Last modified: Fri Dec 13 21:03:58 2002 +0900 (JST)
[aml 30163] $B2#IM!'=;4p%M%C%HHsDLCNLs#4#0K|(B$B!#(B $B$&!<$`!#$9$4$$$b$s$@!#(B
[aml 30158] $B"#@>K\4j;{Am6I!V9qN)DIEi;\@_!WLdBj"#(B010$B!#(B $B$J$s$@$+%4%?$D$$$F$$$k$h$&$G!#(B
Privman - A library to make privilege Separation easy $B$H$$$&$b$N$,$"$k$=$&$G$9!#(B wu-ftpd 2.6.2 / BSD ftpd 6.5-0.32 $BMQ(B patch $B$bG[I[$5$l$F$$$^$9!#(B (info from [ftpd 839])
$B!V%F%m;Y1g%5%$%H$X$N%j%s%/$O0cK!!W!=!=JFBg3X$,3X@8$K7Y9p(B (ZDNet)$B!#(B U.S.A. $B$K<+M3$J$7!#(B
incidents.org$B!#(B22321 (wnn6_Tw) $B$X$N(B scan $B$,A}$($F$$$k(B?!
$B%Y%k8&5f=j$NMnF|$N%J%>(B ($B:#F|$NI,$:%H%/$9$k0l8@(B)$B!#(B June 29 $B$G$9$h1|$5$s(B! $B;3Fb$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
$BElEE!$!V4E$($,$"$C$?!W(B---$BF|K\5!3#3X2q!VElEELdBj!WFCJL%;%C%7%g%s(B ($BF|7P(B D&M ONLINE)$B!#(B $B;2>H(B: $B!V8!::$N:_$jJ}$K4X$9$k8!F$2q!W(B$B!#(B $B%R%3!<%-$,(B 1 $B5!Mn$A$F$bF|K\$OD@KW$7$J$$$,!"86H/$,(B 1 $B8DGzH/$9$kF|K\$,D@KW$9$k!"$H$$$&0U<1$O$"$k$N$+$J!D!D!#(B $B%R%3!<%-$,(B 1 $B5!Mn$A$F86H/$K%V%AEv$?$k>l9g$O!"F|K\D@KW$@$1$I!#(B
$B!V2q
$B!!(B2. Description of the "tar" problem
$B$O!"(BGNU tar $B$K$*$$$F!"(Btar $B%"!<%+%$%V$K(B ../ $B$J%Q%9L>F~$j$N%U%!%$%k$r;E9~$s$G$*$/$H!"(B
$B$=$N%"!<%+%$%V$NE83+;~$K(B /etc/passwd $B$J$I$N=EMW%U%!%$%k$r>e=q$-$5$;$k$3$H$,$G$-$k!"$H$$$&;XE&$J$N$+$J!#(B
1.3.19 $B0JA0$NLdBj!"$H$5$l$F$$$?$,!"(B1.3.25 $B$G$bN`;w$NLdBj$,$"$kLOMM!#(B
CVE: CAN-2001-1267$B!"(B
CAN-2002-0399 ($BCf?H$,$J$$!D!D(B)$B!#(B
$B!!$5$i$K!"(Binfo-zip $B$N(B unzip 5.42 $B0JA0$K$bF1MM$NLdBj$,$"$k$h$&$@!#(B CVE: CAN-2001-1268, CAN-2001-1269$B!#(BHistory.550 $B$K$"$k$3$l$+$J(B?
5.5h (12 Jan 02): - unzip.h, unzip.c; mapname() in all ports except CMS/MVS, Tandem, TOPS20: added code to strip "../" path components from extracted names and new option "-:" to allow deactivating this security feature; changed mapname()
$B!!(BRed Hat fix: [RHSA-2002:096-24] Updated unzip and tar packages fix vulnerabilities$B!#(B FreeBSD ports $B$N(B archivers/gtar $B$K$O$3$N(B patch $B$O4^$^$l$F$$$J$5$=$&!#(B
$B!!(BCAN-2002-0399 $B$OCf?H$,$G$-$F$^$9!#(B
$B!!(B2002.09.17 $B$N(B MS Word$B$KJ8=q$N%O%$%8%c%C%/$r5v$9LdBjE@(B $B$KDI5-$7$?!#(BCIACTech02-005$B!#(B
$B!!J?@.(B14$BG/(B7$B7n(B24$BF|!J?e!K(B17:30$B!A(B20$B!'(B50 $B3+:E$NBh(B 477 $B2sM};v2q!#D>8e$@$H8@$&$N$K!"%&%#%k%9%a!<%kAw?.A{$.$K$D$$$F!"2?$N5DO@$b$7$F$$$J$$LOMM!#(B $B$"$^$j$K%@%a$9$.!#(B
$B!!(B2002.09.24 $B$N(B $BIY;NDL(B HDD $BL5=~8r49$OI9;3$N0l3Q(B? $B9b29B?<>$N>u672<$G(BLSI$B$,7PG/Nt2=(B $B$KDI5-$7$?!#%=%K!
$B!!;~Be$O!V$U$D$&(B RAID 1$B!W$C$F%3%H$J$s$G$7$g$&$+!#$^$!!"0B$$$G$9$1$I$M$'!#(B
$B!!(B$B%5%s$,(BOpenSSL$B%W%m%8%'%/%H$K0E9f2=5;=Q$rDs6!(B (CNET) $B$NOC$K$O!"#173053 $B$b;2>H!#(BDebian GNU/Linux $B$5$s$O$I$&$5$l$k$s$@$m$&!#(B
$B!!(B2002.09.27 $B$N(B Tests of Anti-Virus Software: Comparison Test 2002-02 (Unix) Linux $B$KDI5-$7$?!#(B F-Secure AntiVirus $B$O!"(B--dumb $B%*%W%7%g%s$r$D$1$l$P$[$\(B 100% $B$NLOMM!#(B
$B!!(B2002.09.12 $B$N(B Apple QuickTime ActiveX v5.0.2 Buffer Overrun (a091002-1) $B$KDI5-$7$?!#$*$/$l$P$;$J$,$i!"(BApple $B%*%U%#%7%c%k>pJs$rDI5-!#(B QuickTime 5 for Windows $BMQ$N(B fix $B$O=P$J$$LOMM!#(B
TeraTerm Pro Web 3.1.2 - Enhanced Telnet/SSH2 Client (ayera.com)$B!#(B SSH2 $B$O$o$+$k$,!"AH$_9~$_(B web server $B$C$F!D!D!#D,ED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
squid 2.5-STABLE1 $B=P$F$$$^$9!#$$$m$$$m5!G=$,A}$($F$^$9!#(B acl $B$G(B referer $B$r@)8f$G$-$kOC$r(B Referer $B%j%/%(%9%H%X%C%@$N=|5n(B $B$KDI5-$7$^$7$?!#;32l$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
$B%Y%k8&5f=j!"O@J8YTB$$G8&5f
RC5-64 HAS BEEN SOLVED! (distributed.net)$B!#(B $BD9$$F.$$$G$"$C$?!D!D!#(B $B4XO"(B: distributed.net$B$,(B64$B%S%C%H0E9f!V(BRC5-64$B!W$N2rFI$K@.8y(B (INTERNET Watch)$B!#(B
$B!!(BMicrosoft FrontPage Server Extension 2000/2002 $B$K
$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#Ev=i(B FPSE 2000 for Windows 2000/XP
$B$@$1$@$C$?$,!"(BFPSE 2002 $BMQ!"(BFPSE 2000 for NT 4.0 $BMQ$bEP>l$7$F$$$k!#(B
Windows XP SP1 $B$K$O$3$N(B patch $B$,4^$^$l$F$$$k!#(B
$B$^$?!"(BFPSE 2002 $BMQ(B patch $B$rE,MQ$9$k$K$O!"$"$i$+$8$a%"%C%W%G!<%H(B patch
$B$rE,MQ$7$F$*$/I,MW$,$"$k$=$&$@!#(B
Q317296
$B$r;2>H$5$l$?$$!#(B
$B!!$J$*!"(BFPSE $B$,ITMW$J>l9g$O%"%s%$%s%9%H!<%k$7$F$7$^$&$N$,$h$$!#(B
$B%G%U%)%k%H$G$O%$%s%9%H!<%k$5$l$F$7$^$C$F$$$k$N$GCm0U$5$l$?$$!#(B
$B!!(BFPSE 2000 / 2002 for UNIX $B$K$O$3$NLdBj$O$J$$$=$&$@!#;2>H(B:
Update - Microsoft Security Bulletin MS02-053 (rtr.com)
FPSE for UNIX $B$r%5%]!<%H$7$F$$$k(B Ready-to-Run Software $B$K$h$k8x<08+2r!#(B
Microsoft FrontPage Server Extensions 2002 for UNIX
(Microsoft)
$B:G?7%P!<%8%g%s$O(B 5.0.2.2623$B!#$?$@$7!"(BHEAD / HTTP/1.0 $B$J$I$r
Microsoft FrontPage 2000 Server Extensions SR1.2: Downloads for UNIX-Based Servers
(Microsoft)
$B:G?7%P!<%8%g%s$O(B 4.0.2.4222$B!#(B
2003.02 $B$K(B Service Release 1.4 $B$H$$$&$b$N$,EP>l$7$?;~E@$G(B
FPSE 2000 $B$OBG$A$I$a$J$N$@$=$&$@!#(B
$B$1$s$N$\$d$-(B: 2002-12-10 shtml.dll (tdiary.net)
2002.12.13 $BDI5-(B:
$B!!(BMicrosoft PPTP
Server and Client remote vulnerability
$B$NOC!#(BCNET $B$N5-;v$K$h$l$P!"(BMicrosoft $B$OG$0U$N%3!<%I$N
$B!!(B2002.08.21 $B$N(B web $B%V%i%&%64XO"(B $B$KDI5-$7$?!#(BMS02-050: $B>ZL@=q3NG'$NLdBj$K$h$j!"(BID $B$,56Au$5$l$k(B (Q328145) $B$,2~D{!#(B Mac OS / Mac OS X $BMQ(B IE $B=$@5HG$,?7$?$KEP>l!#$^$@(B fix $B$,$J$$$N$O(B XP 64bit, Office 98/2001/v.X for Mac$B!"(B OutlookExpress for Mac$B!#(B
$B!!(BLinux $BMQ(B anti-virus soft 12 $B
$B!!(BComparison Test 2002-03 (Unix) FreeBSD, OpenBSD, Solaris $B$b=P$F$^$9!#(BSophos AntiVirus$B!"(BLinux $B$d(B FreeBSD $B$G$O(B 100% $B$J$N$K(B Solaris $B$G$O(B 94.6% $B$J$N$O$J$<(B?
