$B%;%-%e%j%F%#%[!<%k(B memo - 2004.06

Last modified: Fri Sep 10 12:12:35 2004 +0900 (JST)


$B"#(B 2004.06.30

$B"#(B Apache 2.0.46$B!A(B2.0.49 Input Header Folding Denial of Service Vulnerability
(secunia, Tue, 29 Jun 2004 03:01:09 +0900)

$B!!(Bapache 2.0.46$B!A(B2.0.49 $B$K7g4Y!#(Bap_get_mime_headers_core() $B4X?t$K7g4Y$,$"$j!"6uGr$^$?$O(B TAB $B$G$O$8$^$kD9Bg$J%X%C%@$K$h$C$F(B DoS $B967b$,2DG=$JB>!"(B4GB $B0J>e$N2>A[5-21$r;}$D(B 64bit $B4D6-$K$*$$$F$O(B heap overflow $B$,H/@8$9$k!#(B

$B!!(Bapache 2.0.50 $B$G=$@5$5$l$F$$$k!#$^$?(B apache 2.0.47$B!A(B2.0.49 $BMQ$N(B patch $B$,MQ0U$5$l$F$$$k!#(B

2004.07.15 $BDI5-(B:

$B!!$3$N7g4Y$@$,!"(B32bit $B4D6-$K$*$$$F$b!"(BPHP $B$J$I$N(B 3rd party $B%b%8%e!<%k$K$*$$$F82Cx$J1F6A$,H/@8$9$k!"$H$N;XE&$,EP>l$7$F$$$k!#(B PHP 4.3.7 / 5.0.0RC3 $B$K(B 2 $B$D$N7g4Y(B $B$r;2>H!#(B

2004.07.30 $BDI5-(B:

fix / patch:

$B"#(B SA11966: Internet Explorer Frame Injection Vulnerability
(secunia, 2004.06.30)

$B!!(B[Full-Disclosure] SUPER SPOOF DELUXE : Take Two $B$N7o$N$h$&$J$N$@$1$I!"

2004.07.01 $BDI5-(B:

$B!!4XO"(B:

2004.07.12 $BDI5-(B:

$B!!(BIE $B$N>l9g$O!"%$%s%?!<%M%C%H%*%W%7%g%s$N(B [$B%;%-%e%j%F%#(B] $B$G!"3F%>!<%s$K$*$1$k!V0[$J$k%I%a%$%s4V$N%5%V%U%l!<%`$N0\F0!W$rL58z$K$9$k$3$H$G2sHr$G$-$k$=$&$@!#(B $B2hA|(B$B!#(B

$B!!$J$*!"!V0[$J$k%I%a%$%s4V$N%5%V%U%l!<%`$N0\F0!W$rL58z$K@_Dj$9$k$H!"$?$H$($P(B 2 $B$A$c$s$M$k7G<(HD(B$B$N1\Mw$K;Y>c$,=P$^$9!#@lMQ%V%i%&%6$r;H$($P$h$$$N$G$7$g$&$,!D!D!#(B

$B!!(B[memo:7646]$B!#$9$$$^$;$s!#(B_o_

2004.09.09 $BDI5-(B:

$B!!(BSA11978: Multiple Browsers Frame Injection Vulnerability (secunia)$B!#(B Safari: CAN-2004-0720$B!#(B

$B"#(B $B!V%*%s%i%$%s$9$j!W$K$4MQ?4!=!=?7$?$J%H%m%$$NLZGO%W%m%0%i%`8+$D$+$k(B
(ITmedia, 2004.06.30)

$B!!(BDownload.Ject $B$,OCBj$K$J$C$?$H$-$K!V56Au2hA|%U%!%$%k$G(B?$B!W$H$$$&OC$,=P$F$$$?$h$&$K5-21$7$F$$$k$,!"$3$l$N$3$H$+!#(B Windows XP SP2 $B$K$O$3$&$$$&$b$N$X$NBP:v$b4^$^$l$F$$$^$9$M!#(B

2004.07.01 $BDI5-(B:

$B!!4XO"(B:

$B"#(B $BDI5-(B

[Full-Disclosure] Buffer overflow in apache mod_proxy, yet still apache much better than windows
Download.Ject $B$K4X$9$k>pJs(B

$B!!4XO">pJs(B:

$B!!4XO"JsF;(B:

$B"#(B Juniper JUNOS PFE $B$N(B IPv6 $B=hM}$K%a%b%j%j!<%/$N@H
(JPCERT/CC, 2004.06.30)

$B!!(B2004.02.24 $B0J9_$N(B Juniper JUNOS Packet Forwarding Engine (PFE) $B$K7g4Y!#(B JUNOS $B$G(B IPv6 $B$rM-8z$K$7$F$$$k>l9g$K!"FCDj$N(B IPv6 $B%Q%1%C%H$K$h$C$F%a%b%j%j!<%/$,H/@8$9$k!#$3$l$rMxMQ$9$k$H!"30It$+$i(B DoS $B967b$,2DG=$H$J$k!#(B

$B!!(B2004.06.21 $B0J9_$N(B JUNOS $B$G=$@5$5$l$F$$$k!#$^$?!"(BIPv6 $B$rL58z$H$9$k$3$H$G2sHr$G$-$k!#(B

$B!!4XO"(B:


$B"#(B 2004.06.29


$B"#(B 2004.06.28

$B"#(B $BDI5-(B

Hiki $B$N@H

$B!!(B0.64 $B$K$b7g4Y$,H/8+$5$l$^$7$?(B: Hiki $B$N@H$B!#(B0.65 $B$G=$@5$5$l$F$$$^$9!#(B $B$^$?!">\:Y>pJs$,(B 7/12 $B$K8x3+$5$l$k$=$&$G$9!#(B $B$+$:$R$3$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

Download.Ject $B$K4X$9$k>pJs(B

$B!!4XO">pJs(B:

$B!!4XO"JsF;(B:

$B"#(B $B!V(BWinny$B;v7o$r7@5!$K>pJs=hM}5;=Q$NH/E8$H
(various)

$B!!(BInternet Watch:

$B!!(BITmedia:

$B!!(BCNET:

$B!!8D?M(B web $B%Z!<%8(B:


$B"#(B 2004.06.25

$B"#(B $B$5$^$6$^$J%"%W%j%1!<%7%g%s$r0[>o=*N;$5$;$k(BGIF$B2hA|$,%M%C%H>e$KN.=P(B
($BAk$NEN(B, 2004.06.24)

$B!!0[>o$J(B GIF $B%U%!%$%k$r1\Mw$7$h$&$H$9$k$H0[>o=*N;$7$F$7$^$&%"%W%j$,$"$k!"$H$$$&OC!#Ak$NEN5-;v$K$O(B 2 $B$D$N%5%s%W%k2hA|$G$N%F%9%H7k2L$,7G:\$5$l$F$$$k!#(B $B$^$?!"(Bhttp://tts.s53.xrea.com/temporary/gif.htm $B$K!"2FZ7k2L$,8x3+$5$l$F$$$k!#(B IE $B$,$@$a$@$a$J$N$@$,!"(B Microsoft $BE*$K$O!V$=$l$O%;%-%e%j%F%#LdBj$G$O$J$$!W$H8@$o$l$F$7$^$&$N$@$m$&$J$"!#(BWindows XP SP2 $B$G$O=$@5$5$l$F$$$k$C$]$$$7!#(B

