$B%;%-%e%j%F%#%[!<%k(B memo - 2005.04

Last modified: Mon Jan 16 14:27:30 2006 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2005.04.30

$B"#(B $BDI5-(B

SYM05-007: Symantec AntiVirus RAR archive bypass

$B!!(BSYM05-007: Symantec AntiVirus $B$K(B RAR $B%"!<%+%$%V$r%P%$%Q%9$9$k@H ($B%7%^%s%F%C%/(B)$B!#(B


$B"#(B 2005.04.28

$B"#(B SYM05-007: Symantec AntiVirus RAR archive bypass
(Symantec, 2005.04.28)

$B!!%7%^%s%F%C%/$N(B Windows $BMQ%"%s%A%&%$%k%9%W%m%@%/%H$K7g4Y!#(B $B6qBNE*$K$O!"(B Symantec Web Security, Symantec Mail Security for SMTP, Symantec AntiVirus Scan Engine, Symantec SAV/Filter for Domino NT, Symantec Mail Security for Exchange, Symantec Norton AntiVirus 2005, Symantec Norton Internet Security 2005 , Symantec Norton System Works 2005 $B$K7g4Y$,$"$k!#(B RAR $B%U%!%$%k$N8!::$K$*$$$F!"FCl9g$,$"$k!#$3$N7k2L!"Ev3:(B RAR $B%U%!%$%kFb$K%&%$%k%9$,3JG<$5$l$F$$$F$b8!::$5$l$J$$$^$^$K$J$C$F$7$^$&!#(B

$B!!=$@5HG$,$9$G$KB8:_$9$k!#(BLiveUpdate $BEy$G:G?7$N(B patch $B$rE,MQ$7$F$"$l$P!"=$@5$5$l$?HG0J9_$K$J$C$F$$$k$O$:$N$h$&$@!#>\:Y$K$D$$$F$O(B SYM05-007 $B$r;2>H!#(B $B

2005.04.30 $BDI5-(B:

$B!!(BSYM05-007: Symantec AntiVirus $B$K(B RAR $B%"!<%+%$%V$r%P%$%Q%9$9$k@H ($B%7%^%s%F%C%/(B)$B!#(B

$B"#(B Google$B$N%9%Z%k%_%90-MQ%5%$%H!"%"%/%;%9$9$k$H(BPC$B>h$C
(ITmedia, 2005.04.28)

$B!!LdBj$N%5%$%H(B Googkle.com $B$r$A$g$C$H8+$F$_$?$N$G$9$,!"3N$+$K$$$m$$$m;E3]$1$i$l$F$$$k$h$&$G!#$$$d$O$d!#;E3]$1$N$R$H$D(B counter.jpg $B$NCf?H$O$3$s$J46$8(B:

% unzip -l counter.jpg 
Archive:  counter.jpg
  Length     Date   Time    Name
 --------    ----   ----    ----
    19952  07-09-04 18:03   Counter.class
      240  07-09-04 18:03   Gummy.class
        0  07-09-04 18:03   META-INF/
       71  07-09-04 18:03   META-INF/MANIFEST.MF
      902  07-09-04 18:03   VerifierBug.class
     3400  07-09-04 18:03   Worker.class
     1263  07-09-04 18:03   Xeyond.class
     8992  04-24-05 18:52   web.exe
 --------                   -------
    34820                   8 files

$B!!$3$N$&$A(B MANIFEST.MF $B$O(B

Manifest-Version: 1.0
Created-By: 1.3.0_02 (Sun Microsystems Inc.)

$B$H$$$&$@$1$N%U%!%$%k$J$N$G$$$$$N$G$9$,!"B>$OA4It%"%l$J%U%!%$%k$G$9!#(B Gummy.class $B$d(B web.exe $B$r%&%$%k%9H=Dj$7$J$$%W%m%@%/%H$,$1$C$3$&$"$k$N$GCm0U!#(B web.exe $B$K$D$$$F$O!"(BAVG / Dr.Web / F-Prot / Kaspersky / mks_vir / VBA32 / McAfee $B$O8!=P$7$?!#(BNorton AntiVirus 2005 (20050427.008) $B$d(B Trendmicro (Virus Scanner v3.1, VSAPI v7.510-1002 / Pattern number 2.604.00) $B$G$O8!=P$7$J$+$C$?!#(B

2005.05.02 $BDI5-(B:

$B!!(BHandler's Diary April 30th 2005 (SANS ISC) $B$K$h$k$H!"Ev3:%I%a%$%s$N(B DNS $B%(%s%H%j$,:o=|$5$l$?LOMM!#(B googkle.com $B$NB>$K$b$$$m$$$m$"$C$?$_$?$$$G$9!#(B

$B"#(B $BDI5-(B

Adobe Reader$B!?(BAcrobat$B$K%;%-%e%j%F%#!&%[!<%k!$%O%s%0%"%C%W$5$;$i$l$k62$l$"$j(B

$B!!(B$B%"%I%S%7%9%F%`%: ($BIY;NDL(B, 2005.04.21)$B!#@=IJE:IU(B CD-ROM $BFb$N(B Acrobat Reader / Adobe Reader $B$K4X$9$kJ8=q!#(B

$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B

$B!!(B$B%&%$%k%9%Q%?!<%s%U%!%$%k$K4X$9$kLdBj$K$D$$$F(B ($B%H%l%s%I%^%$%/%m(B) $B$H$$$&%Z!<%8$,$G$-$F$$$^$9!#(B

$B$$$m$$$m(B (2005.03.19)

$B!!(BDSA-717-1 lsh-utils -- buffer overflow, typo (Debian GNU/Linux, 2005.04.27)

Stable CVS Version 1.11.20 Released! * Security Update *

$B"#(B 2005.04.27

$B"#(B $BDI5-(B

mixi$B$K(BCSRF$B@H

$B!!(B$B!V$\$/$O$^$A$A$c$s!W(B $B!=!=CN$i$l$6$k(BCSRF$B967b(B (@IT, 2005.04.27)

Stable CVS Version 1.11.20 Released! * Security Update *
$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B
TCP/IP $B$N@H

$B!!I{:nMQ>pJs(B:

2005 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BWindows $B%$%s%9%H!<%i(B 3.1 $B$r%$%s%9%H!<%k$9$k$H!"=$@5%W%m%0%i%`$K$h$C$F$OE,MQ$K<:GT$9$k2DG=@-$,$"$k(B (updatecorp.co.jp)$B!#(B

Windows $B%$%s%9%H!<%i$N8F$S=P$7;~$K40A4%5%$%l%s%H(B $B%$%s%9%H!<%k$N$?$a$N%*%W%7%g%s$r;XDj$9$k$H!"E,MQ$K<:GT$7$^$9!#(B

$B!!(B4 $B7n$N(B Windows Update $B$NF|$K(B Windows $B%$%s%9%H!<%i(B 3.1 $B$bG[I[$5$l$F$$$^$9$,!"8_49@-$K>/!9Fq$,$"$k$h$&$G$9!#(B


$B"#(B 2005.04.26

$B"#(B Microsoft Word $B$N@H
(Microsoft, 2005.04.13)

$B!!$J$s$@$+(B old news $B$G$9$,!D!D(B

$B!!(BMicrosoft Word 2000 (Office 2000), Word 2002 (Office XP), Word 2003 (Office 2003) $B$K(B 2 $B$D$N7g4Y!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$U$D$&$N?M$O(B Office Update $B$r;H$&$N$,$h$$$@$m$&!#(B

$B"#(B $BDI5-(B

$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B

$B!!:#2s$N;v>]$K$D$$$F$O!"F|7P(B IT Pro $B$N0lO"$N5-;v$,$$$A$P$s$^$H$^$C$F$$$k46$8$G$9!#(B

$B!!$"$H!"$3$s$J5-;v$b(B:

$B!!F|K\@/I\$4MQC#!"$G$9$7$M$(!#(B

2005.04.26 $B?