$B!!F|K\%(%U%;%-%e%"$N5H2,$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):
$B!|(B1. $B!V(BF-Secure $B$@$1(B 80% $BBf!#!W$O3HD%;R@_Dj$N0c$$$K$h$k$b$N$G$9!#(B
$B!!!!!V(B--dumb$B!W%*%W%7%g%s$r;XDj$9$k$3$H$G$[$\A4$F$N%&%$%k%9$r8!=P$$$?$7$^$9!#(B
$B!!(Bav-test.org$B$NI>2ACf$N!V(BF-Secure$B!W$N9`L\$O3N$+$K(B80%$BBf$H$J$C$F$*$j$^$9$,!"$3$l$O!"%F%9%HCf$N(BF-Secure$B%3%^%s%I%i%$%sHG%9%-%c%J$N@_Dj$,B>$N%=%U%H%&%'%"$H0[$J$j!"%F%9%HBP>]%U%!%$%k$K4^$^$l$k$$$/$D$+$N3HD%;R$,8!::BP>]30$K$J$C$F$$$k$?$a$G$9!#(B
$B!!%U%!%$%kL>$rD>@\;XDj$9$k$+!V(B--dumb$B!W%*%W%7%g%s$r;XDj$7!"3HD%;R$K$h$i$J$$8!::$r9T$&$3$H$G!"$[$\A4$F$N%&%$%k%9$r8!=P$$$?$7$^$9!#(B $B7h$7$F(BF-Secure$B$N8!::%(%s%8%s<+BN$NG=NO$,Nt$C$F$$$k$o$1$G$O$J$$$3$H$r$4M}2r4j$$$^$9!#(B
$B!!$J$*!"3HD%;R$K$h$i$J$$8!::$r$7$?>l9g$N8!=PN($N0lIt$,!"(Bav-test.org$B$N0J2<$N%Z!<%8$N!V(BBest possible settings$B!W$N9`L\$G3NG'$G$-$^$9!#(B
$B!!!!!!!!(Bhttp://www.av-test.org/down/data/2002-02-en/results.xls
$B!!3HD%;R@_Dj$N7o$r4^$a$F3F%(%s%8%s$NF0:n>\:Y%3%a%s%H$,(Bav-test.org$B$N0J2<$N%Z!<%8$G$b3NG'$G$-$^$9!#(B
$B!!!!!!!!(Bhttp://www.av-test.org/down/data/2002-02-en/comments.txt
$B!!$^$?!"(BF-Secure$B$G$O(B24$B;~4VBN@)$G3hF0$9$k%&%#%k%98&5f%A!<%`$rMJ$7$F$*$j!"?75,$KH/@8$9$k%&%#%k%9$KBP$7$F$b?WB.$KBP1~$7$F$$$^$9$N$G!"%&%$%k%9$K46@w$9$k2DG=@-$O6K$a$F>/$J$$$H9M$($i$l$^$9!#(B
$B!|(B2. $B!V(BF-Secure $B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$$rH/I=(B (f-secure.co.jp) $B$J$s$F$N$b=P$F$^$9$,(B...$B!W$K$D$$$F$O!"(B"F-Secure $B%"%s%A%&%$%k%9(BLinux$B%2!<%H%&%'%$(B"$B$O%3%^%s%I%i%$%sHG(B(Linux$B%5!<%PHG(B)$B$H$OJL@=IJ$G$"$j!"%G%U%)%k%H@_Dj$G$[$\A4$F$N%&%$%k%9$r8!=P$$$?$7$^$9!#(B
$B!!!!(B(F-Secure$B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$(B:
$B!!!!!!!!(Bhttp://www.f-secure.co.jp/products/linux_gw/index.html )
$B!!@hF|H/I=$$$?$7$^$7$?!V(BF-Secure$B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$!W$G$OA4$F$N3HD%;R$r8!::$$$?$7$^$9$N$G!"$[$\A4$F$N%&%$%k%9$r8!=P$$$?$7$^$9!#(B
$B!!7h$7$F!"!V(BF-Secure$B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$!W$N%&%$%k%98!::G=NO$NG=NO$,Nt$C$F$$$k$o$1$G$O$J$$$3$H$r$4M}2r4j$$$^$9!#(B
$B!!!V(BF-Secure$B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$!W$K$D$$$F$O0J2<$N%Z!<%8$G(B90$BF|4V;nMQHG$b8x3+$7$F$*$j$^$9$N$GI,MW$K1~$8$FI>2AEy$K$4MxMQ$$$?$@$1$^$9$H9,$$$G$9!#(B
$B!!!!(BF-Secure$B%"%s%A%&%#%k%9(BLinux$B%2!<%H%&%'%$(B[90$BF|4VI>2AHG(B]:
$B!!!!!!!!(Bhttp://www.f-secure.co.jp/download/trial/index.html
2002.09.26 $B$O$3$N%Z!<%8$N99?7$O$"$j$^$;$s!#B?J,!#(B
$BK!NX8y$,(B2$BEYL\$NEEGH%8%c%C%/!!BfOQ$+$i1R@1%7%9%F%`$K43>D(B ($BKhF|(B)$B!#BgC@$@$J$"!#(B
$B!V@i$H@i?R!W$N(BDVD$B!!9qL1@83h%;%s%?!<$,HNGd85$K!VCm0U!W(B ($BKhF|(B)$B!#(B $B!V8=>u$N$^$^HNGd$rB3$1$k!W$N$@$=$&$G!#$^$C$+$C$+7O$N?M$O!"$^$C$+$C$+$K8+$($J$$:F@84D6-$r@0$($k$7$+$J$$LOMM!#(B
$BYGCW;v7oD4::CD(B $B#2#8F|GI8/(B$B!"(B
$B;38}(B $B9TJ}ITL@$N=w@-8x3+
$B$=$l$K$7$F$b(B $BL1
$B$S$o8P$N%l%8%c!<5,@)(B $B>rNc0F(B (NHK)$B!#(B
$B4XO"(B: $B<"2l8)H|GJ8P$N%l%8%c!
$B$"!"%+%a$b8+$?$3$H$,$"$k(B ($B5{$8$c$J$$$C$F!D!D(B)$B!#(B
$B$G$b$3$l$,$^$?%_%I%j%,%a(B ($B%_%7%7%C%T!<%"%+%_%_%,%a(B) $B$G30Mh$@$C$?$j$9$k$o$1$@!#(B
BeeAnywhere $B$J$s$F@=IJ$,$"$k$s$G$9$M!#(B
[security:00161] HFNETCHK 3.83 $B%j%j!<%9(B$B!#(B
$B$@$=$&$G$9!#(BREADME
$B$K$h$k$H!"$$$m$$$m5!G=$,A}$($F$$$k$h$&$G$9!#(B-sum $B$,$&$l$7$$$+$J!#(B
$B>.@tK,D+$NGX7J$rC5$k(B
(tanakanews.com)$B!#$?$$$X$s6=L#?<$$!#(B
NEWS HEADLINE
$B$"$N(BGoogle$B$,Am9g%K%e!<%9%5%$%H3+@_(B - $B9bB.<+F0%"%C%W$G>o$K@$3&:G?75-;v(B
(MYCOM PC Web)$B!#(Bgoogle $B$*$=$k$Y$7!#(Bnews.google.co.jp
$B$O$^$@B8:_$7$J$$LOMM!#(B
(info from $B%]%1%C%H%K%e!<%9(B)
penetration technique research site
$B$K(B
$B!V2~$6$s$5$l$?%5%$%H$N(BOpenPort(TCP)$B%i%s%-%s%0!J(B2002.08.01-31$B!K!W(B
$B$,=P$F$$$^$9!#(B
$BAuCe7?!H%m%\%C%H%9!<%D!I3+H/(B
$B5SNO$N0lIt$rJd=u(B ($BCfF|(B)$B!#$*$)!"6/2=309|3J(B!
$B$3$l$G$^$?0lJb!V1'Ch$N@o;N!W$K6a$E$$$?!#%+%b!<%s(B! ($B$O%(%$%j%"%s(B 2)$B!#(B
$B$H$$$C$F$b8=>u$N(B 20kg $B$OF0NO$,@Z$l$k$H$J$+$J$+%-%D$=$&$@$,!#(B
$B!!(Bapache 2.0.42 $B=P$^$7$?!#(Bmod_dav $B$G(B DoS $B967b$5$l$k%P%0$,(B fix $B$5$l$F$$$k$=$&$G$9!#(B
$B!!(Bpath MTU discovery $B$,DL$k$h$&$J(B wall / $B%U%#%k%?$r9=C[$9$k$h$&$K?4$,$1$^$7$g$&!#(BICMP need fragment $B$O$J$k$Y$/%U%#%k%?$7$J$$$h$&$K$7$^$7$g$&!#(B
$B!!(Bsourceforge
$B$+$i$@$H(B tripwire-2.3.1-2 $B$,F~
$B!!(B#170987 $B$G(B jbeef $B;a$O(B
$B;XE&$r$7$?B&$b!"!VLdBj$J$$!W$HH]Dj$5$l$k$H!J$=$7$F$=$l$,4V0c$C$F$$$k$H!K$=$l$K:FH?O@$9$k$N$KM>7W$J%(%M%k%.!<$rI,MW$H$7$F$7$^$&$N$,?M>p$@$H;W$$$^$9(B
$B$H=R$Y$F$$$k$o$1$@$,!"$=$ND>8e$+$i!"
$B!!8D?ME*$K$O!"$d$C$Q$j%3%i%`$,6=L#?<$$!#(B
$BEA8@%5!<%S%9L$J'$$$H623e(B$B!#(B 10 $B?MBaJa$@$=$&$G!#(B $B%o%s@Z$j%b%N(B?
[aml 29987] $B%S%C%0%S%8%M%9$N1"$K(B$B!#(B NHK$B%9%Z%7%c%k!!JF%m@\6a(B $BJQ$o$k%U%m%s%H%i%$%s(B $B$G$O(B$BJsF;$5$l$J$+$C$?OCBj(B$B$@$=$&$G!#(BNHK$B!"$5$9$,$G$9!#(B
[aml 29962] $BJ]0B1!!"(B8$B7n(B7$BF|0JA0$K$O%7%e%i%&%I$N$3$H$O2?$bCN$i$J$$!](B9$B7n(B17$BF|8r>D$GJ]0B1!!](B$B!"(B [aml 29963] $BJ!EgBhFs86H/#39f5!$N%7%e%i%&%I$R$S3d$l1#JC$KJ]0B1!$,4XM?(B$B!#(B $BEENO20$r!VJ]0B!W$9$k1!$G$"$k>Z5r$,$^$?$b$d!#(B
[aml 29986] $BE>:\!&7y$,$i$;$N
infovlad.net $B$X$N(B link $B$O(B $B!Z:_F|![%O%&%9%P!<%b%s%H%+%l!<$N(BCM$B!Z1"KE![(B 2 ($B$N85%9%l(B) $B$GCN$C$?$s$G$9$,(B (info from EVERYDAY PEOPLE $B$G$9$,(B)$B!#(B $B$7$+$7!"$3$s$J$N$h$/5$$,$D$/$J$"!#(B
GnuPG 1.2 $B$,=P$?$=$&$G$9!#(B$BJQ99E@$?$/$5$s(B$B!#(B
KDDI$B!$IT@5%@%$%d%k%"%C%WBP:v$GFCDj9q$X$NDLOC$r5Y;_(B ($BF|7P(B IT Pro)$B!#(B $B!VHH:a9q2H!W07$$(B?
$B!V%"%s%A!&%&%$%k%9$G%7%'%"(B10$B!s$rC%$&!W!=!=?75,;2F~$N4Z9q%"%s%i%\(BCEO ($BF|7P(B IT Pro)$B!#(B
$BB>
$B@8B8#4?M!VL@3N$J5"9q0U;W<($5$:!W$HLL2q$NCs1Q8x;H(B ($BFIGd(B)$B!#(B
$B<($;$k$o$1$,$J$$$@$m$,!D!D!#(B
$B9pH/
Internet Week 2002 $B%W%m%0%i%`(B$B!#:#G/$O$*$b$7$m$=$&$J9`L\$,$1$C$3$&$"$k$J$"!#(B
T13 : $BIT@5%"%/%;%9$N
$B!!(BMac OS X 10.2, 10.2.1 $B$K
$B!!(B2002.09.21 $B$N(B Bypassing SMTP Content Protection with a Flick of a Button $B$KDI5-$7$?!#%H%l%s%I%^%$%/%m(B solution 4732/4742 $BEP>l!#(B
$B!!HH?M$O=;M'%Y!<%/%i%$%H$N%Q%C%1!<%8Iu;_:`!V(BEME-U$B!W$NLOMM!#(B $B1F6A$,6K$a$F9-$$HO0O$K$o$?$k62$l$"$j!#(B HDD$BITNIIJ$NL5=~8r49$GIY;NDL$NIiC4$O(B100$B2/1_D6$9(B ($BF|7P(B BP) $B$N$@$=$&$G!#$9$4$$$M!#(B
$B!!(BIO DATA: $BJ@
$B!!(B$B%=%K! (PC Watch)$B!#(B
$B!!(B$BIY;NDL(BHDD$BITNI!"BP:vCY$lB>@=IJ$XGH5Z7|G0(B
($BF|7P(B BizTech)$B!#(B
2002.09.30 $BDI5-(B:
2002.10.02 $BDI5-(B:
$B!!(BVisual C++ .NET $B$N(B /GS $B%9%$%C%A(B $B$d(B IBM $B9>F#$5$s$N(B ProPolice (SSP)$B!"(B FreeBSD packages/ports $B$K$bF~$C$F$$$k(B libparanoia $B$,>R2p$5$l$F$$$J$$$N$O$J$<(B?