$B!!4XO"(B: [memo:7611] GIF$B2hA|$K$h$k0[>o=*N;(B

$B!!2FpJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B Download.Ject $B$K4X$9$k>pJs(B
(Microsoft, 2004.06.25)

$B!!(BIIS $B$,$$$C$Q$$%d%i%l$?$N$GD4$Y$F$_$k$H!"(B

  1. $B=$@5%W%m%0%i%`L$8x3+$N(B IE $B$N7g4Y$rFM$/(B JavaScript $B$r;E3]$1$?(B web $B%5%$%H$,MQ0U$5$l$F$*$j!"(B
  2. $B$=$N(B JavaScript $B$r(B IE $B$G%"%/%;%9$9$k$H<+F0E*$K%P%C%/%I%"$r;E3]$1$i$l!"(B
  3. $B$=$N%P%C%/%I%"$+$i(B MS04-011 patch $B$,E,MQ$5$l$F$$$J$$(B IIS $B$,%d%i%l!"(B
  4. $B%d%i%l$?(B IIS $B$K$b=$@5%W%m%0%i%`L$8x3+$N(B IE $B$N7g4Y$rFM$/(B JavaScript $B$r;E3]$1$?(B web $B%Z!<%8$,MQ0U$5$l!"(B($B0J2<$/$j$+$($7(B)

$B!D!D$H$$$&%9%H!<%j!<$J$N$+$J$"!#(BIIS attack $B$K$D$$$F$O!"(BMS04-011 patch $B$rE,MQ$7$F$"$l$PKI$2$k$H(B Microsoft $B$O

$B$H$$$&$o$1$G!"!V%^%$%3%s%T%e!<%?%>!<%s$N%m%C%/%@%&%s$OI,?\!W$HG'<1$9$Y$-$J$N$G$7$g$&!#(B

$B!!4XO"(B:

2004.06.26 $BDI5-(B:

$B!!(B$B:G?7%Q%C%A$NE,MQ$H(BJavaScript$B$NL58z2=$r!=!=%H%m%$$NLZGOBP:v(B (ITmedia, 6/25) $B$K$h$k$H!"$^$:(B IIS attack $B$,$"$j!"

$B!!(BIIS$B967b$NJ}K!$G$O0lCW!"$7$+$75,LO$G$O0[O@J.=P(B (ITmedia, 6/26)$B!#$^$@$h$/$o$+$C$F$$$J$$$h$&$@!#(B

2004.06.29 $BDI5-(B:

$B!!4XO">pJs(B:

$B!!4XO"JsF;(B:

2004.06.30 $BDI5-(B:

$B!!4XO">pJs(B:

$B!!4XO"JsF;(B:

2004.07.05 $BDI5-(B:

$B!!(BMicrosoft $B$+$i(B ADODB.Stream $B%*%V%8%'%/%H$rL58z$K$9$k%W%m%0%i%`$,EP>l$7!"(B Windows Update $B$d<+F099?7!"(BMicrosoft Software Update Services $B$GG[I[$5$l$F$$$^$9!#(BWindows 2000 / XP / Server 2003 $BMQ$G$9!#(B

$B!!$J$*!"(BWindows XP SP2 RC2 $B$G$O!"(BADODB.Stream $B%*%V%8%'%/%H$O$"$i$+$8$aL58z2=$5$l$F$$$^$9!#(B

2004.07.08 $BDI5-(B:

$B!!(BADODB.Stream $B%*%V%8%'%/%H$rL58z$K$7$F$b%$%1$F$7$^$&$H$$$&Js9p$,$"$k$h$&$G!#(B

$B!!(BJelmer Kuperus $B;a$N!D!D$H$$$&$N$O(B $B$3$l(B $B$G$9$+$M!#(B

2004.07.09 $BDI5-(B:

$B!!(BHandler's Diary July 8th 2004: Time to update Mozilla/Firefox/Thunderbird and Ethereal; also: sightings of infected IIS 6 servers. (SANS ISC)$B!#(BIIS 6 $B$,(B 100 $B%5%$%H!"$H$"$k$1$l$I!"$=$N(B 100 $B%5%$%H$,$"$kFCDj$N0lBf$N%[%9%H%^%7%s$K=8Cf$7$F$$$^$7$?!"$J$s$F%*%A$@$C$?$i%"%l$@$J$"!#(B


$B"#(B 2004.06.24

$B"#(B $B$$$m$$$m(B
(various)


$B"#(B 2004.06.23

$B"#(B SYM04-010: Symantec Gateway Security $B@=IJ$K(B DNS $B%-%c%C%7%e!&%]%$%>%K%s%0$N@H
(symantec, 2004.06.21)

$B"#(B US-CERT Technical Cyber Security Alert TA04-174A: Multiple Vulnerabilities in ISC DHCP 3
(US-CERT, 2004.06.23)

$B!!(BISC DHCP 3.0.1rc12 / 3.0.1rc13 $B$K(B 2 $B$D$N7g4Y!#(Bdhcpd $B$KBP$7!"(Bremote $B$+$i(B DoS $B967b$dG$0U$N%3!<%I$N

  • CAN-2004-0460$B!#(B $B%m%0$K4XO"$9$k(B buffer overflow $B$,H/@8$9$k$h$&$@!#(B
  • CAN-2004-0461$B!#(B vsnprintf() $B$r;}$?$J$$4D6-$G(B buffer overflow $B$,H/@8$9$k$h$&$@!#(B

$B!!(BISC DHCP 3.0.1rc14 $B$G=$@5$5$l$F$$$k$N$GF~$l$+$($l$P$h$$!#(B $B4XO"(B:

$B"#(B $B$^$?$b$d(BOpera$B$K%"%I%l%9!&%P!<$r56Au$5$l$k%;%-%e%j%F%#!&%[!<%k(B
($BF|7P(B IT Pro, 2004.06.22)

$B!!(BOpera 7.51 $B$K!"%"%I%l%9%P!<$r56Au$G$-$k7g4Y$,$"$k$H$$$&OC!#(B $B!V(B6$B7n(B18$BF|$4$m!$%;%-%e%j%F%#4XO"$N%a!<%j%s%0!&%j%9%H$J$I$KEj9F$5$l$?!W$H$$$&$N$O!"(B [Full-Disclosure] Opera Browser version 7.51 Address Bar Spoofing Vulnerability $B$+(B? $B$3$N%3!<%I$O(B Linux $B>e$N(B Opera 7.50 $B$G$OF0$+$J$$(B$B$H%U%)%m!<$5$l$F$$$k!#(B $BF|7P(B IT Pro $B5-;v$G$O!"(BJavaScript $B$rL58z$K$9$k$3$H$G2sHr$G$-$k$H$5$l$F$$$k!#(B