$B!!%(%P!&%A%'%s

$B!!0lJ}!"%H%l%s%I%^%$%/%m$N%5%]!<%H>pJs$,BgI}$K99?7$5$l$F$$$^$9!#(B

$B!!(BWindows XP SP2$B!"(BWindows Server 2003 gold / SP1 $B$O7g4Y$,9b$$3NN($GH/8=$9$k$,!"(BWindows Me $B$d(B Microsoft Office XP ($B$rEc:\$7$?(B PC) $B$G$bDc$$3NN($G$O$"$k$,H/8=$9$k!"$H$5$l$F$$$^$9!#(B 2ch.net $B$G$O!V(BWindows 2000 $B$@$1$IH/8=$7$?!W$H$$$&Js9p$,=P$F$$$?$1$I!"$3$&$$$&$3$H$@$C$?$N$+$J!#(B

$B!!$^$?!"A49qL5NA=PD%%5%]!<%H$HA49q(B CD $BG[I[$r9T$&$=$&$G$9!#(B

TCP/IP $B$N@H

$B!!I{:nMQ>pJs(B:


$B"#(B 2005.04.25

$B"#(B MSN Messenger $B$N@H
(Microsoft, 2005.04.13)

$B!!$J$s$@$+(B old news $B$G$9$,!D!D!#(B

$B!!(BMSN Messenger 6.2 / MSN Messenger 7.0 $B&B$K7g4Y!#:Y9)$7$?(B GIF $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$r

$B!!=$@5HG(B MSN Messenger 6.2 $B$,MQ0U$5$l$F$$$k$N$G%$%s%9%H!<%k$9$l$P$h$$!#(B MSN Messenger 7.0 $B@5<0HG$K%"%C%W%0%l!<%I$9$k$3$H$GBP1~$9$k$N$b$h$$$@$m$&!#(B

$B!!4XO"(B:

$B"#(B Exchange Server $B$N@H
(Microsoft, 2005.04.13)

$B!!$J$s$@$+(B old news $B$G$9$,!D!D(B

$B!!(BExchange 2000 SP3, Exchange 2003 gold / SP1 $B$K7g4Y!#(B SMTP $B%5!<%S%9$K$*$1$k!"FCDj$N3HD%%3%^%s%I$r=hM}$9$kItJ,(B (xlsasink.dll) $B$K(B buffer overflow $B$9$k7g4Y$,$"$k$?$a!"(Bremote $B$+$iG$0U$N%3!<%I$r

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$?$@$7!"(BExchange 2000 $BMQ$N(B patch $B$r%$%s%9%H!<%k$9$k$K$O!"(B SP3 $B$NB>!"(B2004 $BG/(B 8 $B7n8x3+$N(B Exchange 2000 Server Service Pack 3 $B0J9_$N99?7%W%m%0%i%`$N%m!<%k%"%C%W(B $B$r$"$i$+$8$a%$%s%9%H!<%k$7$F$*$/I,MW$,$"$k!#(B $B$^$?(B patch $B$r%$%s%9%H!<%k$9$k$H!"(BExchange 2000 $B$N>l9g$G$b!"(BExchange 2003 $B$HF1MM$NG'>Z$,;vA0$KI,MW$H$J$k!#(B

$B!!4XO"(B:

$B"#(B SNS Advisory No.80: nProtect:Netizen Arbitrary File Download Vulnerability
(LAC SNS, 2005.04.25)

$B!!(BnProtect:Netizen Ver.2005.4.20.1 $B$h$jA0$K7g4Y!#(BnProtect:Netizen $B$N%"%C%W%G!<%H5!G=$K7g4Y$,$"$j!"G$0U$N%U%!%$%k$rG$0U$N>l=j$KJ]B8$5$;$k$J$I$N0-6H$,2DG=$H$J$k!#(BVer.2005.4.20.1 $B0J9_$G=$@5$5$l$F$$$k!#(BnProtect:Netizen $B$r5/F0$9$k$3$H$K$h$j!"<+F0E*$K99?7$5$l$k!#(B $B4XO"(B:

$B!!(BnProtect:Netizen $B$K$D$$$F$O0J2<$b;2>H(B:

$B!!(BSAISON CARD$B%[!<%`%Z!<%8$K$F(BnProtect Netizen$B%5!<%S%93+;O(B (npro-shop.jp) $B$G$9$+!D!D!#(B

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

mixi$B$K(BCSRF$B@H

$B!!(B$BBgNL$N!V$O$^$A$A$c$s!W$r@8$_=P$7$?(BCSRF$B$N@H (ITmedia, 2005.04.23)

$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B

$B!!B3Js$J$I(B:

Stable CVS Version 1.11.20 Released! * Security Update *

$B"#(B 2005.04.24

$B"#(B $BDI5-(B

$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B

$B!!B3Js$J$I!#(B@IT $B$N5-;v$,>\$7$$!#(B

$B!!(B$B%&%$%k%9%Q%?!<%s%U%!%$%k(B2.594.00$B!JF|K\;~4V!'(BAM7:33$B:"8x3+!K$X$N%"%C%W%G!<%H$K$*$1$k!"%3%s%T%e!<%?$N(BCPU$B$,(B100%$B$K$J$k8=>]$K4X$7$F(B ($B%H%l%s%I%^%$%/%m(B) $B$O?o;~2~D{$5$l$F$$$k!#;v>]$O!"%&%$%k%98!:w%(%s%8%s$,(B 7.5xx $B$N>l9g$K$N$_H/@8$7$F$$$?$h$&$@!#$^$"!"$U$D$&$O(B 7.510 $B$r;H$C$F$$$k$O$:$J$o$1$J$N$@$,!#(B

$B860x(B
Ultra Protect$B05=L%U%!%$%k$r2rE`!"8!:w$9$k$?$a$N%Q%?!<%s%U%!%$%k$NLdBj(B
$B"(860x$K$D$$$F$O!"0z$-B3$-D4::Cf$G$9!#(B

$B!!(BUltra Protect $B$H$$$&$N$O!"(B$B$3$l(B $B$N$3$H$+(B?

$B!!$5$i$KB3Js(B:

$B!!$5$i$KB3Js(B (22:53):


$B"#(B 2005.04.23

$B"#(B $B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B
($BFIGd(B, 2005.04.23)

$B!!(BWindows XP SP 2 / Server 2003 + $B%H%l%s%I%^%$%/%m(B $B%&%$%k%9%P%9%?!<(B + $B%Q%?!<%s%U%!%$%k(B 2.594.00 $B$NAH$_9g$o$;$G(B CPU 100% $B>uBV$K$J$C$F$7$^$&$?$a!"(B $B$$$/$D$b$NAH?%$GBg5,LO$J>c32$,H/@8$7$?LOMM!#(B $B%Q%?!<%s%U%!%$%k(B 2.596.00 $B$G=$@5$5$l$F$$$k!#(B

$B!!JsF;$K$h$k$H!">/$J$/$H$b6&F1DL?.!"D+F|?7J9!"FIGd?7J9!"F|K\7P:Q?7J9!";:7P?7J9!"?.G;KhF|?7J9!"(BJR $BElF|K\!":4@n5^JX!"Bg:e;T1DCO2c32$,H/@8$7$F$$$?LOMM!#(B

$B!!(BWindows XP SP2 / Server 2003 $B$r:NMQ$7!"$+$D%Q%?!<%s%U%!%$%k$bB(9o99?7$7$F$$$k$h$&$JAH?%$G$@$11F6A$,H/8=$7$F$$$k$N$O!"$J$s$H$bHiFy$JOC$G$O$"$k!#(B

$BJ$J$I$K$O%H%i%V%k$O$J$/!"6bM;5!4X$N8=6b<+F0MBJ'5!!J#A#T#M!K$X$N>c32Js9p$b$J$$$H$$$&!#(B

$B!!$3$l$i$G$O(B XP SP2 / Server 2003 $B$r;H$C$F$$$J$$$N$+!"$"$k$$$O%Q%?!<%s%U%!%$%k$rB(9o99?7$7$F$$$k$o$1$G$O$J$$$N$+!#>/$J$/$H$b(B ATM $BJ}LL$O$^$@$^$@(B NT 4.0 $B$,B?$$$H;W$&$1$I!#(B