$B!!(B2002.09.17
$B$N(B
CERT Advisory CA-2002-27 Apache/mod_ssl Worm
$B$KDI5-$7$?!#0!
[aml 29897] $BK!<99T5!4X$N%0%m!<%P%k2=8&5f2q(B($B!V%5%$%P!
[debian-announce:00032] Debian $B>&I8$NEPO?$K$D$$$F(B$B!#(B
$B@h
$B%5%s$,(BOpenSSL$B%W%m%8%'%/%H$K0E9f2=5;=Q$rDs6!(B (CNET)$B!#(B $BBJ1_6J@~0E9f$@$=$&$G!#(B
$BF|K\%O%`;R2q
$BElKLEENO$b#9#8G/=)8!::$GH/3P$N=}$NC{8u!"8xI=$;$:(B$B!"(B $BCfItEENO$b86H/%H%i%V%k1#$7!!IM2,86H/$9$Y$FDd;_$X(B (asahi.com)$B!#$1$C$-$g$/$_$s$J$d$C$F$k$N$M!#(B $BGz?4CO$b(B $B%H%i%V%k1#$Z$$$5$i$K#87o!!ElEE(B ($B;:7P(B) $B$@$=$&$G!#$5$9$,$G$9!#(B
$BBhFs2s(B $B>pJs%;%-%e%j%F%#4XO"$ND4::!&3+H/$K4X$9$k8xJg(B (IPA)$B!#(B
$B!!(BRFC2046: Multipurpose Internet Mail Extensions (MIME) Part Two: Media Types $B$N(B section 5.2.2.1 $B$GDj5A$5$l$F$$$k(B Fragmentation and Reassembly $B5!9=$rMxMQ$9$k$H!"%"%s%A%&%#%k%9%2!<%H%&%'%$$r2sHr$7$F%&%#%k%9$rAw$j9~$`$3$H$,2DG=$K$J$k!"$H$$$&OC!#(BNIDS $B2sHr%M%?$K$b$=$&$$$&$N$,$"$j$^$7$?$M$(!#(B
$B!!2sHrJ}K!$H$7$F$O!"%U%!%$%"%&%)!<%k$J$I$G(B message/partial $B$J%a!<%k$rC!$-Mn$H$7$F$7$^$&J}K!$,$"$k!#$H8@$C$F$b!"$A$g$C$HMpK=$@$h$M$'!#$d$O$j%"%s%A%&%#%k%9%2!<%H%&%'%$<+?H$,$-$A$s$HBP1~$9$k$3$H$,K>$^$7$$$o$1$G!#(B $B855-;v$G$O(B symantec $B$d(B trendmicro $B$J$I$$$/$D$b$N%W%m%@%/%H$NBP1~>u67$,=R$Y$i$l$F$$$kB>!"(B MIMEDefang $B$G$O(B 2.21 $B$G(B fix $B$5$l$?$=$&$@!#$^$?(B amavis-perl $B$G$bMxMQ$5$l$F$$$k(B MIME::Tools 5.411a $B$K$b(B$B$3$NLdBj$,$"$j(B$B!"(B patch $B$H!"$3$N(B patch $B$rE,MQ$7$?(B MIME-tools-5.411a-RP-Patched.tar.gz $B$,8x3+$5$l$F$$$k!#(B
$B!!$J$*!"3F<+$G>u67$r;n$7$?$$>l9g$O(B http://www.gfi.com/emailsecuritytest/ $B$K(B go! $B$i$7$$!#(B
$B!!(BCVE: CAN-2002-1121$B!#(B CERT Vulnerability Note: VU#836088$B!#(B
$B!!(Bsolution 4742: InterScan VirusWall UNIX: SMTP$B!'J,3d%a!<%k$X$NBP1~(B$B!"(B solution 4732: InterScan VirusWall NT: SMTP$B!'J,3d%a!<%k$X$NBP1~(B ($B%H%l%s%I%^%$%/%m(B)$B!#(Bmessage/partial $B$r3VN%$7$F=*$j!"$N$h$&$KFI$a$k!#(B
$B!!(BMicrosoft Java VM build 3805 $B0JA0$K(B 3 $B$D$N
$B$"$i$f$k(B DLL $B$rFI$_9~$_!"
$B;HMQITG=967b(B (IE $B$N0[>o=*N;(B) $B$,2DG=$G!"G$0U$N%3!<%I$N
Java $B%"%W%l%C%H$+$i$9$Y$F$NG$0U$NA`:n$r
$B$H$$$&!"$$$:$l$b6K$a$F4m81$J
$B!!$J$*!"$3$N(B patch $B$rE,MQ$7$F$b!"(Bjview $B%3%^%s%I$J$I$G3NG'$G$-$k(B build $BHV9f$KJQ2=$O$J$$$h$&$@!#(BKB Q329077
$B$K$O(B
$B!!$H$3$m$,!"(BMicrosoft Java VM $B$K$O$BJF(BMicrosoft$B$N(BJava$B%;%-%e%j%F%#!<%[!<%k=$@5$OIT==J,$HH/8+
$B!!(BTechnical information about the vulnerabilities fixed by MS-02-52$B!#(B
This update upgrades your Microsoft VM with the
5.00.3807 patch
$B$H$"$j!"<($5$l$F$$$k%l%8%9%H%j$K$b(B
"Version"="5,00,3807,0"
$B$J$s$F=q$$$F$"$k$N$@$,!"(BMS02-052 $B<+?H$K$O$o$6$o$6!V(B$BCm(B : Jview $B$K$h$jI=<($5$l$k%P!<%8%g%sHV9f$K4X$o$i$:!">e5-$N%l%8%9%H%j%-!<$O$3$N=$@5%W%m%0%i%`$N@5$7$$%$%s%9%H!<%k$r3NG'$9$kMWAG$H$J$j$^$9(B
$B!W$H=q$$$F$"$k$N$G!"$=$&$$$&$3$H$J$N$@$m$&!#$$$^$$$AG2002.10.01 $BDI5-(B:
$B!!(BWindows 2000 $B%?!<%_%J%k%5!<%P!
$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$^$?(B Windows XP SP1 $B$G$O$3$NLdBj$O=$@5$5$l$F$$$k!#(B
$B!!;2>H(B: Microsoft Windows XP Remote Desktop denial of service vulnerability$B!#(B
$B!!(B2002.09.19 $B$N(B $BKI1RD#$N%G!<%?N.=P$GO*Dh!J>e!K(BIT$B6H3&$N2<@A$19=B$$N4m$&$5(B $B$KDI5-$7$?!#!J2l!#(B
$B!!(BHTML $BHG(B:
SecurityFocus Newsletter #159[1/2] 2002-8-19->2002-8-23$B!"(B SecurityFocus Newsletter #159[2/2] 2002-8-19->2002-8-23
$B!!%F%-%9%HHG(B:
$B@/I\!"6H3&!"9qL1$,0l4]$K!=!=%[%o%$%H%O%&%9$N%M%C%H%;%-%e%j%F%#@oN,(B$B!"(B $B%M%C%H%;%-%e%j%F%#6/2=$K>h$j=P$9JF@/I\(B (ZDNet)$B!#(B
[aml 29909] $BYGCW2HB2$KBP$9$k$BYGCW5?OG;v7o$O!"F|K\@/I\$KKLD+A/$X$N?)NH;Y1g$r$5$;$J$$$3$H$rA@$$$H$7$F!":G6a$K$J$C$F9M$(=P$5$lH/I=$5$l$?;v7o$J$N$G$"$k$k(B
$B!W(B
$B$O$b$C$H%"%l$@$J$"!#(B
$BBh0l2s(BFSIJ$B5;=Q%;%_%J!<(B$B!#(B 2002.10.21$B!"F|K\650i2q4[(B ($BEl5~ET@iBeED6h(B)$B!"M-NA!#(BDebian $B$,B?$$$J$"!#(B
Debian Security Advisory DSA-136-1 openssl$B!"(BDSA-136-1$B!A(B3 $B$NFbMF$,(B merge $B$5$l$F$k$s$@$+$i!"(B DSA-136-1 $B$C$FI=5-$OJQ$@$H;W$&$N$@$,!#KAF,$N(B DSA-136-1 $B$C$F%H%3$@$18+$F!V$^$@JQ$C$F$M$'$J!<2?$d$C$H$s$8$c!
$B5~ETD+F|%7%M%^(B$B!"(B $B%A%g%`%9%-!<(B 9.11 Power and Terror $B$N0FFb=P$F$^$9!#(B 2002$BG/(B10$B7n(B12$BF|!A(B25$BF|!!%7%M%^(B1$B!!%l%$%H%7%g!<(B 20:45$B!A(B22:04 $B$@$=$&$G$9!#8+F($5$J$$$h$&$K$7$J$/$A$c!#(B
$B%"%I%P%s%9%H!&%U%!%$%k%7%9%F%`!&%$%s%W%j%a%s%?! (ibm.com/jp)$B!#(B (info from slashdot.jp)
Windows XP Service Pack 1 $B@5<0$KEP>l$7$F$$$^$9!#(B
http://www.linuxsecurity.com/ $B$K(B ($B$H$$$&$+(B packetstorm $B$X$N(B link $B$J$s$@$1$I(B) openssl-too-open.tar.gz $B$J$s$F$N$,=P$F$^$9$M!#(B $B$&!<$`!"$-$l$$$K7h$^$j$9$.!#$^$:$$$C$9!#(B $B$^$@(B$BBP:v(B$B$G$-$F$J$$?M!D!D$$$J$$$G$9$h$M(B?
$B$A$J$_$K!"(BRed Hat Linux $B$K7b$C$F$_$?$H$3$m!"(BRH 7J $B$@$H$3$s$J(B log $B$,(B /var/log/httpd/error_log $B$KF~$j$^$9!#(B
[Thu Sep 19 13:18:38 2002] [error] mod_ssl: SSL handshake failed (server XXX.ryukoku.ac.jp:443, client XXX.XXX.XXX.XXX) (OpenSSL library error follows)
[Thu Sep 19 13:18:38 2002] [error] OpenSSL: error:1406908F:SSL routines:GET_CLIENT_FINISHED:connection id is different
RH 7.2J $B$@$H$3$&$G$9(B:
[Thu Sep 19 17:40:04 2002] [error] mod_ssl: SSL handshake failed (server XXX.ryukoku.ac.jp:443, client XXX.XXX.XXX.XXX) (OpenSSL library error follows)
[Thu Sep 19 17:40:04 2002] [error] OpenSSL: error:1406908F:lib(20):func(105):reason(143)
chkrootkit 0.37 $B=P$F$^$9$M!#(B
$B%;%-%e%j%F%#!&%S%8%M%9$KBT$A9=$($kFqLd(B ($BF|7P(B IT Pro)$B!#(B $B$3$NJ,Ln!"(B10 $BG/(B 20 $BG/$Nu67$G?.Mj$r4s$;$m$C$?$C$FL5M}$G$7$g$&!#(B
Easel
$B$N(B 2.2.1b4 $B$,=P$F$$$^$9!#(B
Easel is a general-purpose modeling/simulation language and tool that is used to predict behavior in a seemingly uncertain world
$B$H$$$&%b%N$@$=$&$G!#(B
$B!!(B2002.06.25 $B$N(B WindowsXP$B$N(B5/30$BLdBj$r9M$($k%Z!<%8(B $B$KDI5-$7$?!#(BWindows XP SP1 $B$rE,MQ$9$k$H!"LdBj$,>CLG$7$F$7$^$&(B?!
