$r%F%-%9%H%(%G%#%?$GJT=8$9$kJ}$,3N

$B"#(B SecurityFocus.com Newsletter #146 2002-5-20->2002-5-24
(bugtraq-jp, Tue, 04 Jun 2002 18:28:57 +0900)

$B!!(BSecurityFocus.com Newsletter $BBh(B 146 $B9fF|K\8lHG(B ($B%F%-%9%H(B)$B!#(B

$B"#(B How to assign a password for MSDE (Microsoft SQLServer Desktop Edition)
(incidents.org, 2002.05.30)

$B!!(BMSDE $B$N(B 'sa' $B%"%+%&%s%H$K%Q%9%o!<%I$r@_Dj$9$kJ}K!!#(B $B%d%i%l$kA0$K!"$D$1$F$*$-$^$7$g$&!#(B

$B"#(B Internet Security Systems Security Alert Summary AS02-22 June 3, 2002
(ISS, 2002.06.04)

$B!!(BISS AS02-22 $B$G$9!#(B

$B"#(B Windows$B$K(BMcAfee$B$N%"%s%A%&%$%k%9!&%=%U%H$rE}9g$+(B
([memo:4082], Tue, 04 Jun 2002 13:27:53 +0900)

$B!!K\Ev$J$N$+(B?! $B


$B"#(B 2002.06.03

$B"#(B GnuPG-1.0.6$B$+$i(BGnuPG-1.0.7$B$K%"%C%W%0%l!<%I$7$?D>8e$NLdBj(B
([macosx-jp:10782], Mon, 03 Jun 2002 12:05:56 +0900)

$B!!(B1.0.6 $B$+$i(B 1.0.7 $B$K(B upgrade $B$9$k$H!"<+J,<+?H$N(B key $B$,(B trust: -/- $B$K$J$C$F$7$^$&$N$GCm0U$7$h$&!"$H$$$&OC!#(B $B$=$&$$$($P

$B"#(B [memo:4015] Content-Type: text/plain $B$J%Z!<%8$G(BIE$B$K@8$:$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$NLdBj(B
(memo ML, Sat, 01 Jun 2002 00:31:58 +0900)

$B!!!V(BMSIE $B$,(B Content-Type: $B$r@5$7$/I>2A$7$J$$!WOC$,%/%m%9%5%$%H%9%/%j%W%F%#%s%0@HMS01-058 $B$d(B fusianasan $B%H%i%C%W(B $B$b(B Content-Type: $B$r@5$7$/I>2A$7$J$$$+$i$3$=H/@8$7$?;vNc$J$o$1$G!":,K\860x$O$d$O$j(B MSIE $B$N%@%a%@%a$5$K$"$k$o$1$G!#(B

$B!!$3$N(B MSIE $B$HF1$8LdBj$,%G%U%)%k%H>uBV$N(B Opera $B$K$b$"$k$H%U%)%m!<$5$l$F$$$k(B [memo:4017]$B!#$3$A$i$O!"@_Dj$9$l$P$^$H$b$JF0:n$K$J$k$h$&$@!#(B MSIE $B$b$;$a$F!"!V@_Dj$9$l$P$^$H$b$JF0:n$K$J$k!W$h$&$K$O$G$-$J$$$N$@$m$&$+!#(B $B%G%U%)%k%H$G$=$&$J$C$F$/$l$l$P$b$C$H$&$l$7$$$1$I!#(B MSIE $B$K4E$($FJQ$J(B Content-Type: $B$rAw$C$F$/$k%5%$%H$,B?$9$.$k$s$G$9$h$M!#(B

$B"#(B UNIX fixes
(various)

$B"#(B Trojan/backdoor in fragroute 1.2 source distribution
(bugtraq, Fri, 31 May 2002 16:55:21 +0900)

$B!!(Bmonkey.org $B$,%/%i%C%/$5$l$?$?$a$K!"$=$3$GG[I[$5$l$F$$$?(B dsniff-2.3, fragroute-1.2, fragrouter-1.6 $B$,LZGOF~$jHG$K$J$C$F$$$?!"$H$$$&OC!#(B Dug Song $B;a$N%U%)%m!<(B$B$b;2>H!#(B

$B"#(B SRT Security Advisory (SRT2002-04-31-1159): Mnews
(bugtraq, Sat, 01 Jun 2002 03:59:41 +0900)

$B!!(Bsprintf() $B$H$+(B strcpy() $B$H$+%P%7%P%7$G$9$7$M$(!#(B ($BI=8=$r$9$3$7=$@5(B: $B1n4]$5$s46

2002.06.17 $BDI5-(B:

$B!!(Bofficial fix $B$O$$$^$@EP>l$7$F$$$J$$$,!"ports/security/libparanoia $B$r%j%s%/$7$F$*Cc$rBy$7$F$_$?!#(B $B$H$j$"$($:(B bugtraq $B$KN.$l$?(B exploit $B$G;n$7$?$H$3$m!"(B mnews[51250]: Stack violation - exiting $B$H$$$C$F=*N;$9$k$h$&$K$O$J$k$3$H$r3NG'!#(B

$B"#(B Linux How-To - PPTP$B$K$h$k(BVPN$B$N9=C[(B
(ZDNet, 2002.05.28)

$B!!(BLinux $B$G(B PPTP $B%5!<%P$rN)$A$"$2!"(BWindows XP $B$+$i@\B3$9$k!"$H$$$&5-;v!#(B


$B;d$K$D$$$F(B