$B!!EZMKF|$@$C$?$?$a!"EZMKF|$G$b2TF/$7$F$$$k$h$&$JAH?%(B ($B%$%s%U%i7O(B) $B$G$7$+I=N)$C$?>c32$,H/8=$7$J$+$C$?$h$&$@$,!"J?F|$G$"$l$P$b$C$HBg5,LO$J>u67$K$J$C$F$$$?$H9M$($i$l$k!#@5D>!"$3$N$H$3$m$N%H%l%s%I%^%$%/%mJ}LL$OIT6q9g$,B?$9$.$k$h$&$K;W$&$N$@$,!"%H%l%s%I%^%$%/%m@=IJ$rF3F~!&1?MQ$7$F$$$kAH?%$NCf$N?M$O$I$N$h$&$K9M$($F$$$k$s$@$m$&!#(B

$B!!4XO"(B:

2005.04.24 $BDI5-(B:

$B!!B3Js$J$I!#(B@IT $B$N5-;v$,>\$7$$!#(B

$B!!(B$B%&%$%k%9%Q%?!<%s%U%!%$%k(B2.594.00$B!JF|K\;~4V!'(BAM7:33$B:"8x3+!K$X$N%"%C%W%G!<%H$K$*$1$k!"%3%s%T%e!<%?$N(BCPU$B$,(B100%$B$K$J$k8=>]$K4X$7$F(B ($B%H%l%s%I%^%$%/%m(B) $B$O?o;~2~D{$5$l$F$$$k!#;v>]$O!"%&%$%k%98!:w%(%s%8%s$,(B 7.5xx $B$N>l9g$K$N$_H/@8$7$F$$$?$h$&$@!#$^$"!"$U$D$&$O(B 7.510 $B$r;H$C$F$$$k$O$:$J$o$1$J$N$@$,!#(B

$B860x(B
Ultra Protect$B05=L%U%!%$%k$r2rE`!"8!:w$9$k$?$a$N%Q%?!<%s%U%!%$%k$NLdBj(B
$B"(860x$K$D$$$F$O!"0z$-B3$-D4::Cf$G$9!#(B

$B!!(BUltra Protect $B$H$$$&$N$O!"(B$B$3$l(B $B$N$3$H$+(B?

$B!!$5$i$KB3Js(B:

2005.04.24 22:53 $BDI5-(B:

$B!!$5$i$KB3Js(B:

2005.04.25 $BDI5-(B:

$B!!B3Js$J$I(B:

2005.04.26 $BDI5-(B:

$B!!:#2s$N;v>]$K$D$$$F$O!"F|7P(B IT Pro $B$N0lO"$N5-;v$,$$$A$P$s$^$H$^$C$F$$$k46$8$G$9!#(B

$B!!$"$H!"$3$s$J5-;v$b(B:

$B!!F|K\@/I\$4MQC#!"$G$9$7$M$(!#(B

2005.04.26 $B?

$B!!%(%P!&%A%'%s

$B!!0lJ}!"%H%l%s%I%^%$%/%m$N%5%]!<%H>pJs$,BgI}$K99?7$5$l$F$$$^$9!#(B

$B!!(BWindows XP SP2$B!"(BWindows Server 2003 gold / SP1 $B$O7g4Y$,9b$$3NN($GH/8=$9$k$,!"(BWindows Me $B$d(B Microsoft Office XP ($B$rEc:\$7$?(B PC) $B$G$bDc$$3NN($G$O$"$k$,H/8=$9$k!"$H$5$l$F$$$^$9!#(B 2ch.net $B$G$O!V(BWindows 2000 $B$@$1$IH/8=$7$?!W$H$$$&Js9p$,=P$F$$$?$1$I!"$3$&$$$&$3$H$@$C$?$N$+$J!#(B

$B!!$^$?!"A49qL5NA=PD%%5%]!<%H$HA49q(B CD $BG[I[$r9T$&$=$&$G$9!#(B

2005.04.27 $BDI5-(B:

2005.04.28 $BDI5-(B:

$B!!(B$B%&%$%k%9%Q%?!<%s%U%!%$%k$K4X$9$kLdBj$K$D$$$F(B ($B%H%l%s%I%^%$%/%m(B) $B$H$$$&%Z!<%8$,$G$-$F$$$^$9!#(B

2005.05.01 $BDI5-(B:

$B!!4XO"5-;v(B:

2005.06.27 $BDI5-(B:


$B"#(B 2005.04.22


$B"#(B 2005.04.21

$B"#(B Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (890923) (MS05-020)
(Microsoft, 2005.04.13)

$B!!(BIE 5.01 / 5.5 / 6 $B$K!"?7$?$J(B 3 $B$D$N7g4Y!#(B

$B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B $B$A$J$_$K=$@5%W%m%0%i%`$K$O!"%;%-%e%j%F%#=$@5$@$1$G$O$J$/!"Hs%;%-%e%j%F%#$N=$@5$b4^$^$l$F$$$k!#(B $BHs%;%-%e%j%F%#=$@5$bE,MQ$7$?$$>l9g$O!"(B897225 - Internet Explorer 6 Service Pack 1 $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`$K4^$^$l$k=$@5%W%m%0%i%`$r%$%s%9%H!<%k$9$kJ}K!(B (Microsoft) $B$K=>$C$F:n6H$9$k$3$H!#(B $B4^$^$l$F$$$kHs%;%-%e%j%F%#=$@5$N0lMw$O$3$A$i(B: 890923 - [MS05-020] Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (Microsoft)

$B"#(B $BDI5-(B

NISCC Vulnerability Advisory ICMP - 532967: Vulnerability Issues in ICMP packets with TCP payloads

$B!!(BICMP attacks against TCP (Proof-of-Concept code) (MS05-019, CISCO:20050412)

TCP/IP $B$N@H

$B!!(BWindows Malformed IP Options DoS Exploit (MS05-019)$B!#(B

$B%a%C%;!<%8(B $B%-%e!<$N@H

$B!!(BMS05-017$B!?(B892944 $B%a%C%;!<%8!&%-%e!<$N@H (@IT, 2005.04.19) $B$K$h$k$H!"(B

$B$?$@$7(BDA Lab$B$G8!>Z$7$?$H$3$m!"(BWindows XP SP1$B!?(BSP1a$B$G$O!"L@<(E*$K(BMSMQ$B$r%$%s%9%H!<%k$7$F$$$J$$>l9g$G$b!"(BWindows Update$B$G(BMSMQ$B$r9=@.$9$k%U%!%$%k$N0lIt$,8!=P$5$l!"(BMSMQ$B$r%$%s%9%H!<%k$7$F$$$J$$4D6-$G$b!"(BWindows Update$B$G(BMS05-017$B$NE,MQ$,I,MW$@$HH=Dj$5$l$k>l9g$,$"$k!#6qBNE*$J1F6A$OITL@$@$,!"$3$N>l9g$OG0$N$?$a(BMS05-017$B$rE,MQ$7$F$*$$$?J}$,0B?4$@$m$&!#(B

$B$@$=$&$G$9!#(BSugawara $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

mixi$B$K(BCSRF$B@H

$B!!F?L>4uK>$5$s$+$i(B ($B>pJs$"$j$,$H$&$4$6$$$^$9(B):

Ver.3 $B$KBP$9$kBP:v$O$$$A$*$&(Bmixi$B$G$b(B $B$N2U=j$K4X$7$F$OF1MM$N967b$,DLMQ$9$k$H$N$3$H!#(B
http://d.hatena.ne.jp/mixi_love/20050420/p6

$B$J$*!"(Bmixi $B$G$O$3$l$^$G$K2?EY$b(B CSRF $B$N@Hl$7$N$.$NBP1~$G=*$o$C$F$$$^$9!#(B

$B;d$,CN$C$F$$$k$@$1$G$b(B

2005$BG/(B2$B7n(B mixi $B$X$N>7BT5!G=$G(B CSRF
http://yamagata.int21h.jp/d/?date=20050217#p04