$B!!@5<0$KEP>l$7$F$$$^$9!#(BIE 6 SP1 README $B$bFI$_$^$7$g$&!#FC$K!"%;%-%e%j%F%#3HD%$N$?$a$N5!G=(B: $B0J9_!#(B
$B!!(B2002.07.31 $B$N(B OpenSSL Security Advisory [30 July 2002] $B$KDI5-$7$?!#(BDebian $B$N$5$i$K?7$7$$(B fix package $B=P$F$^$9!#(B Turbolinux $B$N7Y9p!#(B
$B!!(B2002.09.17 $B$N(B UNIX fixes $B$KDI5-$7$?!#(BFreeBSD-SA-02:39.libkvm - Applications using libkvm may leak sensitive descriptors $B$NItJ,$KDI5-$H=$@5!#%P%+$9$.(B > $B26!#(B
$B!!$I$&9M$($F$b!VI9;3$N0l3Q!W!#$3$3$G$bI,MW$H$5$l$F$$$k$N$O!V9=B$2~3W!W$J$N$@$,!"!D!D!#(B
$B!!(B2002.09.17 $B$N(B MS Word$B$KJ8=q$N%O%$%8%c%C%/$r5v$9LdBjE@(B $B$KDI5-$7$?!#(BMicrosoft $B8x<08+2rEP>l!#(B
$B!!?tJ,$GFI$a$F$7$^$&$N$@$1$I!"7P83>e(B ($B>P(B)$B!"$3$N5-;v$r=q$/$N$O$?$$$X$s$@$C$?$@$m$&$H;W$&!#$=$s$JO+:n$rL5NA$GFI$a$k$N$OK\Ev$K$"$j$,$?$$$3$H$G$9!#(B
$BF?L>4uK>$5$s!"j5$"$j$,$H$&$4$6$$$^$9!#(B
$B4Z9q%"%s%i%\$,F|K\$N%;%-%e%j%F%#;T>l$K;2F~(B ($BF|7P(B IT Pro)$B!#(B
$BB>
$B%A%'%C%/!&%]%$%s%H!$(BFireWall-1$B$r(BIPv6$BBP1~$K$9$k%b%8%e!<%k$rDs6!(B ($BF|7P(B IT Pro)$B!#(B $BMhG/$N(B N+I TOKYO $B$"$?$j$J$i@)8B$J$7HG$K$J$C$F$$$k$N$+$J$"!#(B
Tea Room for Conference No.1065 $B$K!"(B$B%$%s%?!<%M%C%H6(2q(B$B$N(B$BAGE($J%i%$%;%s%9(B$B$NOC$,=P$F$$$^$9$M!#$^$k$G=!65CDBN$@$J$"!#(B
$B=;4p%M%C%HJ}LL(B: $B$_$s$J$G(B11$B$1$?$KK!N'$K4p$E$/0[5A?=$7N)$F$r(B! (seach.jkcc.gr.jp)$B!#(B [aml 29844] $B$NFbMF$,JdB-!&>\:Y2=$5$l$F$$$^$9!#$o$+$j$d$9$/=q$+$l$F$$$^$9!#(B $B!:@Z$O(B$B!V0[5A?=N)$F$K78$k=hJ,$,$"$C$?$3$H$rCN$C$?G/7nF|$NMbF|$+$i(B 60 $BF|!W(B= 2002.10.04 $BI,Ce(B$B!"$@$=$&$J$N$G!"$$$=$.$^$7$g$&!#(B $B$$$7$O$i$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
$B=;4p%M%C%HJ}LL(B: [aml 29844] Fwd: $B=;4p%M%C%H$K!ZK!N'$K4p$E$/!V0[5D?=$7N)$F!W![$r!*(B$B!"(B [aml 29863] [$B>pJs!O(B $B=;4p%M%C%H$K4X$9$kOC$N%S%G%*!J@6?eJYJ[8n;N!'A49q;TL1%*%s%V%:%^%sA49qBg2q(B $B>pJs8x3+J,2J2q$K$F!K(B$B!#(B
$BKLD+A/J}LL!"(B8 $BL>;`K4$H$O!D!D$&!<$`!D!D!#0dBN$rAw4T$N>e?H853NG'!"$/$i$$$O$7$F$b$i$o$J$$$H2HB2$OG
$B>pJs=hM}3X2q4X@>;YIt%A%e!<%H%j%"%k9V1i2q(B
$B!X>pJs%;%-%e%j%F%#$N
[harden-mac:0078] $B%+%`Aw$j2r>{(B$B!#(B
NHK $B$N%`!<%S!
Windows XP $BF|K\8lHGMQ(B SP1 $B$i$7$-$b$N(B$B$,(B
get $B$G$-$k$h$&$G$9$M!#(B
$B
$B@5<0H/I=A0$N$b$N$J$N$G!"%$%s%9%H!<%k$7$?$"$H2?$,5/$3$C$F$b(B
at your own risk $B$H$$$&$3$H$G!#(B
$B!Z>pJs%;%-%e%j%F%#%;%_%J! (IPA ISEC)$B!#(B
$B:#G/$b3+$+$l$k$h$&$G$9!#(B
$B8&5fJs9p!V%/%m!<%s$K$O!"$[$\3No$,H/@8$9$k!W(B (WIRED NEWS)$B!#$$$/$D$b$NCO0h$G(B go $B$,$+$+$C$F$$$k$O$:$@$,!D!D!#(B
$B%d%U%*%/$GBg5,LO:>5=;v7oH/@8(B (slashdot.jp)$B!#$7$g$;$s8D?MGdGc$N@$3&$G$9$+$i$M$'!D!D!#(B
VMware 3.2 $B$,=P$?$h$&$G$9$M!#(B"Designed for Windows"
$B$r
$B$C$F!"!V%V%j%C%8%M%C%H%o!<%/$r:o=|Cf!W$G;_$^$C$F$k$8$c$s(B > 3.1 $B$N%"%s%$%s%9%H!<%k!#$0$O$!(B ($BEG7l(B)$B!#(B
$B7k6I%O!<%I%j%;%C%H$7$F$7$^$C$?!#(B
$B%$%s%9%H!<%kCf!"8+;v$K(B
MS02-050
$B$NI{:nMQ$,H/@8$7$^$9$M$(!#$;$C$+$/(B "Designed for Windows" $B
$B!!;2>H(B: Security side-effects of Word fields$B!#(B $B1#$7%U%#!<%k%I!"$G$9$+!D!D!#(B
$B!!(B$BJs9p$5$l$?(B Microsoft Word $B%U%#!<%k%I$N@H$B:GA1$N%;%-%e%j%F%#$N$?$a$K!"%^%$%/%m%=%U%H$O$*5RMM$K(B Word 2002 (Office XP) $B$r$4MxMQ$$$?$@$/$3$H$r?d>)$7$^$9(B
$B!W(B
$B$H$$$&$N$O!"$^$"!"(BMicrosoft $B$H$7$F$O!"$=$&$J$s$@$m$&$J$"!#(B
$B!!(BCIACTech02-005: Understanding Capturing Files with Microsoft Word Field Codes (CIAC)$B!#(B $B>\:Y$J2r@b!#(B
$B!!(BMS02-059: Word $B%U%#!<%k%I$*$h$S(B Excel $B$N30It%G!<%?99?7$NLdBj$K$h$j!">pJs$,O3$($$$5$l$k(B (Q330008) $BEP>l!#(BWord 97/98/2000/2002, Excel 2002, Word 98/2001/X for Macintosh $B$GLdBj$,H/@8$9$k!#(B Word 2000/2002, Excel 2002, Word 98/2001/X for Macintosh $B$K$D$$$F$O=$@5%W%m%0%i%`$b$"$k!#(BWord 97/98 for Windows $B$@$1!"$^$@(B patch $B$,$J$$!#(B
FreeBSD-SA-02:39.libkvm - Applications using libkvm may leak sensitive descriptors
sgid kmem $B$J%"%W%j$+$i5/F0$7$?%W%m%;%9$+$i$O(B /dev/mem $B$*$h$S(B /dev/kmem $B$rD>@\FI$a$J$$$O$:$J$N$K!"pJs(B: [VulnWatch] iDEFENSE Security Advisory 09.16.2002: FreeBSD Ports libkvm Security Vulnerabilities$B!#(B
patch $B$,$"$k$N$GE,MQ$9$k$+!"5-:\$N=$@5:Q$_%P!<%8%g%s$r(B cvsup
$B$9$kEy$7$FF~
$B:4F#$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):
> patch $B$,$"$k$N$GE,MQ$9$k$+!"5-:\$N=$@5:Q$_%P!<%8%g%s$r(B > cvsup $B$9$kEy$7$FF~R2p$5$l$F$$$^$9!#@EE*%j%s%/$7$F$$$k%P%$%J%j$r(B $B:F9=C[$9$kI,MW$O$"$k$b$N$N!":#2s$N=$@5$K4X$7$F!":F5/F0$O(B $BI,$:$7$bMW5a$5$l$^$;$s!#(B $B$^$?!"(B > sgid kmem $B$J%"%W%j$+$i5/F0$7$?%W%m%;%9$+$i$O(B > /dev/mem $B$*$h$S(B /dev/kmem $B$rD>@\FI$a$J$$(B > $B$O$:$J$N$K!"r7o$O(B $B!V(Bsgid kmem $B$5$l$F$$$k$3$H!W$G$O$J$/(B $B!V?F%W%m%;%9$,(B /dev/kmem $B$r%*!<%W%s$7$F$$$k$3$H!W$G$9$7!"(B exec(2) $B$G(B descriptor $B$,EO$5$l$l$P!"$=$l$K$O%"%/%;%9(B $B$G$-$k$N$,IaDL$G$9$h$M!#(B $B:#2s$NLdBj$NMW$O!"%"%/%;%9$K9b$$8"8B$,I,MW$J%U%!%$%k$N(B descriptor $B$O(B exec(2) $B$7$?%W%m%;%9$KEO$5$J$$$h$&(B close-on-exec $B$r;XDj$9$Y$-$J$N$KBP$7$F!"(Bclose-on-exec $B$r(B $B;XDj$9$k$?$a$NJ}K!$,Ds6!$5$l$F$$$J$+$C$?!"$H$$$&ItJ,$K$"$j$^$9!#(B $B$D$^$j!VD>@\FI$a$J$$$O$:!W$J$N$G$O$J$/$F!"(B $B!VFI$a$J$$$h$&$K$9$Y$-$J$N$K!"$=$&$J$C$F$$$J$$!W$H$$$&$N$,(B $B@5$7$$M}2r$@$H;W$$$^$9!#(B
kernel $B$X$2$X$2ItJ,$N4V0c$$$OCWL?E*$J$N$G(B <s> $B$G0O$C$FD>$7$F$*$-$^$7$?!#(B $BF|K\8lHG$N(B Re: ANNOUNCE: FreeBSD Security Advisory FreeBSD-SA-02:39.libkvm $B$b;2>H!#$D!<$+$A$c$s$HFI$a(B > $B26!#(B
[RHSA-2002:190-06] Updated gaim client fixes URL vulnerability
7.0 $BMQ!#(B
[RHSA-2002:189-08] Updated gaim client fixes URL vulnerability
7.1$B!A(B7.3 $BMQ!#(B
[RHSA-2002:036-26] Updated ethereal packages available
6.2/7.0/7.1 $BMQ!#(B
[RHSA-2002:188-08] New wordtrans packages fix remote vulnerabilities
7.3 $BMQ!#(B $B;2>H(B: Guardent Client Advisory: Multiple wordtrans-web Vulnerabilities
NetBSD SA $B$,(B$BBgNL2~D{(B$B!#(BNetBSD 1.6 $BEP>l$K$"$o$;$F(B $B2~D{$5$l$F$$$k$h$&$G$9!#$^$?!"(B2002-015 $B$H(B 2002-016 $B$O(B
NetBSD-SA2002-015 and NetBSD-SA2002-16 are pending advisories awaiting disclosure co-ordination with third parties. The issues they will describe are fixed in NetBSD-1.6 and NetBSD-current.