$B!!$&!<$s!"(B[Full-Disclosure] Opera Browser version 7.51 Address Bar Spoofing Vulnerability $B$r!D!D!#(B

2004.06.24 $BDI5-(B:

$B!!(BWeb$B%V%i%&%6! ($BAk$NEN(B, 6/23)$B!#$J$<:F8=$G$-$J$$$s$@$m$&(B > $B26!#(B

2004.07.09 $BDI5-(B:

$B!!(BOpera 7.52 $B$G=$@5$5$l$?$h$&$G$9!#(B $B$H8@$C$F$$$k4V$K!"$^$?JL$N7g4Y$,H/8+$5$l$?$h$&$G(B: Opera$B$K$^$?$b$d(BURL$B$r:>>N$G$-$k@H$B!#(B

$B"#(B SNS Advisory No.76: Printing from Internet Explorer Lets Users to Cause DoS
(LAC SNS, 2004.06.23)

$B!!(BIE 6 SP1 $B$G!"FCDj$N(B web $B%Z!<%8$r0u:~$9$k$H(B CPU 100% $B$K$J$j!"BgNL$N0u:~J*$,@8@.$5$l$F$7$^$&$=$&$J!#(B


$B"#(B 2004.06.22

$B"#(B $B$$$m$$$m(B
(various)


$B"#(B 2004.06.21

$B"#(B $BDI5-(B

$B%&%$%k%9Dj5A%U%!%$%k(B(DAT4367)$B$NLdBj$K$D$$$F(B

$B!!(BDAT4367 $B$K4X$9$kLdBj(B (NAI) $B$,99?7$5$l$F$$$^$9!#$I$&$d$i!"IT6q9g$,H/@8$9$k$N$O!"!VK\Mh%"%C%W%0%l!<%I$5$l$F$$$k$O$:$N$b$N$,%"%C%W%0%l!<%I$5$l$F$$$J$$!W>l9g$K8B$i$l$k$h$&$G$9!#$=$N$?$a!"$3$N8=>]$,H/@8$7$?>l9g$O!V(BSDAT4367 $B$r6/@)E,MQ$9$k!W$3$H$G2r7h$G$-$k$h$&$G$9!#6/@)E,MQ$9$k$?$a$NJ}K!$K$D$$$F$O!"(BDAT4367 $B$K4X$9$kLdBj(B (NAI) $B$r;2>H!#(B

New (Linux) Kernel Crash-Exploit discovered

$B!!(BVine Linux: [ 2004,06,19 ] kernel $B$K%;%-%e%j%F%#%[!<%k(B

$B"#(B Hiki $B$N@H
(Hiki Development Team, 2004.06.21)

$B!!(BHiki 0.63 $B0JA0$K(B

$B"#(B livedoor$B$N>pJs%;%-%e%j%F%#(B
($B:;Lm(B 16 $B:P$5$s(B, 2004.06.21)

$B!!(Blivedoor blog $B$rB`2q$9$k$K$O!"%0%0$i$J$$$HC5$;$J$$(B$BB`2q?=@A%U%)!<%`(B$B$+$i!"F~2q;~$K$OF~NO$7$F$$$J$$8D?M>pJs$rF~NO$5$;$i$l$?5s6g!"(BSSL $B2=$5$l$F$$$J$$DL?.O)(B (livedoor $B%W%i%$%P%7!<%]%j%7!<(B$B0cH?(B) $B$r;H$o$5$l$kLOMM!#AGE($G$9$M!#(B


$B"#(B 2004.06.18

$B"#(B $BO":\!Z#I#TK[N.!!%Y%s%jZ!!!VB>?M$N%U%j!W4JC1(B
($BFIGd(B, 2004.06.17)

$B!!!V%0%_;X!W$N(B$B>>K\JY@h@8(B$B!"Fz:LG'>Z$b@V30@~pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B>>K\65Z$O!"<+M3$KJQ$($i$l$k%Q%9%o!<%I$J$I$H0[$J$j!"$J$j$9$^$5$l$F$bBeBXZ$N@:EY$r5R4QE*$K<($9I,MW@-$r>'$($F$$$k!#(B

$B!!$=$3$G$9$h$M$(!#$3$l$@$1!V8D?M>pJsO31H!W$,B3H/$9$k@$$NCf$G$9$7!#(B $B4XO"(B:

$B!!0B$$@=IJ$K$O0B$$M}M3$,$"$k!"$H$$$&$3$H$G$9$M!#9b2A$J@=IJ$O!V@8$-$F$$$k$+$I$&$+!W$rH=CG$7$F$$$k$O$:$G$9!#$b$C$H$b!"Bh;0Z$7$F$$$k$o$1$G$b$J$$$G$7$g$&$+$i!"$=$l$i$b==J,$J$N$+$I$&$+$O$h$/$o$+$i$J$$$H$$$&$N$,K\Ev$N$H$3$m$G$7$g$&$,!#(B

$B"#(B $BDI5-(B


$B"#(B 2004.06.17

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

$B"#(B $B%&%$%k%9Dj5A%U%!%$%k(B(DAT4367)$B$NLdBj$K$D$$$F(B
(McAfee Support Information, 2004/06/17)

$B!!%(%s%8%s(B 4.1.60 + DAT4367 $B$N>l9g$K!"(BVirusScan 4.5.1 SP1 $B$d(B NetShield 4.5 HFR for Windows $B$J$I$,5/F0$7$J$$>l9g$,$"$k$=$&$@!#(B $B2sHr$9$k$K$O%(%s%8%s$r(B 4.2.60 $B$d(B 4.3.20 $B$K%"%C%W%0%l!<%I$9$l$P$h$$$N$@$,!"(B $B$9$k$H:#EY$O!"(BWindows 9x/Me + VirusScan 4.5.1 SP1 $B$K$*$$$F!"(BPC $B$,5/F0$7$J$$(B (!!) $B>l9g$,$"$k$=$&$@!#$3$l$r2sHr$9$k$K$O!"(BDAT4366 $B0JA0$K%m!<%k%P%C%/$9$k$+!"(B autoexec.bat $B$K5-:\$5$l$F$$$k%^%9%?!<%V!<%H%l!<%I%9%-%c%sItJ,$r%3%a%s%H%"%&%H$9$l$P$h$$$=$&$@!#(B

$B!!$J$*!"