2005$BG/(B3$B7n(B
$B%^%$%_%/%7%#$N6/@):o=|$*$h$S%3%_%e%K%F%#$N6/@)B`2q$K4X$9$k(BCSRF$B$r(Bmixi$B$KJs9p$9$k$b!"CfESH>C<$JBP:v$N$_!#(B

2005$BG/(B4$B7n(B
$B%^%$%_%/%7%#$N%j%/%(%9%H$N6/@)Aw?.$K4X$9$k(BCSRF$B$r(B mixi$B$KJs9p$9$k$bJVEz$J$7!#(BIPA$B$XO"Mm!"
$B$H$$$&$h$&$J>u67$G$9!#(B
telnet $B%/%i%$%"%s%H$KJ#?t$N7g4Y(B

$B!!(BGentoo, Vine, Debian, Heimdal $BDI2C!#(B

Microsoft$B$N(BJet$B%G!<%?%Y!<%9%(%s%8%s$K@H

$B!!(BExploit-MSJet.gen ($B%^%+%U%#!<(B)

$B"#(B $B$$$m$$$m(B
(various)

2005.05.11 $BDI5-(B:

$B!!(BWindows 2000 $B$N(B Explorer $B$N7o$O(B MS05-024 $B$G=$@5$5$l$^$7$?!#(B


$B"#(B 2005.04.20

$B"#(B TCP/IP $B$N@H
(Microsoft, 2005.04.13)

$B!!(BWindows $B$N(B TCP/IP $B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#$J$*!"(BWindows Server 2003 SP1 $B$K$O$3$N7g4Y$O$J$$!#(B

$B!!$^$?!"(Bpatch $B$rE,MQ$9$k$H!"$=$NI{:nMQ$H$7$F(B TCP $B$N%&%$%s%I%&%5%$%:$,(B 64K $B$+$i(B 17520 $B%P%$%H$K8:>/$9$k$N$GCm0U!#;2>H(B: 890345 - $B%;%-%e%j%F%#99?7%W%m%0%i%`(B 893066 $B$O(B Windows 2000 $B$G(B TCP $B (Microsoft)$B!#%l%8%9%H%j$r$$$8$k$3$H$K$h$j!"(BSP3 $B0J9_$N%G%U%)%k%HCM$@$C$?(B 64KB $B$KLa$9$3$H$,2DG=!#(B

2005.04.21 $BDI5-(B:

$B!!(BWindows Malformed IP Options DoS Exploit (MS05-019)$B!#(B

2005.04.26 $BDI5-(B:

$B!!I{:nMQ>pJs(B:

2005.04.27 $BDI5-(B:

$B!!I{:nMQ>pJs(B:

2005.05.17 $BDI5-(B:

$B!!(BWindows (XP, 2k3, Longhorn) is vulnerable to IpV6 Land attack. (ntbugtraq)$B!#(B patch $BE,MQ8e$b!"(BIPv6 $B$K$D$$$F$O(B land $B%"%?%C%/$,M-8z$G$"$k!"$H$$$&;XE&!#(B

2005.05.20 $BDI5-(B:

$B!!(BMS05-019 patch $B$K$O!"(BVulnerability Note VU#637934: TCP does not adequately validate segments before updating timestamp value $B$KBP$9$k=$@5$b4^$^$l$F$$$k$=$&$@!#(B

$B!!$^$?(B Microsoft Security Advisory (899480) $B$K$O!"(BMS05-019 patch $B$,(B 6 $B7n$K:F%j%j!<%9$5$l$kM=Dj$G$"$k!"$H$b5-:\$5$l$F$$$k!#(B KB898060 $BLdBj$,=$@5$5$l$k$h$&$@!#(B

2005.05.26 $BDI5-(B:

$B!!(BMicrosoft Security Advisory (899480) $B$NF|K\8lHG$,=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (899480) TCP $B$N@H (Microsoft)

2005.06.15 $BDI5-(B:

$B!!2~D{HG(B patch $B$,=P$F$$$^$9!#E,MQ$7$^$;$&!#(B

2005.06.17 $BDI5-(B:

$B!!2~D{HG(B patch $B$rE,MQ$9$k$H!"(BISS $B@=IJ$N0lIt$,F0:n$rDd;_$7$F$7$^$&$=$&$G(B:

$B!!(BISS $B@=IJMQ$N(B patch $B$,=P$F$$$k$N$G!"3:Ev

$B"#(B $BEE;R?=@A(B $B9T@/%=%U%H$KIT6q9g(B
(NHK, 2005.04.20)

$BK!L3>J$H2,;3!";3M|!"BgJ,$N3F8)$,5nG/$+$i:#G/$K$+$1$FDs6!$7$?EE;R?=@AMQ$N%=%U%H$K7g4Y$,$"$k$3$H$,$o$+$j$^$7$?!#(B

$B!!$0$0$C$F$_$k$H!"$3$N$"$?$j$N$*OC$N$h$&$G$9(B:

$B!!$I$&$d$i$*OC$O(B 2 $B

$B!!(BNHK $B$NJsF;$O!"8e

2005.05.03 $BDI5-(B:

$B!!(B$BEE;R?=@A%7%9%F%`$NE@8!;X<((B (NHK, 2005.04.29)$B!#$9$G$K>C$($F$7$^$C$F$$$k(B (T_T) $B$N$G!"0J2<$KA4J80zMQ$5$;$F$$$?$@$-$^$9!#(B

$BAmL3>J$O9T@/$,7g4Y$N$"$k%=%U%H$rG[I[$7$F$$$?$3$H$OLdBj$@$H$7$F!"A49q$N<+<#BN$KBP$7!"F1$8$h$&$J7g4Y$N$"$k%=%U%H$rG[I[$7$F$$$J$$$+$I$&$+Mh7n#1#3F|$^$G$KE@8!$9$k$h$&;X<($7$^$7$?!#$^$?!"Fb3U41K<>pJs%;%-%e%j%F%#!<%;%s%?!<$G$b3F>JD#$KBP$7!"A49q$N=P@h5!4X$,;H$C$F$$$kEE;R?=@A%=%U%H$N0BA4@-$rE@8!$9$k$h$&;X<($7$^$7$?!#(B

$B!!$^$@A4$F$NBP1~$,=*$C$?$o$1$G$O$J$$!"$H$$$&$3$H$J$s$G$7$g$&$+!#(B $B$=$N3d$K$O!"$$$m$s$J<+<#BN$,>!pJs$r=P$7$F$7$^$C$F$$$F!"$J$+$J$+%"%l$J5$$,$7$^$9!#(B $B%$%s%7%G%s%HBP1~

$B!!$H$3$m$G!"(B$B%=%U%H%&%(%"Ey$N@HpJs$K4X$9$kFO=P>u67(B [2005$BG/Bh(B1$B;MH>4|!J(B1$B7n!A(B3$B7n!K(B] (IPA ISEC) $B$K$3$s$JJ8>O$,$"$k$N$G$9$,!"(B

2005$BG/Bh(B1$B;MH>4|$NFO=P;vNc$H$7$F!"(BJava$B%"%W%j%1!<%7%g%s!J(BJava$B%"%W%l%C%H!K$N%$%s%9%H!<%k%W%m%0%i%`Ey$,%$%s%9%H!<%k;~$K%/%i%$%"%s%H(BPC$B$N(BJava$B4D6-$N%;%-%e%j%F%#%]%j%7!<$r=q49$($F$7$^$$!"7k2L$H$7$F!"%/%i%$%"%s%H(BPC$B$N%;%-%e%j%F%#%l%Y%k$rDc2<$5$;$F$7$^$&!"$H$$$&$b$N$,J#?t$"$j$^$7$?!#(B(7)
$BCfN,(B
(7) $B$3$l$i$O!"%/%i%$%"%s%H(BPC$B$K%$%s%9%H!<%k$9$k%=%U%H%&%(%"$G$9$,!"%&%'%V%"%W%j%1!<%7%g%s$r;H$&$?$a$N$b$N$G$"$j!"$=$N%&%'%V%"%W%j%1!<%7%g%s$HFHN)$7$F5/F0$5$l!";HMQ$5$l$k$b$N$G$O$J$$$?$a!"%&%'%V%"%W%j%1!<%7%g%s$N0lIt$H$7$FB*$(!"%&%'%V%"%W%j%1!<%7%g%s$N@HpJs$NFO=P$H$7$F