$B$J$N$@$=$&$G$9!#(B
NetBSD Security Advisory 2002-006: buffer overrun in libc/libresolv DNS resolver
NetBSD Security Advisory 2002-007: Repeated TIOCSCTTY ioctl can corrupt session hold counts
NetBSD Security Advisory 2002-009: Multiple vulnerabilities in OpenSSL code
NetBSD Security Advisory 2002-011: Sun RPC XDR decoder contains buffer
NetBSD Security Advisory 2002-012: buffer overrun in setlocale
NetBSD Security Advisory 2002-013: Bug in NFS server code allows remote
NetBSD Security Advisory 2002-014: fd_set overrun in mbone tools and pppd
NetBSD Security Advisory 2002-017: shutdown(s, SHUT_RD) on TCP socket does not work as intended
NetBSD Security Advisory 2002-018: Multiple security isses with kfd daemon
$B!!(BAES (Rijndael) $B$H(B Serpent $B$K
$B2a<:$NM-L5$NH=CG$K$O!$!H6H3&I8=`!I$K1h$C$?%j%9%/4IM}$r9T$C$F$$$k$+$I$&$+$,O@E@$H$J$k!#B;32$rM=KI$9$k$?$a$KAj1~$NBP:v$r;\$7$F$$$l$P!$Bh;0$B$H$$$&$h$&$JOC$O!"(B$BBh(B 1 $B2s(B STPP $B%;%-%e%j%F%#BP:v%;%_%J!<(B $B$G$b%H%l%s%I%^%$%/%m$N5WJ]$5$s$,KAF,$G$*$C$7$c$C$F$$$i$C$7$c$$$^$7$?$M!#(B $B5WJ]$5$s$O$b$A$m$s!"!V$$$^$I$-%&%#%k%9BP:v$J$7$G$O%@%a%@%a$G$7$g$&!W$H$$$&OC$r$5$l$?$N$G$9$,!#(B
$B!!(B2002.07.31 $B$N(B OpenSSL Security Advisory [30 July 2002] $B$KDI5-$7$?!#(BOpenSSL 0.9.6g $BOC$H3F%Y%s%@!<$G$N:G?7$N(B fix $B$N>u67$r$^$H$a$F$_$?!#(B Debian $B$N?7$7$$(B fix package $B=P$F$^$9!#FC$K$^$@(B potato $B$N?M!":#$9$0E,MQ$7$h$&!#(B
$B!!(BOpenSSL $B7j(B $B$rFM$/(B worm $B$,EP>l!#(B$B:#$N$H$3$m(B$B!"(B $B!V(Bmod_ssl $B$,M-8z$J(B Linux $B>e$N(B Apache$B!W(B $B$,967bBP>]$NLOMM!#967b$O(B https (443/tcp) $B$rDL$8$F9T$o$l$k$N$G!"$3$l$r:I$$$G$"$l$P!"$H$j$"$($:$3$N(B worm $B$+$i$N967b$OKI$0$3$H$,$G$-$k!#(B
$B!!:#2sBP>]$K$J$C$F$$$k
$B!!(Bworm $B$K$h$k967b$,@.8y$9$k$H(B DDoS $B967bMQ$N%=%U%H$,?"$($D$1$i$l$k$=$&$@!#$3$$$D$O(B 2002/udp $B$r;H$C$FDL?.$r9T$&$=$&$J$N$G!"$3$l$b:I$$$G$7$^$&$N$,$h$$!#(B
$B!!4XO">pJs(B:
$B6[5^Js9p(B - OpenSSL $B$N@H
$BF|K\$G$b46@w;vNc$,H/8+$5$l$F$$$k$h$&$G$9!#Cm0U$7$^$7$g$&!#8&5f$N$?$a$K(B 1 $BI$$[$7$$$1$I!"8=>u$N
Analysis:
OpenSSL Vulnerabilities (incidents.org)
$B967bBP>]$O!"(B$B:#$N$H$3$m(B
$B$N$h$&$G$9!#(B
struct archs {
char *os;
char *apache;
int func_addr;
} architectures[] = {
{"Gentoo", "", 0x08086c34},
{"Debian", "1.3.26", 0x080863cc},
{"Red-Hat", "1.3.6", 0x080707ec},
{"Red-Hat", "1.3.9", 0x0808ccc4},
{"Red-Hat", "1.3.12", 0x0808f614},
{"Red-Hat", "1.3.12", 0x0809251c},
{"Red-Hat", "1.3.19", 0x0809af8c},
{"Red-Hat", "1.3.20", 0x080994d4},
{"Red-Hat", "1.3.26", 0x08161c14},
{"Red-Hat", "1.3.23", 0x0808528c},
{"Red-Hat", "1.3.22", 0x0808400c},
{"SuSE", "1.3.12", 0x0809f54c},
{"SuSE", "1.3.17", 0x08099984},
{"SuSE", "1.3.19", 0x08099ec8},
{"SuSE", "1.3.20", 0x08099da8},
{"SuSE", "1.3.23", 0x08086168},
{"SuSE", "1.3.23", 0x080861c8},
{"Mandrake", "1.3.14", 0x0809d6c4},
{"Mandrake", "1.3.19", 0x0809ea98},
{"Mandrake", "1.3.20", 0x0809e97c},
{"Mandrake", "1.3.23", 0x08086580},
{"Slackware", "1.3.26", 0x083d37fc},
{"Slackware", "1.3.26",0x080b2100}
};
$B!!4XO"JsF;(B:
Slapper $B%o!<%`!!9T@/I\!"<+<#BN$G%?!<%2%C%H$K$J$k$N$O(B 38 IP$B%"%I%l%9(B(2002.9.16) (netsecurity.ne.jp)
Slapper$B%o!<%`!"967b$N$?$a$NJbJ<%^%7%s$rAH?%Cf(B (ZDNet / $B%m%$%?!<(B)
$B!X%j%J%C%/%9!Y%5!<%P!<$G%M%C%H%o!<%/$r:n$k%o!<%`!X%9%i%C%Q! (WIRED NEWS)
$B!!$5$C$=$/0!
$B!!(Bopenssl-too-open.tar.gz $B$J$s$F$b$N$b$"$k$N$G!"FCDj%U%!%$%k$NM-L5$@$1$G%d%i%l6q9g$rH=CG$7$?$j$7$J$$$h$&$K$7$^$7$g$&!#(B
$B!!(B$B!V%&%$%k%9$N?J2=!W$r<($7$?(BSlapper$B%o!<%`(B (ZDNet)$B!#(B $B$3$l$+$i$O(B P2P $B$,N.9T$j$J$s$G$7$g$&$+!#(B
$B9pH/
$BF|K\$N$/$i$C$/%5%$%H>pJs(B$B$5$s$,$^$?0\E>$7$F$$$^$9!#(B
2 $BEY$"$k$3$H$O(B 3 $BEY$"$k$K(B 100 $B$^$k$Z(B (^^;)$B!#(B
$B$@$+$i869F=q$1(B > $B26!#(B
$B$G!"869F=q$-$N$?$a$K(B Red Hat Linux 7.2 $B%(%i!<%?(B $B$H$+FI$s$G$$$?$j$7$?$N$@$,!"$"$^$j$K$"$^$j$J!VF|K\8l!W$,B?$9$.$d$7$J$$$+(B?
$BJF9qL1!"%F%mBP:vK!$X$N0U<1$KJQ2=!)(B (WIRED NEWS)$B!#(B [aml 29782] Re:$B%$%i%/967b$K$D$$$F(B [ $B%o%7%s%H%s!&%]%9%H$N$U$?$D$N5-;v(B]$B!#(B U.S. $B9qFb$G$b%P%1$NHi$,$O$,$l$D$D$"$k!"$N$+$J$"!#(B $B;R%V%C%7%e$OK\Ev$K@oAh$,Bg9%$-$_$?$$$@$1$I!D!D!#(B
NASDA$B$KIT@5%"%/%;%9$7$?85El
$B6%:n1G2h!V%;%W%F%s%P!<(B11$B!W!!%K%U%F%#$J$I$G(BBB$B8x3+(B
($BKhF|(B)$B!#(B
$B$=$&$$$($P!"(B
$B%A%g%`%9%-!<(B 9.11
$B$N(B
$B40@.HdO*>e1G!u%H!<%/%i%$%V(B
$B$O$I$s$JMM;R$@$C$?$s$@$m$&!#(B
[aml 29780] $B$*$9$9$a!*%4%k%4#1#3(B $B%"%H%_%C%/%/%i%$%7%9(B$B!#(B
$BMQ7o$rJ9$3$&$+!D!D!#(B
$BK\$H8@$($P!"K?=j$G(B
$BIT3N
$B$,OCBj$K$J$C$F$$$?$j!#(B
$B5$$,$D$1$P!"(B
KUINS $B%;%-%e%j%F%#>pJs(B
$B$b(B
$BF|K\$N$/$i$C$/%5%$%H>pJs(B
$B$5$s$b%G!<%?%Y!<%92=$5$l$F$^$9$M!#(B
$B
$B$h$&$d$/(B PASV $B$,DL$k$h$&$K$J$C$?!#(B
$B8DJL(B port $B$N3+$1@_Dj$H(B PASV $B$,7v2^$7$F$$$?LOMM!#(B
$B0JA0MxMQ$7$F$$$?(B wall $B$G$O%9%F!<%H%U%k%$%s%9%Z%/%7%g%s$J$s$F$G$-$J$+$C$?$N$G!"(BPASV $B;~$KMxMQ$9$k(B port $B$r8DJL$K5v2D$7$F$$$?$N$@$,!"$3$N@_Dj$r(B FW-1 $B$X$b$=$N$^$^0\9T$5$;$F$7$^$C$F$$$?!#$3$N>l9g!"$=$N8DJL(B port $B$r(B ftp PASV $B$GMxMQ$9$k$3$H$O(B FW-1 $B$,5qH]$9$k!#$7$?$,$C$F(B PASV $B$G$-$J$$!"$H!#(B
$B9M$($F$_$l$PEvA3$JOC$G$O$"$k!#(B
$B8DJL(B port $B@_Dj$r:o=|$7$F2r7h!#:dK\$5$s$*
$B!D!D$7$+$7!"3:Ev%5!<%P$N8DJL(B port $B$G$J$/$F$b!"$I$3$+$N%5!<%P$N8DJL(B port $B@_Dj$HF1$8HV9f$N(B port $B$r(B PASV $B$,;H$*$&$H$9$k$@$1$G$&$^$/$$$+$J$$$i$7$$!#$&!<$`!#$=$l$O$J$s$@$+JQ$JF0:n$N$h$&$J5$$,$9$k$>!#(B
$B=;4p%M%C%H$H$N@\B3$r@ZCG!!El5~ETCfLn6h(B$B!"(B
$B!V%7%9%F%`$N0BA4@-$O3NG'$G$-$J$$!W!!CfLn6hD9$N2q8+MW;](B ($BKhF|(B)$B!#(B
$B2q8+MW;]$rFI$`$H!"AmL3>J$N8@$&!V==J,$J%;%-%e%j%F%#!