  • Windows 98
  • VirusScan 4.5.1 SP1
  • $B%(%s%8%s(B 4.3.20
  • DAT4367

$B$H$$$&4D6-$G$O!"B?>/;~4V$O$+$+$k$b$N$N5/F0$O$G$-$F$$$^$9!#(B

$B!!(B$B%5%]!<%H(B Q & A $B$K$b>pJs$r=q$$$F$[$7$$$J$"!D!D!#(B $B!D!D$"!"=P$?(B: DAT4367 $B$K4X$9$kLdBj(B (NAI)$B!#(B

2004.06.21 $BDI5-(B:

$B!!(BDAT4367 $B$K4X$9$kLdBj(B (NAI) $B$,99?7$5$l$F$$$^$9!#$I$&$d$i!"IT6q9g$,H/@8$9$k$N$O!"!VK\Mh%"%C%W%0%l!<%I$5$l$F$$$k$O$:$N$b$N$,%"%C%W%0%l!<%I$5$l$F$$$J$$!W>l9g$K8B$i$l$k$h$&$G$9!#$=$N$?$a!"$3$N8=>]$,H/@8$7$?>l9g$O!V(BSDAT4367 $B$r6/@)E,MQ$9$k!W$3$H$G2r7h$G$-$k$h$&$G$9!#6/@)E,MQ$9$k$?$a$NJ}K!$K$D$$$F$O!"(BDAT4367 $B$K4X$9$kLdBj(B (NAI) $B$r;2>H!#(B

$B"#(B $B%-!<%\!<%IF~NO$J$I$r5-O?$730It$KAw?.$9$k%W%m%0%i%`$K4X$9$kCm0U4-5/(B
(JPCERT/CC, 2004.06.17)

$B!!$?$H$($P(B [Full-Disclosure] spamming trojan? $B$G$O$8$^$k%9%l%C%I$+$i$?$I$l$k%5%$%H$K$"$k$b$N$b(B VBS/Psyme (NAI) $B$G$9(B ($B$H(B VirusScan Enterprise 7.1 $B$O8@$$$^$7$?(B)$B!#(B $B$3$N[Full-Disclosure] Internet explorer 6 execution of arbitrary code (An analysis of the 180 Solutions Trojan) $B$H$$$&OC$,$"$j$^$7$?$7!#8D?ME*$K$O!"8=>u$G$O(B IE $B$OA4$/$*$9$9$a$G$-$^$;$s!#(B $B$=$l$G$b(B IE $B$r;H$&>l9g$O!"(BQwik-Fix $B$/$i$$$OJ;MQ$7$?J}$,$$$$$H;W$$$^$9!#(B IE $B$H$$$&0UL#$G$O(B Windows XP SP2 $B$,$*$9$9$a$J$s$G$9$1$I$M!#(B

$B!!$3$NCm0U4-5/$NBP>]$O(B IE $B$@$1$G$O$J$$$h$&$G$9$,!D!D!#(B

2004.06.18 $BDI5-(B:

$B!!4XO"(B: $B8D?M>pJsN.=P$N?7 (NHK, 6/18)$B!#(B

$B%3%s%T%e!<%?!<$NIT@5%"%/%;%9$J$I$N>pJs$rDs6!$7$F$$$k!V#J#P#C#E#R#T%3!<%G%#%M!<%7%g%s%;%s%?!pJs$rN.$7B3$1$F$$$k%Q%=%3%s$,9qFb$G>/$J$/$H$b#1#5#0Bf$K$N$\$C$F$$$k$H$3$H$,$o$+$j$^$7$?!#(B

$B!!$=$&$@$C$?$s$G$9$+!D!D!#L@4V$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!$b$&$R$H$D4XO"(B: JPCERT/CC$B!"%-!<%m%,! (ITmedia, 6/17 21:39)$B!#(B

JPCERT/CC$B$K$h$k$H!"(BIP$B%"%I%l%9%Y!<%9$G$*$h$=(B100$B7o$NFO=P$,$"$C$?$H$$$&!#(B

$B!!$*$h$=(B 100 $B7o(B = 150 $BBf!"$J$N$+!"(BITmedia $B5-;v$N$"$H(B 50 $B7o$NJs9p$,$"$j!"(BNHK $B$,!V(B150 $B7o!W$r!V(B150 $BBf!W$H4V0c$($?$N$+!"$I$C$A$@$m$&!#(B


$B"#(B 2004.06.16

$B"#(B $BDI5-(B


$B"#(B 2004.06.15

$B"#(B $BDI5-(B

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B PHP 4.3.7 Release Announcement
(PHP.net, 2004.06.02)

$B!!(BWindows $BHG(B PHP 4 $B$N(B escapeshellcmd() $B$H(B escapeshellarg() $B$K7g4Y$,$"$C$?$=$&$G$9!#(B Windows $BHG(B PHP 4 $B$rMxMQ$7$F$$$k>l9g$O!"(B4.3.7 $B$X$N0\9T$,?d>)$5$l$F$$$^$9!#(B

This is a maintenance release that in addition to several non-critical bug fixes, addresses an input validation vulnerability in escapeshellcmd() and escapeshellarg() functions on the Windows platform. Users of PHP on Windows are encouraged to upgrade to this release as soon as possible.

$B!!4XO"(B:

$B"#(B [Full-Disclosure] Buffer overflow in apache mod_proxy, yet still apache much better than windows
(Full-Disclosure, Thu, 10 Jun 2004 23:38:26 +0900)

$B!!(Bapache 1.3.31 $B0JA0$KIUB0$N(B mod_proxy $B$K(B buffer overflow $B$9$k7g4Y$,$"$k$H$$$&;XE&!#(BCVE: CAN-2004-0492$B!#(B Apache httpd 1.3 vulnerabilities (Apache Week) $B$K$h$k$H!"$3$N7g4Y$O(B Apache 1.3.26$B!A(B1.3.31 $B$KB8:_$9$k$=$&$@!#(B

fix / patch:

$B"#(B New (Linux) Kernel Crash-Exploit discovered
(linuxreviews.org, 2004.06.11)

$B!!(Bx86 / x86_86 $B%"!<%-%F%/%A%c$G$N(B Linux 2.4.x / 2.6.x $B$K!"(Blocal user $B$+$i(B DoS $B967b$r

$B!!(BCVE: CAN-2004-0554$B!#(B US-CERT Vulnerability Note VU#973654$B!#(B

fix / patch:

$B"#(B $B$*OM$S$H:#8e$NJ}?K$K$D$$$F(B
(web-up.cside.biz)

$B!!(Bweb-up.cside.biz $B$GG[I[$5$l$F$$$?(B CGI $B%9%/%j%W%H$K$O!"(B

$B%9%/%j%W%H$NIT@5MxMQKI;_$rL\E*$H$7$F!"0J2<$N%1!<%9$K$*$$$F4IM}

$B$H$$$&!V%W%m%0%i%`E*A

1.$B%9%/%j%W%H$N=i2s@_CV;~(B
2.$BCx:n8"I=<(5Z$S%P!<%8%g%s>pJs$,2~JQ!&:o=|$5$l$?$H$-(B
3.$B%7%'%"%&%'%"EPO?(BID$B$,2~JQ!&:o=|$5$l$?$H$-!J@55,HG%9%/%j%W%H$N$_!K(B
4.$B%7%'%"%&%'%"%9%/%j%W%HEPO?$N$4?=@A;~@_CV(BURL
$B!!0J30$N(BWEB$B%9%Z!<%9$K$F@_CV$5$l$?$H$-!J@55,HG%9%/%j%W%H$N$_!K(B

$B"(;nMQHG$N$_!"(B1$B$K$*$$$FJ@$B!!(B $B2r@O(BCGI$B$K$F@_CV(BURL$B$r5-O?(B

$B!!(Bweb-up.cside.biz $BED5WJ];a$O!"LH@U;v9`$H$7$F(B

$BK\%9%/%j%W%H$NIT@5MxMQKI;_!&@_CV>u67GD0.$rL\E*$H$7$F!"K\%9%/%j%W%H$+$i@_CV@h%5!<%P!<$N>pJs$r<}=8$9$k$3$H$,$"$j$^$9$,!"MxMQ