$B%;%-%e%j%F%#LdBj$N>\:Y@bL@(B ($B$d$^$J$7?=@A!&M=Ls%]!<%?%k%5%$%H(B) $B$K(B

$B!!(B2005$BG/(B2$B7n(B16$BF|$N(B10$B;~(B33$BJ,$K!"(BIPA$B!JFHN)9T@/K!?M>pJs=hM}?d?J5!9=!K$N%;%-%e%j%F%#%;%s%?$+$i!"(Be-$B$d$^$J$7%5%]!<%H%;%s%?08$K!V$d$^$J$7?=@A!&M=Ls%]!<%?%k%5%$%H!W$N!V$*;H$$$N(BPC$B$N@_Dj!W(B-$B!V%f!<%6@_Dj%U%!%$%k!W$G%U%!%$%k$NAH$_9~$_$r9T$C$?>l9g!"%;%-%e%j%F%#>e$NLdBj$,@8$8$k2DG=@-$,$"$k$H$$$&$4;XE&$rD:$-$^$7$?!#(B
($BCfN,(B)
$B%;%-%e%j%F%#LdBj(B
$B!!EE;R?=@A%5!<%S%9$NEE;R=pL>$r9T$&>l9g$K$O!"$*;H$$$N%Q%=%3%s>e$K$"$k;q8;!J=pL>$KI,MW$J%U%!%$%kEy!K$NMxMQ$r9T$&$?$a$K!"%f!<%6@_Dj%U%!%$%k$NAH$_9~$_$r9T$C$F$$$?$@$$$F$$$^$9!#(B
$B!!$=$N%f!<%6@_Dj%U%!%$%k$N(B1$B$D$H$7$F!"!V(Bjava.policy$B!W%U%!%$%k$NAH$_9~$_$r9T$C$F$$$?$@$$$F$$$^$9$,!"(B2005$BG/(B2$B7n(B16$BF|0JA0$N!V(Bjava.policy$B!W%U%!%$%k$N5-=RFbMF$K8m$j$,$"$j$^$7$?!#(B
$B!!(B2005$BG/(B2$B7n(B16$BF|0JA0$K%f!<%6@_Dj%U%!%$%k$NAH$_9~$_$r9T$C$?%Q%=%3%s$G!"0-0U$N$"$k%5%$%H$rK,$l$?>l9g$K!"%f!<%6L>!"%m!<%+%k%U%!%$%k$NEp$_=P$7!&GK2u!"G$0U%3!<%I$N

$B$H$"$k$N$G!"$3$l$,$=$NOC$J$s$8$c$J$$$N$+$J!<$H$$$&5$$,$7$^$9!#(B

$B!!$7$+$7$3$NOC$N>l9g!"1F6AHO0O$,Ev3:(B web $B%5%$%H$K8B$i$l$k$o$1$G$O$J$$$N$G$9$+$i!"!V%&%'%V%"%W%j%1!<%7%g%s$N@HpJs$NFO=P$H$7$F

$B"#(B Windows Kernel $B$N@H:3J$*$h$S%5!<%S%95qH]$,$*$3$k(B (890859) (MS05-018)
(Microsoft, 2005.04.13)

$B!!(BWindows 2000 / XP / Server 2003 $B$K7g4Y!#(B Windows Kernel $B$K(B 4 $B$D$N7g4Y$,$"$k!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

2005.04.27 $BDI5-(B:

$B!!$=$&$$$($P!"IT6q9g>pJs$,$"$C$?$N$G$7$?!#(B

2005.05.27 $BDI5-(B:

$B!!(BYou receive a "STOP 0x0000001E" error after you install security update MS05-018 on a Windows 2000-based computer (Microsoft)$B!#%5%]!<%H7PM3$G(B hotfix $B$rF~

$B"#(B Mac OS X 10.3.9 Update $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B
(Apple, 2005.04.12)

$B!!(BMac OS X 10.3.9 Update $B$K$OJ#?t$N%;%-%e%j%F%#=$@5$,4^$^$l$F$$$k!"$H$$$&OC!#(B

$B!!(BMac OS X 10.3.x $BMxMQ

$B$J$*!"(BMac OS X 10.3.9 $B$r%$%s%9%H!<%k$9$k$H!"(BJava $B$,$&$^$/F0$+$J$/$J$k;vNc$,H/@8$7$F$$$kLOMM!#3:Ev$9$k>l9g$O(B Java and Safari issues after updating to Mac OS X v10.3.9 (Apple) $B$r;2>H$7$FBP1~$5$l$?$$!#(B Java Update 1.4.2 Update 2 $B$*$h$S(B / $B$^$?$O(B Security Update 2005-002 $B$NE,MQ$K$h$j2r7h$9$kLOMM!#(B

$B"#(B $B%a%C%;!<%8(B $B%-%e!<$N@H
(Microsoft, 2005.04.14)

$B!!(BWindows 2000$B!"(BWindows XP SP1 $B$K7g4Y!#(B Microsoft Message Queuing ($B%G%U%)%k%H$G$O%$%s%9%H!<%k$5$l$F$$$J$$(B) $B$K(B buffer overflow $B$9$k7g4Y$,$"$j!"(Bremote $B$+$iG$0U$N%3!<%I$r(B local SYSTEM $B8"8B$G

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B!!4XO"(B:

2005.04.21 $BDI5-(B:

$B!!(BMS05-017$B!?(B892944 $B%a%C%;!<%8!&%-%e!<$N@H (@IT, 2005.04.19) $B$K$h$k$H!"(B

$B$?$@$7(BDA Lab$B$G8!>Z$7$?$H$3$m!"(BWindows XP SP1$B!?(BSP1a$B$G$O!"L@<(E*$K(BMSMQ$B$r%$%s%9%H!<%k$7$F$$$J$$>l9g$G$b!"(BWindows Update$B$G(BMSMQ$B$r9=@.$9$k%U%!%$%k$N0lIt$,8!=P$5$l!"(BMSMQ$B$r%$%s%9%H!<%k$7$F$$$J$$4D6-$G$b!"(BWindows Update$B$G(BMS05-017$B$NE,MQ$,I,MW$@$HH=Dj$5$l$k>l9g$,$"$k!#6qBNE*$J1F6A$OITL@$@$,!"$3$N>l9g$OG0$N$?$a(BMS05-017$B$rE,MQ$7$F$*$$$?J}$,0B?4$@$m$&!#(B

$B$@$=$&$G$9!#(BSugawara $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B mixi$B$K(BCSRF$B@H
(interrupted train, 2005.04.20)

$B!!%=!<%7%c%k%M%C%H%o!<%/(B mixi $B$K(B Cross-Site Request Forgeries (CSRF; $B%/%m%9%5%$%H!&%j%/%(%9%H56B$(B) $B7g4Y$,$"$C$?LOMM!#(B $BNX2&$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B $B8=:_$O!V$O$^$A$A$c$s(B ver 3.0$B!W$r4^$aBP1~$5$l$F$$$k$h$&$G$9!#(B

$B!!(B$B%=%U%H%&%(%"Ey$N@HpJs$K4X$9$kFO=P>u67(B [2005$BG/Bh(B1$B;MH>4|!J(B1$B7n!A(B3$B7n!K(B] (IPA ISEC) $B$K!V%/%m%9!&%5%$%H!&%j%/%(%9%H!&%U%)!<%8%'%j!W$H$$$&8@MU$,=P$F$$$F!"8D?ME*$K$O!V$=$l$O2?(B?$B!W>uBV$@$C$?$N$G$9$,!"$3$&$$$&$b$N$@$=$&$G$9(B:

$B!!@$$NCf$$$m$$$m$"$k$s$G$9$M!#(B

2005.04.21 $BDI5-(B:

$B!!F?L>4uK>$5$s$+$i(B ($B>pJs$"$j$,$H$&$4$6$$$^$9(B):

Ver.3 $B$KBP$9$kBP:v$O$$$A$*$&(Bmixi$B$G$b(B $B$N2U=j$K4X$7$F$OF1MM$N967b$,DLMQ$9$k$H$N$3$H!#(B
http://d.hatena.ne.jp/mixi_love/20050420/p6

$B$J$*!"(Bmixi $B$G$O$3$l$^$G$K2?EY$b(B CSRF $B$N@Hl$7$N$.$NBP1~$G=*$o$C$F$$$^$9!#(B

$B;d$,CN$C$F$$$k$@$1$G$b(B

2005$BG/(B2$B7n(B mixi $B$X$N>7BT5!G=$G(B CSRF
http://yamagata.int21h.jp/d/?date=20050217#p04

2005$BG/(B3$B7n(B
$B%^%$%_%/%7%#$N6/@):o=|$*$h$S%3%_%e%K%F%#$N6/@)B`2q$K4X$9$k(BCSRF$B$r(Bmixi$B$KJs9p$9$k$b!"CfESH>C<$JBP:v$N$_!#(B

2005$BG/(B4$B7n(B
$B%^%$%_%/%7%#$N%j%/%(%9%H$N6/@)Aw?.$K4X$9$k(BCSRF$B$r(B mixi$B$KJs9p$9$k$bJVEz$J$7!#(BIPA$B$XO"Mm!"
$B$H$$$&$h$&$J>u67$G$9!#(B

2005.04.25 $BDI5-(B:

$B!!(B$BBgNL$N!V$O$^$A$A$c$s!W$r@8$_=P$7$?(BCSRF$B$N@H (ITmedia, 2005.04.23)

2005.04.27 $BDI5-(B:

$B!!(B$B!V$\$/$O$^$A$A$c$s!W(B $B!=!=CN$i$l$6$k(BCSRF$B967b(B (@IT, 2005.04.27)

2005.05.01 $BDI5-(B:

$B!!(B$B%/%m%9%5%$%H%j%/%(%9%H%U%)!<%8%'%j!J(BCSRF$B!K$N@5$7$$BP:vJ}K!(B ($B9bLZ9@8w!w<+Bp$NF|5-(B, 2005.04.27)

$B"#(B RealNetworks, Inc.$B!"%;%-%e%j%F%#@H
(RealNetworks, 2005.04.19)

$B!!(BRealPlayer$B!"(BRealOne Player$B!"(BRealPlayer Enterprise$B!"(BHelix Player $B$K7g4Y!#(BRam $B%U%!%$%k(B $B$N=hM}$K$*$$$F(B buffer overflow $B$,H/@8!"96N,(B Ram $B%U%!%$%k$K$h$jG$0U$N%3!<%I$r

$B!!(BRealPlayer 10 $B7ONs$H(B Linux $BMQ$N(B Helix Player 10 $B$*$h$S(B Realplayer Enterprise $B$K$D$$$F$O=$@5%W%m%0%i%`$,MQ0U$5$l$F$$$k!#(B RealOne Player $B$d(B RealPlayer 8 $B$K$D$$$F$O!":G?7$N(B RealPlayer 10 $B7ONs$X$N%"%C%W%0%l!<%I$,I,MW$H$J$k!#>\:Y$O(B RealNetworks $B$K$h$kJ8=q(B$B$r;2>H$5$l$?$$!#(B

$B!!4XO"(B: RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Overflow$B!#(B

$B"#(B $BDI5-(B

2005 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BWindows Update$B ($B%^%+%U%#!<(B, 2005.04.15)$B!#(BVirusScan for Client 4.5.1 SP1 $B$H(B Windows Installer 3.1 $B$,7v2^$r$9$k$=$&$G$9!#(BVirusScan Enterprise $B$X%"%C%W%0%l!<%I$9$l$P2r7h$9$k$=$&$G$9!#(B


$B"#(B 2005.04.19

$B"#(B $BDI5-(B

OLE $B$*$h$S(B COM $B$N@H

$B!!(B896648 - $B%;%-%e%j%F%#99?7%W%m%0%i%`(B 873333 $B!J(BMS05-012$B!K(B $B$N%$%s%9%H!<%k8e(B svchost.exe $B%(%i!<$,H/@8$9$k$3$H$,$"$j$^$9(B (Microsoft) $B$,99?7$5$l$^$7$?!#(B 895200 - Availability of Windows XP COM+ Hotfix Rollup Package 9 (Microsoft) $B$rE,MQ$9$k$3$H$G2r7h$9$k$=$&$G$9!#%U%m!<%H$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

iDEFENSE Security Advisory 03.31.05: PHP getimagesize() Multiple Denial of Service Vulnerabilities

$B!!(B[SECURITY] [DSA 708-1] New PHP3 packages fix denial of service$B!#(BDebian $B$5$9$,$G$9!#$$$^$@$K(B PHP3 $B$,%a%s%F%J%s%9$5$l$F$$$^$9!#(B

Critical Patch Update - April 2005

$B"#(B [Full-disclosure] iDEFENSE Security Advisory 04.18.05: McAfee Internet Security Suite 2005 Insecure File Permission Vulnerability
(iDEFENSE, Tue, 19 Apr 2005 07:08:20 +0900)

$B!!(B$B%^%+%U%#!<(B $B%$%s%?!<%M%C%H%;%-%e%j%F%#%9%$!<%H(B 2005 $B$K7g4Y!#(B $B%$%s%9%H!<%k$5$l$?>uBV$K$*$1$k!"%^%+%U%#!<(B $B%$%s%?!<%M%C%H%;%-%e%j%F%#%9%$!<%H(B 2005 $B$N%U%!%$%k$N%Q!<%_%C%7%g%s$K7g4Y$,$"$j!"4IM}

$B!!%^%+%U%#!<(B $B%$%s%?!<%M%C%H%;%-%e%j%F%#%9%$!<%H(B 2005 $B$N<+F099?75!G=$K$*$$$F=$@5$5$l$F$$$k$=$&$@!#$,!"F|K\$G$b$=$&$J$N$+$O$$$^$$$AITL@!#(B

$B!!(BCVE: CAN-2005-1107

2005.04.19 $BDI5-(B:

$B!!@DLZ$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B)

$B$3$l$G$9$,!"(BTrendMicro VirusBuster $B$b;w$?$h$&$J$b$N$N$h$&$K;W$($^$9!#(B

$B0J2<$O%P%9%?!<(B 2004 $B$NOC$G$9$,(B 2005 $B$bF1MM$@$C$?$h$&$J!#(B

C:\Program Files\Trend Micro\Virus Buster 2004
$B$3$l0J2<$N%U%!%$%k!"%U%)%k%@$O(B Everyone: Full $B$K$J$C$F$$$^$9!#$=$3$K$O(B Tmntsrv.exe, tmproxy.exe $B$,$"$j$^$9$,!"$=$l$i$O(B LocalSystem $B$K$FF0$/%5!<%S%9$G$9!#$^$?$3$l$i$N%5!<%S%9$O!"@)8B%f!<%6!<$GDd;_!"3+;O$,2DG=$K@_Dj$5$l$F$$$^$9!#(B

$B$=$&$7$J$$$H4IM}8"8B$N$J$$%f!<%6!<$,%m%0%*%s$7$F$$$k$H$-$K%Q%?!<%s%U%!%$%kEy$N%"%C%W%G!<%H$,=PMh$J$$$?$a!"$=$N$h$&$J!V;EMM!W$K$J$C$F$$$k$N$G$O$J$$$+$H;W$o$l$^$9!#(B

$B!!