[SECURITY] [DSA 159-2] New Python packages fix problem introduced by security fix
[SECURITY] [DSA 160-1] New scrollkeeper packages fix insecure temporary file creation
[SECURITY] [DSA 161-1] New Mantis package fixes privilege escalation
[SECURITY] [DSA 162-1] New ethereal packages fix buffer overflow
[SECURITY] [DSA 163-1] New mhonarc packages fix cross site scripting problems
[SECURITY] [DS 164-1] New cacti package fixes arbitrary code execution
TRU64 formal disclosure from Snosoft. $B$J$s$F$N$b=P$F$^$9!#(B
$B!!(BQuickTime 5.0.2 for Windows $B$N(B ActiveX $B%3%s%]!<%M%s%H$K
$B!!(BQuickTime 6 for Windows $B$K$O$3$NLdBj$O$J$$$H$$$&!#(Bupgrade $B$7$^$7$g$&!#(B
$B!!(B[harden-mac:0083]
$B$G$N;XE&$K$"$o$;$F(B "for Windows" $B$rDI5-!#(B
$B!!(BApple $B%*%U%#%7%c%k(B: M-128: Apple QuickTime ActiveX Buffer Overrun [Apple Security Advisory APPLE-SA-2002-09-19]$B!#(B
$B$3$3$G$b!V(BQuickTime 6 for Windows $B$K(B upgrade$B!W$K$J$C$F$^$9!#(BQuickTime 5 for Windows $BMQ$N(B fix $B$O=P$J$$LOMM!#(B
2002.09.17 $BDI5-(B:
2002.09.30 $BDI5-(B:
$B!!(B2 $B$D$N(B CRLF Injection $BLdBj;XE&!#(B
$B%j%/%(%9%H$K(B %0D%0A $B$rA^F~$9$k$H%/%m%9%5%$%H%9%/%j%W%F%#%s%0@H
$B2sHrJ}K!$J$7!#F~NOCM8!::$r9T$&$3$H$G2sHr$5$l$?$$!#(B
php.ini $B$G(B allow_url_fopen
$B$r(B Off $B$K$9$l$P2sHr$G$-$k!#(B
$B!!(BPGP Corporate Desktop 7.1.[01] $B$K
$B!!4XO"JsF;(B: PGP$B0E9f%a!<%k$,!HEE;R$NCF4]!I$K$J$k!)(B (ZDNet)
$B!!(BMSIE $B$H(B KDE Konqueror $B$KBP$9$k;XE&!#(B
MSIEv6 % encoding causes a problem again
$B
MSIEv6 % encoding - Konqueror 3.0.3 also vulnerable
fix $B=P$^$7$?(B: KDE Security Advisory: Konqueror Cross Site Scripting Vulnerability
$B!!(BKDE $BJ}LL$G$O(B KDE Security Advisory: Secure Cookie Vulnerability $B$J$s$F$N$b=P$F$$$k$=$&$G!#(B
$B!!(BMicrosoft Java VM $B$K$O(B 10 $B$r1[$($kL$8x3+$N@H
$B!!4XO"JsF;(B: Internet Explorer$B$N(BJava$B4D6-$K%;%-%e%j%F%#!<%[!<%k(B (INTERNET Watch)$B!#;3Ln0f$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
$B!!F|K\8lHG$,?7$?$K(B 2 $B$D=P$F$^$7$?(B ($BC1$K5$$,$D$/$N$,CY$$(B > $B26(B)$B!#(B
$B!!5$J,$O(B$B%$%s%G%Z%s%G%s%9!&%G%$(B? $BG'>Z$b$J$K$b$+$+$C$F$J$$$h$&$JL5@~(B LAN $B$J$i!"IT@5%"%/%;%96X;_K!$K$b?($l$J$$$@$m$&$7!D!D!#(B
$B@$$NCf(B 9.11 $BDIEi$J$N$O$$$$$,!"(B $B$"$o$;$F!"%"%U%,%K%9%?%s$G(B U.S. $B$N!V8mGz!W$d!VITH/CF!W$K$h$jK4$/$J$i$l$??MC#$N$?$a$K$b5'$k$N$,6Z$C$F$b$N$@$H;W$&!#(B $B$D!<$+!"Jd=~$/$i$$$7$m(B > U.S.$B!#(B
$B:dK\$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#$D$C$D$$$F$_$^$9!#(B
$B!D!D$=$&$$$&9`L\$O
$B!!(B2002.08.21 $B$N(B web $B%V%i%&%64XO"(B $B$KDI5-$7$?!#(BMS02-050: $B>ZL@=q3NG'$NLdBj$K$h$j!"(BID $B$,56Au$5$l$k(B (Q328145) $B$,2~D{!#(B Windows 2000 $BMQ(B patch $B$,?7$?$KEP>l!#$^$@(B fix $B$,$J$$$N$O(B XP 64bit, Office 98/2001/v.X for Mac, IE/OutlookExpress for Mac$B!#(B
$B!!$^$?!"$3$N(B patch $B$rE,MQ$9$k$3$H$K$h$kI{:nMQ$,(B MS02-050 $B$N!V7Y9p!WMs$KDI5-$5$l$F$$$k!#(Bpatch $B$rE,MQ$9$k$H!"(B
Microsoft $B<+?H$,MxMQ$7$F$$$k!V$"$kFCDj$N!W%G%8%?%k>ZL@=q$^$G(B
reject $B$5$l$F$7$^$&$?$a!"
$BF)$1$k=;L1I<%3!<%IDLCN!"!V;d8"?/32!WB;GeDsAJ$X!!BgJ,(B ($BKhF|(B)$B!#(B $B@o$$$O$D$E$/!#(B
$B$*!"(BH2A 3 $B9f5!BG$A>e$2@.8y(B$B$7$?$N$G$9$M!#(B
$B$*$a$G$H$&$4$6$$$^$9!#(B
(link fixed: $B0l@P$5$s:4F#$5$sL@4V$5$s46
$B1?E>Dd;_2sHr$G$R$S1#$7$+(B$B!"(B
$B6[5^Nd5QAuCV$b%H%i%V%k1#$7(B
(NHK)$B!#(B
$B$b$&$a$A$c$/$A$c!#(B
$B$R$^$o$j#59f!"G3NA;D$j$o$:$+!!5$>]4QB,9KEO$jB3$/(B (asahi.com)$B!#(B
$B6/$^$k%G%8%?%k%3%s%F%s%D5,@)$KH?H/$9$k%*!<%W%s%=!<%9?X1D(B (WIRED NEWS)$B!#(B
$B$=$&$$$($P!"(B$Bu!!Bh(B2$B2s(B
$B@D;g?'%l!<%6!<$bLdBj$J$$!)!!@=IJ2=$K8~$1?J$`(BBlu-ray Disc
(ZDNet) $B$K$O!V(B
$B$$$^$@$K(B PASV $BDL$i$J$$$8$c$s!D!D!#(B
Blu-ray Disc$B$G$O!"Ev=i$+$i!"%a%G%#%"$@$1$G$J$/%I%i%$%V$K(B1$B$D(B1$B$D0[$J$k%f%K!<%/$J(BID$B$r:NMQ$7!"$3$l$rCx:n8"J]8n0J30$K$b@Q6KE*$KMxMQ$G$-$k$h$&$K$J$C$F$$$k(B
$B!W$J$s$F=q$$$F$"$k!#$$$D$>$d$N%$%s%F%k(B CPU $BOC$rA[5/$7$F$7$^$&$,!"$3$l$H$$$C$?@<$,J9$3$($F$3$J$$$N$O$J$<(B?
PHP4.2.3 $B%j%j!<%9(B (slashdot.jp)$B!#!V$I$/$$$j$-$1$s(B $B$?$Y$?$i$7$L$G!W$K$J$k>l9g$,$"$kLOMM!#(B
IPSJ$B!"(B
8/2 $B$H(B 9/2 $B$r4V0c$($F$k(B?
$B%&%#%k%9%a!<%kOC$O$I$&$J$C$?$s$@!D!D!#(B
(fixed: s/ISPJ/IPSJ/; $B$J$+$N$5$s46
$B$J$s$+!"$$$^$4$m$K$J$C$F$^$?(B Nimda $B$,$A$g$/$A$g$/N.$l$F$-$F$$$k$_$?$$$G$9$M$(!D!D!#(B
$BL@0E$rJ,$1$?(B2$B$D$N!X(BKlez$B!Y(B (CNET) $B$J$s$F5-;v$b=P$F$^$9$,!#(B
Windows 2000 $B%5!<%S%9%Q%C%/(B 3 $BF|K\8lHG$X$NBP1~$D$$$F(B ($B%H%l%s%I%^%$%/%m(B)$B!#(B
Q328691: MIRC Trojan-Related Attack Detection and Repair (Microsoft)$B!#(B
update $B$5$l$F$$$^$9!#(B
Backdoor.IRC.Flood $B$H$$$&%b%N$@$=$&$G!#(B
YEN $BE*1=OC(B$B!"(B9/22, 23 $B$H9-EgJ}LL$G%^%K%e%U%!%/%A%c%j%s%0!&%3%s%;%s%H$,>e1G$5$l$k$=$&$@!#(B
9/23 $B$OL5NA(B (!!)$B!#(B(info from $B0[J,;R(B($B2>(B) -dissident- $B%A%g%`%9%-!)
$B$H$j$"$($:(B web page $B$O8+$($k$h$&$K$J$C$?LOMM$G$9!#(B
ftp.st.ryukoku.ac.jp $B$O!"(BPORT $B$O$G$-$k$1$I!"(BPASV $B$9$k$H$&$^$/$$$+$J$$$_$?$$!#(B
$B$?$@$N(B FW-1 $B$J$N$K!"$J$<@_Dj$G$-$J$$(B > NEC$B!#(B
Antivirus software may indicate that it has
detected Trojans, such as Backdoor.IRC.Flood
and its variants
$B$H8@$o$l$F$b!"(B
Windows 2000 Server
$B$K(B Antivirus software $B$,$I$NDxEYF~$C$F$$$k$N$d$i!#(B
$B$=$&$$$&?M$O(B
$B%&%$%k%9%P%9%?!<%*%s%i%$%s%9%-%c%s(B
$B$7$F$_$k$H$+(B?
($B$d$C$?$3$H$J$$$1$I(B)
Mozilla Browser$B$N:F@_7WHG(B $B!V(BPhoenix$B!W(B
(slashdot.jp)$B!#MWCmL\$+(B?!
$B$H$j$"$($:(B proxy $BBP1~
MSDN Library: Security $B%Z!<%8$b%"%s%F%J$KF~$l$?J}$,$h$5$=$&$@$J$"!#$J$s$@$+$$$C$Q$$$"$k$>!D!D!#(B
$B4X@>%*!<%W%s%=!<%9(B+$B%U%j!<%&%'%"(B2002$B!"(B2002.12.06$B!A(B07$B!"Bg:e;:6HAOB$4[!#(B BOF $B$O(B?
[memo:4766] $B=;4p%M%C%HD4::0Q(B$B!#(B $B0KF#cU0l;a$N(B Japanese National ID $B$K4XO">pJs$,$"$k$=$&$G$9!#(B
$BEl5~EENO!'(B $BJ!EgBh#186H/#19f5!!!860x?<9o$J8D=j1#$Z$$(B ($BKhF|(B)$B!#(B $B
$B$3$l$,IT?3A%$@(B ($BKhF|(B)$B!#(B $B$U$D$&$N5yA%$b!V9):nA%!W$K8+$($k$h$&$K$7$F$_$k%F%9%H(B? $B!V9):nA%!W$NJ'$$2<$25yA%(B?