$B$H=q$$$F$"$k!"$HO$r(B $B!V@_CV@h%5!<%P!<$N>pJs(B = CGI $BMxMQ

$B!!BP1~:v$@$,!"$3$N!V%W%m%0%i%`E*A

$B!!4XO"(B:

$B!!F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B Windows$BG'>Z$r?tIC$G2r@O(B $B@H
($BF|7P(B IT Pro, 2004.06.01)

$B!!(BNTLMv1 $B$O$b$&$@$a$@$a!"$H$$$&$3$H$G!#(B


$B"#(B 2004.06.14

$B"#(B $BDI5-(B

$B"#(B Mozilla Browser Address Bar Spoofing Weakness
(Secunia, Mon, 14 Jun 2004 21:04:41 +0900)

$B!!(BMozilla 1.0$B!A(B1.6, Firefox 0.x $B$K7g4Y!#(B Internet Explorer Security Zone Bypass and Address Bar Vulnerability $B$HF1MM$N>r7o!"$D$^$j(B http://[trusted_site]%2F%20%20%20.[malicious_site]/ $B7A<0$N(B URL $B$K$*$$$F!"(B

  1. malicious_site $B$N%I%a%$%s$K%o%$%k%I%+!<%I(B A $B%l%3!<%I$,EPO?$5$l$F$$$k(B
  2. malicious_site $B$,8m$C$?(B Host: $B%X%C%@$r

    $B>l9g$K!"%"%I%l%9%P!<$K$*$1$kI=<($r(B trusted_site $B$K56Au$9$k$3$H$,$G$-$F$7$^$&!#(B

$B"#(B Internet Explorer Security Zone Bypass and Address Bar Spoofing Vulnerability
(secunia, 2004.06.12)

$B!!(BIE 6 $B$K7g4Y!#(B http://[trusted_site]%2F%20%20%20.[malicious_site]/ $B7A<0$N(B URL $B$K$*$$$F!"(B

  1. malicious_site $B$N%I%a%$%s$K%o%$%k%I%+!<%I(B A $B%l%3!<%I$,EPO?$5$l$F$$$k(B
  2. malicious_site $B$,8m$C$?(B Host: $B%X%C%@$r

    $B>l9g$K!"(Bmalicious_site $B>e$N%3!<%I$,(B trusted_site $B$N8"8B$G

    $B!!2sHrJ}K!$H$7$F$O!VB>$N%V%i%&%6$r;H$&!W$,5s$2$i$l$F$$$k!#(B

$B"#(B Subversion <= 1.04 DoS / heap overflow
(subversion, 2004.06.10)

$B!!(BSubversion 1.04 $B0JA0$K7g4Y!#(Bsvn:// $B%W%m%H%3%k$d(B svn+ssh:// (ssh $B%H%s%M%kHG(B)$B!"(Bsvn+*:// ($BB>$N%W%m%H%3%k$K$h$k%H%s%M%kHG(B) $B$N=hM}$K$*$$$F(B heap overflow $B$,H/@8!"(Bremote $B$+$iG$0U$N%3!<%I$r

$B!!(BSubversion 1.05 $B$K$*$$$F=$@5$5$l$F$$$k$N$GF~$l$+$($l$P$h$$!#(B CVE: CAN-2004-0413

fix / patch:

$B"#(B RealNetworks, Inc. $B$,%;%-%e%j%F%#@H
(Real Networks, 2004.06.09)

$B!!(BRealPlayer 8 / 10, RealOne Player, RealOne Player v2 $B$K=EBg$J7g4Y!#(B

$B!!>e5-$,F1$87g4Y$r;XE&$7$F$$$k$N$+!"$=$l$H$b$=$l$>$l0c$&$b$N$J$N$+!"$O$h$/$o$+$i$J$$!#(B

$B!!(BRealOne, RealOne v2, RealPlayer 10 $B$K$O=$@5%W%m%0%i%`$,8x3+$5$l$F$$$k$N$G!"%"%C%W%G!<%H5!9=$rDL$8$FE,MQ$9$l$P$h$$!#(B RealPlayer 8 $B$O!"(BRealPlayer 10 $B$K%"%C%W%0%l!<%I8e!"%"%C%W%G!<%H$r9T$&!#(B RealPlayer 10 $B$N%$%s%9%H!<%k$K$D$$$F$O!"(B RealPlayer$B$O%9%Q%$%&%'%"!)(B $B!](B $B!V>e ($B%"%@%k%H%5%$%HHo32BP:v$NIt20(B) $B$b;2>H$5$l$?$$!#(B

$B!!4XO"5-;v(B: $B!V(BRealOnePlayer$B!W$d!V(BRealPlayer$B!W$J$I$KG$0U$N%3!<%I$r (Internet Watch)$B!#(B


$B"#(B 2004.06.11

$B"#(B $BDI5-(B


$B"#(B 2004.06.10

$B"#(B FreeBSD Security Advisory FreeBSD-SA-04:12.jailroute - Jailed processes can manipulate host routing tables
(FreeBSD, Tue, 08 Jun 2004 06:06:14 +0900)

$B!!(BFreeBSD 4.9-RELEASE $B0JA0$K7g4Y!#(Bjail(2) $B$NFbB&$+$i%[%9%H$N%k!<%F%#%s%0%F!<%V%k$rA`:n$G$-$F$7$^$&!#:G?7$N(B RELENG_4_8 $B$d(B RELENG_4_9 $B$K99?7$7$?$j!"(Bpatch $B$rE,MQ$7$?$j$7$?>e$G%+!<%M%k$r$D$/$j$J$*$7$F%$%s%9%H!<%k!":F5/F0$9$l$P$h$$!#(B $B$^$?(B FreeBSD 4.10-RELEASE $B$G$O$3$N7g4Y$O=$@5$5$l$F$$$k!#(B

$B"#(B $B:f;T$N=;4p%M%C%H!!$:$5$s1?MQ!!7@Ls7k$P$:6HL3$r0QBw(B
($B;:7P?7J9(B, 2004.06.10)

$B!!:f;T$bIY;NDL$b!"ITE,@Z$J1?MQ$r9T$C$F$$$?$3$H$O4V0c$$$J$$$G$9$M$(!D!D!#(B $BEDCf$?$1$h$7;T5D(B$B$N;XE&$,$J$+$C$?$i!"$:!<$C$H$3$s$J>uBV$rB3$1$F$$$?$C$F$3$H$J$s$G$9$+$M!#(B $B$b$7$+$7$F!"$3$s$J1?MQ!"B>$K$b$"$C$?$j$9$k$s$G$9$+$M!#(B

$B!!4XO"(B: $B=;4p%M%C%H!"7@Ls@Z$l8e$b1?MQ!!Bg:eI\:f;T(B (asahi.com)$B!#(B

$B!!%8%_!<$5$s!"NoH~$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2004.06.15 $BDI5-(B:

$B!!>\:Y(B: $B=;L14pK\BfD"%M%C%H%o!<%/%7%9%F%`$N4pK\E*1?MQ$,4m5!$K$5$i$5$l$F$$$^$9(B $B!]:f;T$HIY;NDL!&=;L14pK\BfD"%M%C%H$N6HL30QBw7@#2%v7n4V7k$P$l$:!](B ($BEDCf$?$1$h$7;T5D(B, info from [social-memo:32])$B!#(B

$B$^$?IY;NDL$N!VI\2<#1#0<+<#BN$G$b

$B"#(B $BIT@5$J8D?M>pJs
(Yahoo! JAPAN)

$B!!(BYahoo! JAPAN $BA@$$$N%U%#%C%7%s%0$@$=$&$G!#(B $B!VJ8=qNc!W$d!VIT@5$J%[!<%`%Z!<%8%"%I%l%9!W$N;vNc$,7G:\$5$l$F$$$^$9$M!D!D!#(B 61.121.100.100 $B$O(B Nifty$B!"(B202.212.115.115 $B$H(B 218.47.162.23 $B$O$W$i$i$G$9$+!#(B http://www.pureweb.jp/~sagi/geocity/ID/login $B$H(B http://j2k.naver.com/j2j.php/height/edit.yahoo.co.jp/config/send_webmesg?.src=pg&.target=dy4649 $B$O$^$@;D$C$F$^$9$M!D!D!#(B $B@5$7$$%V%i%&%6$r;H$($P!"(Bhttp://www.pureweb.jp/~sagi/geocity/ID/login $B$NJ}$O%=!<%9$7$+8+$($J$$$N$G$9$,!#%=!<%9$,8+$($J$$%V%i%&%6$OJQ$J%V%i%&%6$J$N$G!";H$o$J$$$h$&$K$7$^$7$g$&!#(B $B$3$&$$$&0UL#$G$b!"(BWindows XP SP2 $B$,BT$A1s$7$$$G$9$M!#(B

$B!!$^$?$I$A$i$b!"!V%b!<%I(B: $B%;%-%e%"(B (SSL)$B!W$NJ}$OK\J*$K$D$J$,$k$h$&$K$J$C$F$^$9$M!#(BSSL $B;H$C$?>e$G!"$A$c$s$H80$NCf?H$r3NG'$7$^$7$g$&!#!D!D$H$O(B Yahoo! $B$NJ8=q$K$O=q$+$l$F$$$J$$$J$"!#$$$^$I$-$N@$$NCf$G$O%"%I%l%9%P!<:>>N967b$H$+$b$"$j$^$9$+$i!"2DG=$J8B$j(B SSL $B$KM6F3$7$?J}$,$$$$$H;W$&$N$@$1$I!#(B $B$=$&$$$&0UL#$G$O!"%m%0%$%s2hLL$N!VI8=`!W$H$$$&8@MU$O$h$/$J$$$G$9$M$(!#(B

$B"#(B enpa-sa-00014: Multiple security problems in Ethereal 0.10.3
(ethereal.com, 2004.05.13)

$B!!(BEthereal 0.9.8$B!A(B0.10.3 $B$K(B 4 $B$D$N7g4Y!#(B0.10.4 $B$G=$@5$5$l$F$$$k!#(B

fix / patch:

$B"#(B [Full-Disclosure] iDEFENSE Security Advisory 06.08.04: Squid Web Proxy Cache NTLM Authentication Helper Buffer Overflow Vulnerability
(Full-Disclosure, Wed, 09 Jun 2004 04:00:21 +0900)

$B!!(Bsquid 2.5.x / 3.x $B$KIUB0$9$k(B NTLM $BMQG'>Z%X%k%Q!<$K(B buffer overflow $B$9$k7g4Y$,$"$k!"$H$$$&;XE&!#(BCVE: CAN-2004-0541$B!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$^$?!"(BNTLM $BMQG'>Z%X%k%Q!<$r;H$o$J$$$3$H$G2sHr$G$-$k!#(B $B%G%U%)%k%H$G$O!"(BNTLM $BMQG'>Z%X%k%Q!<$O;H$o$l$J$$!#(B

fix / patch:

$B"#(B $BDI5-(B

$B"#(B goo$B%j%5!<%A7k2L(B (No.59) $B!VBh#22s4k6H$N8D?M>pJsJ]8n$H>pJs%;%-%e%j%F%#BP:v$K4X$9$k0U<1D4::!W(B
(goo $B%j%5!<%A(B, 2004.06.09)

$B!!!VD4::BP>]!'

$B!!(Btop $B$K$O!V8D?M>pJsO31L;v7o$NB?H/$r$-$C$+$1$K!"H>?t0J>e$N4k6H$,8D?M>pJsJ]8nBP:v$r?d?J!W$H$"$k$,!"Cf?H$rFI$s$G$$$/$H!"!VH>?t0J>e$N4k6H!W$NLs(B 2/3 $B$O!V8!F$Cf!W$H$$$&CJ3,!#(B

$B:#8e

$B!!(BISMS $B$d(B BS7799 $B$OL5;k$5$l$F$$$k$s$@$m$&$+!D!D$H;W$C$F$_$F$_$k$H!"$J$s$H!"!V(BISMS $B$N$N9`L\$b(B 10% $BBf$J$o$1$G!"$=$l$@$1FC=P$7$7$F!V:G$bB?$/!W$J$I$H8@$&$Y$-$G$O$J$$5$$,!#(B


$B"#(B 2004.06.09

$B"#(B [Full-Disclosure] Advisory 09/2004: More CVS remote vulnerabilities
(Full-Disclosure, Wed, 09 Jun 2004 22:00:04 +0900)

$B!!(BCVS 1.12.8 / 1.11.16 $B0JA0$K7g4Y!#(B $B$3$N$^$($NOC(B $B$N$"$H$GD4$Y$J$*$7$?$i!"(BCVS $B$K$O$^$@$^$@7g4Y$,$"$C$?$=$&$G!#$7$+$bJ#?t!#(B remote $B$+$iG$0U$N%3!<%I$rCAN-2004-0414 CAN-2004-0416 CAN-2004-0417 CAN-2004-0418 $B$,EPO?$5$l$?$=$&$G!#8=>u$G$OM=Ls$5$l$F$$$k$@$1$N$h$&$G$9$,!#(B

fix / patch:

Changelog:

2004.06.10

$B!!(BCVS, Red Hat, Debian, OpenBSD $B$N(B fix / patch $B$rDI5-!#(B

$B"#(B $BDI5-(B

$B"#(B $B!V%&%$%k%9%P%9%?!<(B2004$B!W$KIT6q9g!$$?$@$7%;%-%e%j%F%#>e$N1F6A$O>.$5$$(B
($BF|7P(B IT Pro, 2004.06.08)

$B!!