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B FreeBSD-SA-05:04.ifconf - Kernel memory disclosure in ifconf()
(FreeBSD-announce-jp, 2005.04.15)

$B!!(BFreeBSD 4.x / 5.x $B$K7g4Y!#(BSIOCGIFCONF ioctl $B$K$*$$$F%P%C%U%!$,=i4|2=$5$l$J$$$^$^;HMQ$5$l$F$7$^$&$?$a!"%+!<%M%k%a%b%j$NFbMF(B (12 $B%P%$%H(B) $B$,O31H$7$F$7$^$&!#(B

$B!!:G?7$N(B RELENG_4 / RELENG_4_10 / RELENG_4_11 / RELENG_5 / RELENG_5_3 / RELENG_5_4 $B$K99?7$9$k$+!"$"$k$$$O(B FreeBSD 4.x / 5.3 $BMQ$N(B patch $B$rE,MQ$7!"(Bkernel $B$r:F9=C[$7$F%$%s%9%H!<%k$7!":F5/F0$9$k!#(B RELENG_4_8 $B$O$b$O$d0];}$5$l$F$$$J$$$,!"(BFreeBSD 4.x $BMQ(B patch $B$OE,MQ$G$-$?!#(B

$B!!$&$%!"$^$?%+!<%M%k$D$/$j$J$*$7$G$9$+!D!D(B (T_T)

$B"#(B Stable CVS Version 1.11.20 Released! * Security Update *
(cvshome.org, 2005.04.18)

$B!!(BCVS 1.11.19 / 1.12.11 $B0JA0$KJ#?t$N7g4Y!#(BNEWS $B$K$h$k$H!"(BCVS $BK\BN$K(B buffer overflow $B$d(B memory leak $B$J$IJ#?t$N7g4Y$,$"$j!"(B $B4sB#$5$l$?J#?t$N(B perl $B%9%/%j%W%H$K$b7g4Y$,$"$C$?(B$B$H$$$&!#(B buffer overflow $B$K$D$$$F$O(B CAN-2005-0753 $B$H$7$FEPO?$5$l$F$$$k!#(BCVS $B3+H/

$B!!(BCVS 1.11.20 $B$*$h$S(B 1.12.12 $B$G=$@5$5$l$F$$$k!#$?$@$7!"(Bperl $B%9%/%j%W%H$N7g4Y$O40A4$K$O2r>C$5$l$F$$$J$$$=$&$@!#(B

fix / patch:

$B"#(B 2005.04.18

$B"#(B Windows $B%7%'%k$N@H
(Microsoft, 2005.04.13)

$B!!(BWindows 2000 / XP / Server 2003 $B$K7g4Y!#(B MS Office $BJ8=q$O!"3HD%;R$rJQ99$7$F$b(B MS Office $BJ8=q$H$7$F3+$+$l$k$3$H$O$h$/CN$i$l$F$$$k!#$3$l$HF1$85!9=$rMxMQ$9$k$3$H$G!"G$0U$N3HD%;R$N$D$$$?%U%!%$%k$r(B Microsoft HTML Application Host (MSHTA) $B%U%!%$%k$G$"$k$H$7$F

$B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#$J$*!"$3$N7g4Y$O(B Windows Server 2003 SP1 $B$*$h$S(B Windows XP / Server 2003 x64 Edition $B$K$OB8:_$7$J$$!#(B

$B!!4XO"(B:

$B"#(B $BDI5-(B

JVN#9ADCBB12: $B7HBSEEOCC

$B!!>\:Y$,8x3+$5$l$?(B: au$B7HBSEEOC$N%P!<%3!<%I%j!<%@$G%8%c%s%W@h(BURL$B$,56Au$5$l$k(B (bugtraq-jp)

$B"#(B VULNERABILITY OF FIRST-GENERATION DIGITAL CERTIFICATES Rev 1.1 AND POTENTIAL FOR PHISHING ATTACKS AND CONSUMER FRAUD
(GeoTrust, 2005.04.12)

$B!!$H$s$G$b$J$$4*0c$$$r$7$F$$$?$N$G=$@5!#@>B<$5$s$4;XE&$"$j$,$H$&$4$6$$$^$9!#(B _o_

$B!!(BSSL $B%5!<%P>ZL@=q$K$*$$$F!"(BOrganization $B9`L\(B$B$,:>>N$5$l$?$b$N$rC/$G$b4JC1$K

$B!!(BPoC $B%5%$%H$H(B Opera 8 Beta 3 $B$G$NI=<(Nc$,(B http://www.geotrust.com/resources/advisory/sslorg/index.htm $B$K<($5$l$F$$$k!#(BOpera 8 Beta 3 $B$G$O%"%I%l%9%P!<$K:>>N$5$l$?(B Organization $B9`L\$,Bg$-$/I=<($5$l$F$7$^$&$?$a!"

$B!!(BGeoTrust $B$,(B Organization $B:>>N>ZL@=q$r$I$3$+$iF~

$B"#(B $B;0$D$NCWL?E*7g4Y$r=$@5$7$?(BFirefox 1.0.3$B$H(BMozilla 1.7.7$B%j%j!<%9(B
(slashdot.jp, 2005.04.16)

$B!!(BFirefox 1.0.3 / Mozilla 1.7.7 $BEP>l!#B??t$N7g4Y(B (Firefox: 9 $B$D!"(BMozilla: 7 $B$D(B) $B$,=$@5$5$l$F$$$k!#(B

$B7g4Y(B $B=EBg@-(B $B1F6A(B $B2sHrJ}K!(B
Firefox Mozilla
MFSA 2005-33 $BCf(B $B$"$j(B $B$"$j(B JavaScript $B$rL58z$K$9$k(B
MFSA 2005-34 $BBg(B $B$"$j(B N/A Firefox $B%W%i%0%$%s%U%)%k%@$G!V(BManual Install$B!W%\%?%s$r2!$5$J$$(B
MFSA 2005-35 $BCf(B $B$"$j(B $B$"$j(B $B%V%m%C%/$7$?%]%C%W%"%C%W$O1\Mw$7$J$$(B
MFSA 2005-36 $BBg(B $B$"$j(B $B$"$j(B JavaScript $B$rL58z$K$9$k(B
MFSA 2005-37 $BFCBg(B $B$"$j(B $B$"$j(B JavaScript $B$rL58z$K$9$k(B
MFSA 2005-38 $BCf(B $B$"$j(B $B$"$j(B $B?.Mj$G$-$J$$=P<+$N8!:w%W%i%0%$%s$O%$%s%9%H!<%k$7$J$$(B
MFSA 2005-39 $BFCBg(B $B$"$j(B N/A JavaScript $B$rL58z$K$9$k(B
MFSA 2005-40 $BCf(B $B$"$j(B $B$"$j(B JavaScript $B$rL58z$K$9$k(B
MFSA 2005-41 $BFCBg(B $B$"$j(B $B$"$j(B JavaScript $B$rL58z$K$9$k(B

$B!!(BFirefox / Mozilla $BMxMQ

$B!!(B(typo fixed: $B>._7$5$s46

$B!!4XO"(B:


$B"#(B 2005.04.14

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

March 2005 DNS Poisoning Summary

$B!!(B4/12 $BDI5-J,$H$^$H$a$?!#(B

2005 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BPRIMERGY FT $B%b%G%k(B: Windows Update$B$K4X$9$kN10U;v9`(B ($BIY;NDL(B)$B!#(B PRIMERGY TX200FT $B$X$N(B MS05-018 $BE,MQ$GLdBj$,H/@8$9$k$h$&$G!"!V6[5^=$@5%W%m%0%i%`!W$,8x3+$5$l$F$$$^$9!#(B$B%;%-%e%j%F%#99?7%W%m%0%i%`(B (890859) (MS05-018) $BE,MQ$K4X$9$kN10U;v9`(B ($BIY;NDL(B) $B$b;2>H!#(B(typo fixed: Shibuya $B$5$s46

$B"#(B OpenOffice.org1.1.4$B%R!<%W!&%*!<%P!<%U%m!<$N@H
(OOoWiki, 2005.04.14)

$B!!(BOpenOffice.org 1.1.4 $B0JA0$K7g4Y!#(B StgCompObjStream::Load() $B$K(B heap overflow $B$9$k7g4Y$,$"$j!"(B $B96N,J8=q%U%!%$%k$r3+$+$;$k$3$H$K$h$jG$0U$N%3!<%I$rIssue 46388 (openoffice.org) $B$r;2>H!#(B