$B!!(B2002.08.22 $B$N(B White paper: Exploiting the Win32 API. $B$KDI5-$7$?!#(BInformation About Reported Architectural Flaw in Windows $B$NF|K\8lHG!"(B$BJs9p$5$l$?(B Windows $B$N9=B$>e$NLdBj$K4X$9$k>pJs(B$BEP>l!#(B $BK]Lu%9%T!<%I>e$,$C$F$k$J$"!#(B
$B!!%8%c%9%H%7%9%F%`$N(B Shuriken, Shuriken Pro, Shurken Pro2,
$B%+%i%a%k(B, $B%+%i%a%k%Q%U%'(B, $B%+%i%a%k(B2, e$B%?%$%`(B, e$B%?%$%`(B2 $B$K(B 2 $B$D$N
$B$N%3%^%s%I$r%^%$%3%s%T%e!<%?%>!<%s$GF0:n$5$;$k$3$H$,2DG=!#(B
2. $B$N
$BE:IU%U%!%$%k$N0l;~E83+@h$,4{CN$G$"$k(B ($B%i%s%@%`2=$5$l$F$$$J$$(B) $B$?$a$K!"(B
HTML $B%a!<%kFb$K!"0l;~E83+@h$KB8:_$9$kE:IU%U%!%$%k$X$ND>@\%j%s%/$r@_Dj$9$k$3$H$,2DG=!#(B
$B$3$N%j%s%/$r%/%j%C%/$5$;$k$3$H$K$h$j!"E:IU%U%!%$%k$K;E9~$^$l$?G$0U$N%3%^%s%I$r
$B!!BP1~$H$7$F$O!"$3$l$i$r(B fix $B$9$k(B patch $B$,=P$F$$$k$N$GE,MQ$9$l$P$h$$!#(B
$B%@%&%s%m!<%I@h$O(B [memo:4768] $B$r;2>H!#(B
$B!!$=$l$K$7$F$b!"(B[memo:4769] $B!V%;%-%e%j%F%#$r6/2=!WJ82=$NEA>5(B
$B$K$b$"$j$^$9$,!"$I$&$7$F!V=$@5!W$H8@$($J$$$s$G$7$g$&$+$M$(!#(B
$B!!(B2002.08.21 $B$N(B web $B%V%i%&%64XO"(B $B$KDI5-$7$?!#(BMS02-050: $B>ZL@=q3NG'$NLdBj$K$h$j!"(BID $B$,56Au$5$l$k(B (Q328145) $B$,2~D{!#(B Windows 98/98SE/Me $BMQ(B patch $B$,?7$?$KEP>l!#(B $B$^$@(B fix $B$,$J$$$N$O(B Windows 2000, XP 64bit, Office 98/2001/v.X for Mac, IE/OutlookExpress for Mac$B!#$i$`$8$#$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B
MS$B!"%3%s%T%e!<%?!<$+$i$NDy$a=P$7967b$K$D$$$F7Y9p(B (WIRED NEWS)$B!#(B
$B!!(B2002.08.21 $B$N(B web $B%V%i%&%64XO"(B $B$KDI5-$7$?!#(BMS02-050: $B>ZL@=q3NG'$NLdBj$K$h$j!"(BID $B$,56Au$5$l$k(B (Q328145) $BEP>l!#(BWindows NT 4.0 $B$H(B Windows XP $BMQ$N(B patch $B$,G[I[$5$l$F$$$k!#(B Windows 9x/Me, 2000 $BMQ$J$I$O$^$@!#(B
$B!!(B2002.08.22 $B$N(B White paper: Exploiting the Win32 API. $B$KDI5-$7$?!#(BInformation About Reported Architectural Flaw in Windows (Microsoft) $BEP>l!#(B Microsoft $B@=%W%m%0%i%`$N$$$/$D$+$K$b$3$NLdBj$,H/8+$5$l!"(Bpatch $B@=:nCf!"$NLOMM!#(B
Opinion$B!';\>{$5$l$?%^%$%/%m%=%U%H$N(BIIS 6.0 (ZDNet)$B!#(B Web Server Edition$B!"CMCJ$K$h$C$F$OBg$$$K%&%1$k$+$b$7$l$J$$!#(B $B$H$$$&$+4|BT$7$F$$$k$s$G$9$,!#(B
$B<+<#BN$N>rNc$K!V=;4p%M%C%H!W$N1F6A(B (ZDNet)$B!#(B $BH3B'$"$j$O(B 10% $B$KK~$?$:!"$G$9$+!#AmL3>J<+?H$,$"$N$F$$$?$i$/$G$9$7$M$(!#(B
$B=)ED2-$KIT?3A%!V7P:Q?e0h30$GH/8+!W(B ($BFIGd(B)$B!"(B $BG=EPH>Eg2-$KIT?3A%!!3$J]!"=d;kA%Dz#1#5@I$rGI8/$74F;k(B (asahi.com)$B!#(B $B:#2s$NBP1~>u67$OA02s$+$i$I$N$h$&$K2~A1$5$l$F$$$k$s$G$7$g$&$M!#(B
$B%7%^%s%F%C%/!"F|K\%F%l%3%`$H6(6H$7!V(BODN$B!W$N%a!<%k%&%$%k%9%A%'%C%/%5!<%S%9$NK\3JE*$JDs6!$r3+;O(B ($B%7%^%s%F%C%/(B)$B!#Aw?.%a!<%k$N%A%'%C%/$O$5$l$J$$LOMM!#$@$a$@$3$j$c!#(B
ICANN$B$,JF(BVeriSign$B$K(BWhois$B%G!<%?%Y!<%92~A1$rMW5a(B
$B!A:G0-%l%8%9%H%i!
$B=;4p%M%C%H$G!V<+<#BN$N@'@5A$B=;4p%M%C%H$O!"DL?.$r$9$Y$F0E9f2=$7$F$*$j!"5;=QE*$K$OK|A4$NA
XFree86 4.2.1 $BEP>l$7$F$$$^$9!#(B security fix $B$b4^$^$l$F$$$^$9!#(B "Update XDarwin support for the Jaguar release" $B$J$s$FJ8;zNs$b$"$j$^$9$M!#(B(info from [macosx-xwinsys-jp:00551])
$B!X(BPassport$B!Y$N%;%-%e%j%F%#!<$r6/2=(B (CNET) $B$@$=$&$G$9!#(B
$B!V$b$C$H<+<#BNCf?4$N1?1D$r!W!!=;4p%M%C%HD4::0Q$,H/B-(B$B!"(B $B=;4p%M%C%H$N%H%i%V%k!"2TF0(B1$B%v7n$G!V(B30$B7o$[$I!W!!AmL3>J(B ($BKhF|(B)$B!#(B $B$J$s$G$b1#$9$N$,!V%;%-%e%j%F%#!W$J$N$G$O$J$$$N$@$,!#(B
IT$B%;%-%e%j%F%#M=;;$K1F6A$rM?$($?$N$O!$(B9$B7n(B11$BF|$N%F%m967b$h$j(B9$B7n(B18$BF|$N!V(BNimda$B!W(B ($BF|7P(B IT Pro)$B!#(B9.11 $B5i$@$H!V9-0h:R32!W$K6a$$$7!#(B 9.11 $B$G4m5!4IM}BN@)A4HL$r8+D>$7$?!"$H$$$&$N$O$"$k$@$m$&$1$I!"(BIT $B%;%-%e%j%F%#$KFC2=$7$F8+D>$7$?!"$H$$$&%7%J%j%*$O9M$($K$/$$!#(BIT $B%;%-%e%j%F%#$H$$$&4QE@$G$O(B CodeRed / Nimda $B$N1F6A$NJ}$,$O$k$+$KBg$-$$!"$H$$$&$N$O$4$/$"$?$j$^$($N7kO@$@$m$&!#(B
$B4Z9q$N%&%$%k%9BP:v%=%U%H:GBg
$B%3%s%T%e!<%?!<%&%$%k%9=8$a#D#B2=!!AmL3>J!"BP:v8&5f(B (asahi.com)$B!#(B
$B!V(B$B!VL16H05Gw!W$HHcH=$r>7$+$J$$$h$&!"8&5f$N$?$a$N>pJs$NC_@Q$dDs6!$K$H$I$a$k$H$$$&(B
$B!W!#L16H!"L16H!#(B
$B%=%K! ($BKhF|(B)$B!#(B $B%F%l%S$N%=!<%9%3!<%I$,F@$i$l$k;~Be$K$J$kLOMM!#(B
$B!!86H/?d?JGI$C$F!"%9%j!<%^%$%kEg(B (TMI) $B;v8N$N$3$m(B ($B8E$/$F$9$^$s(B) $B!VF|K\$N86H/$O(B U.S. $B$h$j$O$k$+$K87$7$/8!::$7$F$^$9$+$i(B ok ok$B!W$J!<$s$F8@$C$F$$$?$h$&$J5-21$,$"$k$s$G$9$,!"
$B!!(B$B!V2r8[!W$5$l$F$$$?ElEE86H/%H%i%V%k1#$7$N>pJsDs6!
$B!!;XE&J8=q(B: SecuRemote usernames can be guessed or sniffed using IKE exchange$B!#(B Check Point $B$5$s$,$*$C$7$c$k$K$O!"(B
Check Point does not recommend the use of IKE Aggressive Mode, because of many well-known limitations in the protocol, and the Check Point products offer much more secure alternatives.
$B!D!DCfN,!D!D(B
By default, Aggressive Mode is not enabled in NG. In 4.1, the recommended configuration is to disable Aggressive Mode and use Hybrid Mode instead (which involves no change to the user experience).
$B$J$s$@$=$&$G!#(B
$B!!(BCisco VPN 3000 $B%7%j!<%:$K$5$^$6$^$J
$B!!BP93%=%U%H$b>R2p$5$l$F$^$9!#(B
$B!!J#?t$N%a!<%k%=%U%H$rJ;MQ$9$k$N$O$1$C$3$&$`$D$+$7$$$b$N$,$"$k$1$I!"J#?t$N(B web $B%V%i%&%6$rJ;MQ$9$k$N$O$=$l$[$I$`$D$+$7$/$J$$!#(BNetscape 6 $B0J9_$O!V(BIE $B$8$c$J$$$HFI$a$J$$$s$@$h$M!W$H$$$&$3$H$b>/$J$/$J$C$?$7!#(BNetscape/Mozilla/Opera $B$J$i(B MIME content-type $B$b$A$c$s$H2r
$B!!$H$j$"$($:!"(BMIME content-type $BLdBj$@$1$O$J$s$H$+$7$F$[$7$$(B > IE$B!#(B
$B%7%c%l$K$J$i$s!#(B
$B%=%U%H$NIT@5%3%T!<$r$7$F$$$?@lLg3X9;$rDsAJ!"(BMS$B$d%8%c%9%H(B ($BKhF|(B)$B!#(B $B!VB;32Ge=~$N3[$J$I$G@^$j9g$o$J$+$C$?$?$aDsAJ$KF'$_@Z$C$?!W!#(B $B$7$+$7!"$$$^$@$K(B Apache/1.2.6 $B$J$s$G$9$M(B > www.accsjp.or.jp$B!#(B
$BHo:RCO$KL5@~(BLAN$B$r!!!AN}GO6h$HET!"9gF171N}(B (ZDNet)$B!#L14V4k6H$J$s$G$9$M!#(B
$BG-5T;&$N%M%C%H7G:\;v7o!!!V87H3C24j!W$O6&46$rF@$i$l$J$$(B ($BKhF|(B)$B!#(B
$B5TBTJ}LL$O9%$-7y$$$H$O$A$g$C$H0c$&$H;W$&$N$@$,!#(B
$B7y1l8"!"$H$$$&$N$O:G6a$h$/J9$/$,!"7yF0J*8"!"$H$$$&$N$O$J$+$J$+J9$+$J$$!"$N$b3N$+$@$,!#;d$OF0J*7y$$$8$c$J$$$1$I!"8$%&%s%3$O2s<}$7$F$/$l(B > $B8$;6JbF1H<
9$B7nKv$^$G$K=;L1I<%3!<%I$r:FG[C#!!L>8E20;T(B ($BKhF|(B)$B!#(B
$B$^$@$^$@LBAvCf$C$F$+$s$8(B?