$B"#(B $B:#F|$O(B Windows Update $B$NF|(B: 2004 $BG/(B 6 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2004.06.09)

$B!!(B6 $B7n$O0J2<$N(B 2 $BE@$G$7$?(B:

$B!!$$$:$l$b(B patch $B$,$"$k$N$GE,MQ$7$^$7$g$&!#(B Window 9x/Me $B$K$O$J$$$G$9$,!#(B

$B"#(B Oracle E-Business Suite$B$K4m81$J%;%-%e%j%F%#!&%[!<%k!$4IM}
($BF|7P(B IT Pro, 2004.06.09)

$B"#(B [SA11791] jCIFS Arbitrary Username Authentication Security Issue
(secunia, Wed, 09 Jun 2004 18:52:38 +0900)

$B!!(BjCIFS: Common Internet File System Client in 100% Java (samba.org) 0.9.0 $B0JA0$K7g4Y!#(BCIFS $B%5!<%P>e$G(B guest $B%"%+%&%s%H$,M-8z$K$J$C$F$$$k$H!"(BjCIFS $B$O4V0c$C$?%f!<%6L>$G$bG'>Z$K@.8y$7$F$7$^$&!#(B jCIFS 0.9.1 $B$G=$@5$5$l$F$$$k!#(B


$B"#(B 2004.06.08

$B"#(B Webmin Unspecified Denial of Service and Security Restriction Bypass
(secunia, Mon, 07 Jun 2004 23:01:56 +0900)

$B!!(BWebmin 1.140 ($B0JA0(B?) $B$K(B 2 $B$D$N7g4Y!#(B

  • $B$"$i$f$k%f!<%6$,!"$?$H$(%"%/%;%9$,5v2D$5$l$F$$$J$/$F$b!"$I$s$J%b%8%e!<%k$N@_Dj$G$b8+$k$3$H$,$G$-$F$7$^$&!#(B
  • $B967b$"$k$$$O%Q%9%o!<%I$rAw?.$9$k$3$H$K$h$j!"@5$7$$%f!<%6$rJD$a=P$7$F$7$^$&$3$H$,$G$-$k!#(B

$B!!(BWebmin 1.150 $B$G=$@5$5$l$F$$$k!#(BChanges since Webmin version 1.140 $B$b;2>H!#(B

2004.06.11 / 14 $BDI5-(B:

$B"#(B [Full-Disclosure] Internet explorer 6 execution of arbitrary code (An analysis of the 180 Solutions Trojan)
(Full-Disclosure, Mon, 07 Jun 2004 10:21:52 +0900)

$B!!A0;K(B: [Full-Disclosure] 180 Solutions Exploits and Toolbars Hacking Patched Users(I.E Exploits)$B!#(B

$B!!(Bhttp://216.130.188.219/ei2/installer.htm $B$K$"$k(B IE $B96N,%H%m%$(B ($B4m81(B!! $B%"%/%;%9$9$k>l9g$O!"(BJavaScript / $B%"%/%F%#%V%9%/%j%W%H$rL58z$K$7$F$+$i$K$9$k$3$H(B) $B$K$D$$$F!"(Bhttp://62.131.86.111/analysis.htm $B$G2r@b$7$F$$$k!#(BJelmer $B;a$O!"(Bhttp://216.130.188.219/ei2/installer.htm $B$G$OJ#?t$N4{CN$N7g4Y$H(B 2 $B$D$N?7

$B!!$J$*!"(Bhttp://216.130.188.219/ei2/installer.htm $B$N%9%/%j%W%HItJ,$O(B Windows Script Encoder ($B%@%&%s%m!<%I(B) $B$K$h$C$F%(%s%3!<%I$5$l$F$$$k!#(B $B$3$l$r30$9$K$O!"$?$H$($P(B Windows Script Decoder $B$,;H$($k$=$&$@!#(B Obfuscated-HTML De-obfuscation Tools $B$H$$$&%Z!<%8$b$"$k$=$&$G!#(B

$B!!$^$?!"(Bhttp://62.131.86.111/analysis.htm $B$K<($5$l$F$$$k(B exploit.zip $B$NCf?H$K$D$$$F!"(B VBS/Psyme ($B%7%^%s%F%C%/(B: Downloader.Psyme) $B$@$HH=CG$9$k%"%s%A%&%#%k%9%W%m%@%/%H$,$"$k$=$&$@(B (Larry Seltzer $B;a$N%a!<%k(B)$B!#(B

$B!!!D!D(BSecunia Advisory $B=P$^$7$?(B: Internet Explorer Local Resource Access and Cross-Zone Scripting Vulnerabilities$B!#(B $B2sHr:v$H$7$F!"%"%/%F%#%V%9%/%j%W%H$NL58z2=$H(B ms-its: URI $B%O%s%I%i$N:o=|$r5s$2$F$$$^$9!#(B

2004.06.09 $BDI5-(B:

$B!!(BIE6$B$KG$0U$N%3!<%I$, (Internet Watch)$B!#(B

2004.06.15 $BDI5-(B:

2004.07.31 $BDI5-(B:

$B!!(BInternet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (867801) (MS04-025) $B$G=$@5$5$l$?!#(B

$B"#(B $BDI5-(B

APPLE-SA-2004-05-21 Security Update 2004-05-24

$B!!(BAPPLE-SA-2004-05-28 Mac OS X Update 10.3.4 ($B8EJkNC;a$K$h$kK.LuHG(B)$B!#(B Mac OS X 10.3.4 $B$K$O(B CAN-2004-0485 $B$N=$@5$,4^$^$l$F$$$^$9!#(B

$B!!$5$i$K!"(BAPPLE-SA-2004-06-07 Security Update 2004-06-07 ($B8EJkNC;a$K$h$kK.LuHG(B) $B$,EP>l!#(Bdisk: URI $B%O%s%I%i$K$D$$$F$N=$@5$,4^$^$l$F$$$^$9!#(B $B$7$+$7!"(B

$B%3%s%]!<%M%s%H(B: DiskImageMounter
CVE-ID: $B$3$l$ODI2CE*$JM=KI:v$G$"$k$?$a!$(BCVE ID $B$O

$B$3$N$h$&$J07$$$OA4$/$$$?$@$1$^$;$s!#(BApple $B$H$$$&2q


$B"#(B 2004.06.07


$B"#(B 2004.06.06

$B"#(B solution 9245: $B%Q%?!<%s%U%!%$%k$,<+F0E*$K(B100$BHVBf$K$J$C$?>l9g$NBP1~J}K!$K$D$$$F(B
($B%H%l%s%I%^%$%/%m(B, 2004.06.05)

$B!!8!:w%(%s%8%s(B VSAPI 6.640 (2004.08.05 $B$G%5%]!<%H=*N;(B) $B0JA0$r;H$C$F$$$k$H!"%Q%?!<%s%U%!%$%k(B 901 (1.901.00) $B$X$N%"%C%W%G!<%H;~$K!"%Q%?!<%s%U%!%$%k$NHV9f$,(B 101 (1.101.00) $B$KLa$C$F$7$^$C$?$j!"%"%C%W%G!<%H$K<:GT$7$?$j$9$k!#(B VSAPI 6.810 $B0J9_$G$O$3$NLdBj$OH/@8$7$J$$!#(B $B0lHL$K$O8!:w%(%s%8%s$N%"%C%W%G!<%H$r9T$($PLdBj$O2r7h$9$k$h$&$@$,!"@=IJ$K$h$C$Fsolution 9245 $B$+$i$?$I$l$k3F@=IJKh$NBP1~J}K!$r;2>H$7$F$*$/$3$H!#(B