$B!V=;4p%M%C%H(BNO$B!*!W=iF|$O(B1202$B?M!!2#IM;T$G;TL1A*Br;O$^$k(B ($BKhF|(B)$B!#(B
$B2#IM;TL1$O$d$j$d$9$/$F$$$$$J$"!#(B
IIJ$B!"Cf7x4k6H8~$1$N>pJsO31LBP:v%5!<%S%9!V(BIIJ Mail$B%2!<%H%&%'%$%5!<%S%9!W$r3+;O(B (IIJ)$B!#(B
2002.09.12 $B$N(B
IIJ$B%;%-%e%j%F%#%=%j%e!<%7%g%s!&%;%_%J!<(B
$B$,Cf?H$N@bL@$J$N$+$J!#(B
$B!!F1$8(B machine $B$C$]$$(B address $B$+$i(B Klez $B$,Dj4|E*$K$d$C$F$-$?$j$7$F!"$$$$$+$2$s%&%6$$$H;W$C$F$$$k?M$O!"(BISP $B$KO"Mm$7$FBP1~$rB%$7$F$_$F$b$h$$$+$b$7$l$^$;$s!#I,$:BP1~$5$l$k!"$H$$$&$o$1$G$O$"$j$^$;$s$,!#(B
$B!!(BNamazu $B:G?7HG(B
2.0.12 $B$,EP>l$7$F$$$^$9!#(B
$BI8=`%(%i!<=PNO$K$h$kLdBj(B ($B%/%m%9%5%$%H%9%/%j%W%F%#%s%0LdBj$K$D$J$,$C$F$7$^$&(B) $B$J$I$,GS=|$5$l$F$$$^$9!#(BNamazu $BMxMQ
$B!!;2>H(B: $B%/%m%9%5%$%H%9%/%j%W%F%#%s%0@H
$B!!$&!<$s!"(B
$B%&%#%k%9Ho32$O!"%`%@$K$?$l$J$,$5$l$F$$$k(BIT$BM=;;$N0lIt$r$^$o$;$P!"4JC1$KKI$0$3$H$,$G$-$k$O$:$J$N$K!"$"$($F9T$J$C$F$$$J$$$N$G$"$k!#(B
$B!!%`%@%`%@$J!V(BIT $BM=;;!W;Y=P$,B8:_$9$k$3$H$K$OF10U$9$k$1$l$I!"$=$b$=$b%&%#%k%9BP:v$r@/I\M=;;$G$d$k$Y$-$J$s$@$m$&$+!D!D!#(B
$B%&%#%k%9$K46@w$7$J$$$b$C$H$b8z2LE*$JJ}K!$O!"!V%"%&%H%k%C%/%(%/%9%W%l%9!J(BOE$B!K$H%$%s%?!<%M%C%H%(%/%9%W%m!<%i!J(BIE$B!K$r;H$o$J$$$3$H!W$K$D$-$k!#(B
$B!!(BIE/OE $B$,:$$C$?$A$c$s$J$3$H$K$OF10U$9$k$1$I!"B>$N%a!<%i$G$b!"E:IU%U%!%$%k$r%@%V%k%/%j%C%/$5$l$?$i%*%o%j$J$o$1$G!D!D!#$=$&$$$&ItJ,$G$N!V4pAC650i!W$O$$$:$l$K$7$mI,MW$+$H!#(B
$B!!(BMac OS 9.2.2 $B0JA0MQ!#(BMac OS X $BMQ$O!D!D(B inetd $B$G(B /bin/sh $B$G$bF0$+$7$H$1$P(B ok ok $B$J$N$G$7$g$&!#(B
$B!!:#$N$H$3$m$OJ*M}967b$NJ}$,4JC1$+$DM-8z$JLOMM!#I`$,0lK\$"$l$PEE@~@Z$l$k$7$J$"!#(B
$B!!(B2002.09.02 $B$N(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs%;%s%?!<$NEEOCAk8}$K$D$$$F(B $B$KDI5-$7$?!#$=$l$i$7$$5-=R$,DI2C$5$l$^$7$?!#EvLL$O1Q8l$G$,$s$P$k$7$+$J$$$h$&$G$9!#(B(T_T)
$B!!(B2002.09.02 $B$N(B solution 4576 - InterScan VirusWall UNIX - CVP$B!'(BSecurity Patch$B$rE,MQ8e(BCVP$B%5!<%S%9$,Dd;_$9$k(B $B$KDI5-$7$?!#!V(BHTTP$B$N(BTrickle$B5!G=!W$N2r@b$rDI5-!#(B
$B650i5!4XBP>](B
McAfee.com$B%;%-%e%j%F%#BP:v%=%U%H$NL5=~G[I[$N$40FFb(B ($B%=!<%9%M%/%9%H(B)$B!#(B
$B%?%@$J$N$O(B 1 $BG/$@$1!"$7$+$bEl5~(B23$B6hFb$@$1!#(B
$B1&$`$11&ETCN;v$KU;$S$k%F%9%H$J$N$+(B? ($B
Updated for FreeBSD 4.6.2 Anti Trojan kernel option patches
$B=P$?$=$&$G$9!#(B
CERT Summary CS-2002-03
$B=P$F$^$9!#(B
$B?7L>>N$,<(:6$9$k(BWindows .NET Server$B$NCY$l(B (ZDNet)$B!"$H$$$&$+$=$l$O$b$&4{DjO)@~$G$7$g!#(B
$B$=$NJ,$7$C$+$j0BA4!&0B?4$J%b%N$K$J$C$F$/$l$l$P$=$l$G$$$$$o$1$G!#(B
Music Share-In Festival 2002 (EFF) $B$H$$$&$N$,$"$k$=$&$G!#(B
OpenAudioLicense $B$K6=L#$N$"$kJ}$O!">.@>$5$s$N(B
Music Wants to be Free
$B%Z!<%8$b;2>H$5$l$k$H$h$$$+$b(B ($B>.@>$5$s!">pJs$I$&$b$G$9(B)$B!#(B
$BF|K\$N$/$i$C$/%5%$%H>pJs(B$B!"!V%"%k%F%_%9%$%s%?!<%J%7%g%J%k3t<02q
$B$"$i!"(B2002/08/16 $B$K3t<02q
$B!!(Blinuxconf $B$,D9Bg$J(B LINUXCONF_LANG $B@_Dj$G(B buffer overflow $B$9$k!"$H$$$&;XE&!#(B $BFC$K!"(Blinuxconf $B$,(B setuid $B$5$l$F%$%s%9%H!<%k$5$l$F$$$k>l9g(B ($B$?$H$($P(B Mandrake $B$,3:Ev$9$k$=$&$@(B) $B$OCm0U$,I,MW$@!#(B
$B!!(Blinuxconf 1.28r4 $B$G=$@5$5$l$F$$$k$N$GF~$l$+$($k!#$"$k$$$O3F%G%#%9%H%j%S%e!<%?$N(B fix package $B$r%$%s%9%H!<%k$9$k!#(B
$B!!(B--max_rtt_timeout 50 --max-parallelism 100 $B$r;n$7$F$_$h$&!"$H$$$&5-;v!#(B
FreeBSD-SN-02:05 security issues in ports
$BBP>](B: acroread5, aide, apache+mod_ssl, bugzilla, Canna, ethereal, fam, isakmpd, irssi, kdelibs[23], krb5, linux-netscape6, netscape7, linux-mozilla, mozilla, mm, mpack, newsx, openssh, openssh-portable, php, linux-png, png, postgresql7, samba, squid24, super, webmin, zmailer$B!#(B
$B!!!V(BHTTP$B$N(BTrickle$B5!G=!W$rDd;_$9$l$P2sHr$G$-$k$h$&$@$,!"!V(BHTTP$B$N(BTrickle$B5!G=!W$C$F2?$@$m$&!#(B
$B!!%$%7%2$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):
InterScanVirusWall$B!J(BSolaris$BHG!K$N(Bhttp$B%9%-%c%s@_Dj2hLL$K$O!"0J2<$N$h$&$J%a%K%e!<$,$"$j$^$9!#(B
---------
$B""(B Use Trickle:
Send [ ] bytes of data to client for every [ ] kilobytes received.
(prevents browsers timeouts and provides progress)
---------
$B%G%U%)%k%H$G$O$3$N%A%'%C%/$O%*%U$G!"(B2048kb$B$4$H$K(B5byte$B$:$D%G!<%?$rAw$k?tCM$,F~$C$F$$$^$9!#(B
http$B$d(Bftp$B$r(BInterScan$B$G%A%'%C%/$5$;$k$H!"%U%!%$%k0l$D$r%@%&%s%m!<%I$7=*$($F%&%#%k%9%A%'%C%/$9$k$^$G%/%i%$%"%s%H$KEO$5$J$$$N$G!"2s@~$,:.$s$G$$$?$j!"$H$F$bBg$-$J%U%!%$%k$@$H!"%/%i%$%"%s%H!J%V%i%&%6!K$,%?%$%`%"%&%H$7$F$7$^$$$^$9!#$3$l$rKI;_$9$k$?$a$K!";~!9%/%i%$%"%s%H$r$D$D$$$F!"%;%C%7%g%s$rJ];}$9$k$=$&$G$9!#(B
$B$b$C$H$b%&%A$N2q(^_^;
$B!!$i$`$8$#$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):
(Check box) Use Trickle:
Send XXX bytes of data to client for every YYYY kilobytes received.
(prevents browsers timeouts and provides progress)
$B$H$$$&@_Dj9`L\$K$J$j$^$9!#(B
$BMW$O(B YYYY $B%-%m%P%$%H$r
$BL5DL?.;~4V$,D9$$$HAa!9$K$"$-$i$a$k%/%i%$%"%s%H$NBP:v$G$9!#(B
$B0JA0$O%@%_!<%X%C%@$rAw$jJV$9$3$H$GBP1~$7$F$$$^$7$?$,!"(B
Outside <=> Proxy2 <=> ISVW <=> Proxy1 <=> Clients
$B$H$$$&9=@.$N>l9g!"(BProxy1$B$H$NAj@-$K$h$j$*$+$7$/$J$k>l9g$,$"$C$?$?$a$K(BTricle$B$,
$B!!(BOracle9i Application Server 9.0.2 $B$N(B Web Cache $B5!G=$K
$B!!2sHrJ}K!$,5-:\$5$l$F$$$k$N$GE,MQ$9$l$P$h$$!#(B
$B!!(B0-day $B$G$"$k$+H]$+$rLd$o$:!"?/F~$5$l$?>l9g$K!"!V?/F~$5$l$?!W$3$H<+BN$rH/8+$G$-$k$+H]$+!"$,LdBj$K$J$k$s$@$m$&$J$"!#$=$N>e$G!"$"$i$+$8$aBP:v
$B!!(BPTRS $B$N5HED$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):
$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs%;%s%?!<$NEEOCAk8}$K$D$$$F$G$9$,!";d$NJ}$G(BMSKK$B$NJ}$K3NG'$7$?$H$3$m!VEEOC$G$N@H
$B$h$C$F8=>u$G$O@H
$B$I$&$d$i(BMS$BFbIt$G$bEEOCAk8}$N%5%]!<%HHO0O$K$D$$$F:.Mp$7$F$$$k$h$&$G$9$M!#(B
$B!!$3$N7o!":4L>LZ$5$s$b(B Sat, 10 Aug 2002 11:04:19 +0900 $BIU$N(B bugtraq-jp $B$X$N%]%9%H(B (archive $B$O2=$1$F$^$9(B) $B$G!"$d$O$j!VJF9q$XO"Mm$7$FM_$7$$$H8@$o$l$^$7$?!W$HJs9p$J$5$C$F$^$9!#(B
$B!!$H$$$&$o$1$G!"$3$l$iBP1~$,0U?^$5$l$?>uBV$G$"$k$N$J$i!"(B
TechNet $B%;%-%e%j%F%#(B $B%;%s%?!<(B
$B$NEEOCHV9f$N$H$3$m$K!V@H
$B!!",$N$h$&$J5-=R$,(BTechNet $B%;%-%e%j%F%#(B $B%;%s%?!<(B$B$KDI2C$5$l$^$7$?!#EvLL$O1Q8l$G$,$s$P$k$7$+$J$$$h$&$G$9!#(B(T_T)
2002.09.03 $BDI5-(B:
$B!!(B2002.08.29
$B$N(B
$B%M%C%H%o!<%/6&M-%W%m%P%$%@$NL$%A%'%C%/$N%P%C%U%!$K$h$j!"%5!<%S%95qH]$,5/$3$k(B
(Q326830) (MS02-045)
$B$KDI5-$7$?!#(BISS $B%;%-%e%j%F%#(B $B%"%i!<%H(B: Microsoft Windows SMB $B$K$*$1$k%5!<%S%9ITG=967b$N@H