$B"#(B 2004.06.04


$B"#(B 2004.06.03

$B"#(B $B6HL3>e;H$o$J$/$J$C$?8D?M>pJs$O
($BF|7P(B IT Pro, 2004.06.01)

$B!!(B$BF|7P%3%s%T%e!<%?(B 2004.05.31 $B$N!VFC=8(B 2: $B>pJsO31H!";v7o$K3X$V;v8eBP:v!W4XO"5-;v!#(B $BEz$($,4JC1$K8+$D$+$k$b$N$G$O$J$$$+$i$3$=!"5DO@$r=E$M$kI,MW$,$"$k$N$@$m$&$J$"!#$=$N2aDx$G8+$D$+$k$b$N$b$"$k$@$m$&$7!#(B

$B!!$A$J$_$K!"(Bfml 4 $B$G(B confirm $B$7$F$$$k>l9g!"(B/var/spool/ml/mlname/var/log/confirm $B$,$*$b$$$C$-$j8D?M>pJs$H2=$7$F$$$^$9!#5$$,$D$+$J$5$=$&$J>l=j$K$"$k$N$GCm0U$,I,MW$G$9!#$3$l$K5$$,$D$$$?$H$-$K$O!"$N$1$>$j$^$7$?!#(B

$B"#(B $BDI5-(B

Microsoft Windows $B4XO"(B

$B!!(Bweissbach $B$5$s$+$i$N>pJs(B ($B$"$j$,$H$&$4$6$$$^$9(B) $B$K$h$k$H!"%$%a!<%8%^%C%W$K$h$k%9%F!<%?%9%P!<56Au$N7o$O(B Safari 1.2.2 (v125.7) $B$G$bH/@8$9$k$=$&$@!#(B

$B"#(B MITKRB5-SA-2004-001: buffer overflows in krb5_aname_to_localname
(bugtraq, Wed, 02 Jun 2004 05:32:42 +0900)

$B!!(BMIT Kerberos 1.3.3 $B0JA0$K4^$^$l$k(B krb5_aname_to_localname() $B4X?t$K7g4Y!#(B $B$3$l$O(B aname $B"*(B lname mapping $B$rl9g$KLdBj$H$J$k!#(B krb5_aname_to_localname() $B$K$*$$$F(B buffer overflow $B$9$k$?$a!"$3$l$rMxMQ$9$k$H(B remote $B$+$i%5!<%S%9F0:n8"8B(B ($BDL>o(B root) $B$rCAN-2004-0523

$B!!(BMIT Kerberos 1.3.3 $BMQ$N(B patch $B$,8x3+$5$l$F$$$k!#(BMIT Kerberos 1.3.4 $B$G=$@5$5$l$k$=$&$@!#(B

fix / patch:

$B"#(B Opera Favicon Displaying Address Bar Spoofing Vulnerability
(secunia, 2004.06.03)

$B!!(BOpera 7.50 $B0JA0$N(B 7.x $B$K7g4Y!#Bg$-$J(B favicon $B2hA|$rMxMQ$7$F!"%"%I%l%9%P!<$d%Z!<%8%P!<$J$I$r56Au$9$k$3$H$,2DG=!#(BOpera 7.51 $B$G=$@5$5$l$F$$$k!#(BOpera 7.51 $B$G$O!"%"%I%l%9%P!

$B!!>\:Y(B: [Full-Disclosure] Phishing for Opera (GM#007-OP)

$B"#(B [Full-Disclosure] Format String Vulnerability in Tripwire
(Full-Disclosure, Thu, 03 Jun 2004 08:41:16 +0900)

$B!!(BTripwire $B%*!<%W%s%=!<%9HG(B 2.3.1 $B0JA0(B / $B>&MQHG(B 2.4 $B0JA0$K7g4Y!#(B $B%A%'%C%/7k2L$rEE;R%a!<%k$K$h$jDLCN$9$k5!G=(B (tripwire -m c -M $B$"$k$$$O(B tripwire --check --email-report) $B$K(B format $B%P%0$,$"$j!"FC$r@_Dj$7$?%U%!%$%k$r;E3]$1$i$l$k$3$H$K$h$C$FG$0U$N%3%^%s%I$r

$B!!;XE&J8=q$K%*!<%W%s%=!<%9HG(B Tripwire 2.3.1 $BMQ$N(B patch $B$,E:IU$5$l$F$$$k!#(B


$B"#(B 2004.06.02

$B"#(B $BDI5-(B

$B"#(B $BB>?M$N%a!<%k$rFI$`J}K!(B
([memo:7583], 2004.05.14)

$B!!(Bworld writable $B$J(B mail spool $B$K$OCm0U$7$^$7$g$&!#(B

$B"#(B Microsoft Windows $B4XO"(B
(various)

2004.06.03 $BDI5-(B:

$B!!(Bweissbach $B$5$s$+$i$N>pJs(B ($B$"$j$,$H$&$4$6$$$^$9(B) $B$K$h$k$H!"%$%a!<%8%^%C%W$K$h$k%9%F!<%?%9%P!<56Au$N7o$O(B Safari 1.2.2 (v125.7) $B$G$bH/@8$9$k$=$&$@!#(B

$B"#(B $BJ?@.#1#5G/EYEE5$DL?.%5!<%S%9%b%K%?!<$KBP$9$kBh#22s%"%s%1!<%HD4::7k2L(B
($BAmL3>J(B, 2004.05.28)

$B!!%;%-%e%j%F%#OC$H$7$F$O!V(B3. $B%U%#%k%?%j%s%0$K$D$$$F!W!V(B4. $B%3%s%T%e!<%?%&%#%k%9$K$D$$$F!W$,4XO"$G$7$g$&$+!#(B

$B!!!V(B3. $B%U%#%k%?%j%s%0$K$D$$$F!W$G$O!VI,MW$@$H;W$&(B: 58.1%$B!"?M$K$h$C$F$OI,MW$@$H;W$&(B: 37.9%$B!W$G$"$k$K$b$+$+$o$i$:!"

$B!!$J$*!"(B$B%"%s%1!<%HD4::7k2L!JJs9p=q$h$jH4?h!K(B $B$G$O!"%U%#%k%?%j%s%0$NI,MW@-$N$H$3$m$@$1$7$+:\$C$F$$$J$$!#H4?h$N;EJ}$K6/$$:n0Y$r46$8$k!#(B$B40A4HG(B $B$rFI$_$^$;$&!#(B ($B8m;z=$@5(B: $B$i$`$8$#$5$s46

$B!!!V(B4. $B%3%s%T%e!<%?%&%#%k%9$K$D$$$F!W$G$O!"(BWindows Update $B$O(B 69.0% $B$,B8:_$rCN$C$F$*$j!"(B55.6% $B$,G[?.$"$j


$B"#(B 2004.06.01

$B"#(B $BDI5-(B


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B