$B!!(BOpenOffice.org 1.1.4 $BMxMQl9g$O!"$^$:(B 1.1.4 $B$^$G>e$2!":9BX%U%!%$%k$rE,MQ$9$k!#(B

$B"#(B 890830 - The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Server 2003, Windows XP, or Windows 2000
(Microsoft, 2005.04.13)

$B!!!V0-0U$N$"$k%=%U%H%&%'%"$N:o=|%D!<%k!W(BV 1.3 (April 2005) $B$,EP>l$7$F$$$^$9!#(B V 1.3 $B$G$OCxL>$J(B Windows $BMQ%k!<%H%-%C%H$N$R$H$D(B HackerDefender $B$KBP1~$7$F$$$^$9!#(B HackerDefender 1.0.0 $B$G;n$7$F$_$?$H$3$m!"8!=P!&:o=|$5$l$k$N$O!V5/F0$5$l$F$$$?(B HackerDefender$B!W$@$1$N$h$&$G$9!#(B HackerDefender $B$r5/F0$;$:$KC1$KCV$$$F$*$/$H!":o=|$I$3$m$+8!=P$9$i$5$l$^$;$s$G$7$?!#(B

$B!!$D$$$G$K(B F-Secure BlackLight $B$G(B HackerDefender 1.00 $B$r;n$7$F$_$?$H$3$m!"5/F0$5$l$F$$$?$j1#$5$l$F$$$?$j$7$?%W%m%;%9!&%U%!%$%k$N>pJs$rI=<($9$k$N$_$G$7$?!#!V0-0U$N$"$k%=%U%H%&%'%"$N:o=|%D!<%k!W$O!"$H$j$"$($::o=|$7$F$/$l$k$H$$$&0UL#$G$O$o$+$j$d$9$=$&$G$9!#(B HackerDefender$B$r0-MQ$7$?%9%Q%$%&%'%"(B $B!](B $B%9%Q%$%&%'%"=|5n%"%W%j%1!<%7%g%s$,;H$($J$$(B ($B%"%@%k%H%5%$%HHo32BP:v$NIt20(B) $B$b!"!V0-0U$N$"$k%=%U%H%&%'%"$N:o=|%D!<%k!W$rMxMQ$9$k7A$K99?7$9$k$H$$$$$+$b$7$l$^$;$s!#(B

$B!!$H$$$&$o$1$G!"!V0-0U$N$"$k%=%U%H%&%'%"$N:o=|%D!<%k!W$O!V%"%s%A%&%$%k%9$rF3F~$7$F$$$k?M$b$<$R

$B!!$J$*!"(BHackerDefender $B$NA\:w!&>C5n$K4X$7$F(B Strider GhostBuster Rootkit Detection (Microsoft Research) $B$N5;=Q$,;H$o$l$F$$$k$N$+$I$&$+$K$D$$$F$O$h$/$o$+$j$^$;$s!#(B

$B"#(B JVN#9ADCBB12: $B7HBSEEOCC
(JVN, 2005.04.14)

$B!!(Bau $B$N7HBSEEOC(B PENCK$B!"(BW31SA$B!"(BW21CA$B!"(BW21T$B!"(BW22H$B!"(BW22SA$B!"(BW21SA$B!"(BW21S$B!"(BTalby$B!"(BA5509T$B!"(BA5507SA$B!"(BA5506T$B!"(BA5505SA$B!"(BA5502K$B!"(BA1404S$B!"(BA1402S II$B!"(BA1402S $B$KEc:\$5$l$F$$$k(B $B%P!<%3!<%I%j!<%@%"%W%j$K7g4Y!#(B $BFCDj$N(B QR $B%3!<%I$rFI$_9~$s$@>l9g$K!"!V(B1 $B9TL\!W$K%+!<%=%k$,$"$k$K$b$+$+$o$i$:!V(B2 $B9TL\!W$N(B URL $B$K%"%/%;%9$7$F$7$^$&!#(B $B%P!<%3!<%I(B (2$B (au, 2005.04.14) $B$K>\:Y$,$"$k$N$G;2>H$5$l$?$$!#(B

$B!!=$@5HG$N%P!<%3!<%I%j!<%@%"%W%j$,MQ0U$5$l$F$$$k$N$G99?7$9$l$P$h$$!#(B

2005.04.18 $BDI5-(B:

$B!!>\:Y$,8x3+$5$l$?(B: au$B7HBSEEOC$N%P!<%3!<%I%j!<%@$G%8%c%s%W@h(BURL$B$,56Au$5$l$k(B (bugtraq-jp)

$B"#(B EZ$BHV9f(B ($B%5%V%9%/%i%$%P(B ID) $B$NDLCN@_Dj5!G=DI2C$K$D$$$F(B
(au, 2005.04.04)

$B!!K\F|(B 2005.04.14 $B$+$i!"!X(BEZweb$B%"%/%;%9;~$K(BEZ$BHV9f$r!VDLCN$7$J$$!W@_Dj$rA*Br$G$-$k5!G=!Y$,DI2C$5$l$k$=$&$G$9!#9bLZ@h@8$,2?G/$bA0$+$i$=$N4m81@-$K$D$$$F;XE&$7$F$-$?$o$1$G$9$,!"(B$B%o%s%/%j%C%/:>5=(B$B$K$5$s$6$s0-MQ$5$l$k$h$&$K$J$C$F!"$h$&$d$/!D!D$J$o$1$G$9$M!#(B


$B"#(B 2005.04.13

$B"#(B Critical Patch Update - April 2005
(oracle, 2005.04.12)

$B!!=P$?$h$&$G$9!#(B $BF|K\$N(B Oracle $B$K$O(B 2005.04.15 $B$K>pJs$,7G:\$5$l$k$h$&$G$9!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2005.04.14 $BDI5-(B:

$B!!(B[VulnWatch] Multiple High Risk flaws fixed in Oracle (NGSSoftware)

2005.04.19 $BDI5-(B:

$B"#(B NISCC Vulnerability Advisory ICMP - 532967: Vulnerability Issues in ICMP packets with TCP payloads
(UNIRAS, 2005.04.13)

$B!!(BICMP $B$r;H$&$H!"4{B8$N(B TCP $B%3%M%/%7%g%s$r%j%;%C%H$7$?$jB.EY$rDc2<$5$;$?$j$9$k$3$H$,2DG=$@$H$$$&;XE&!#(B

$B!!F1MM$N967b$O(B IPv6 (ICMPv6) $B$K$*$$$F$b

$B!!4XO"(B:

fix / patch:

2005.04.21 $BDI5-(B:

$B!!(BICMP attacks against TCP (Proof-of-Concept code) (MS05-019, CISCO:20050412)

2005.05.06 $BDI5-(B:

$B!!(BSYM05-008: $B%7%^%s%F%C%/$N%;%-%e%j%F%#!&%2!<%H%&%'%$(B ICMP $B$K%5!<%S%95qH]$N4m81@-(B ($B%7%^%s%F%C%/(B, 2005.05.02)$B!#(B $B0J2<$N%7%^%s%F%C%/@=IJ$K7g4Y$,$"$k$=$&$@!#(B

Symantec Gateway Security 5400 Series, v2.x
Symantec Gateway Security 5300 Series, v1.0
Symantec Enterprise Firewall, v7.0.x $B!J(BWindows $BHG$*$h$S(B Solaris $BHG!K(B
Symantec Enterprise Firewall v8.0 $B!J(BWindows $BHG$*$h$S(B Solaris $BHG!K(B
Symantec VelociRaptor, Model 1100/1200/1300 v1.5
Symantec Gateway Security 300 Series $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Symantec Gateway Security 400 Series $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Symantec Firewall/VPN Appliance 100/200/200R $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Nexland ISB SOHO Firewall Appliances $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Nexland Pro Series Firewall Appliances

$B!!$3$N$&$A=$@5HG$,$"$k$N$O(B Symantec Gateway Security 300 Series$B!"(BSymantec Gateway Security 400 Series $B$@$1$G!"B>$K$D$$$F$O3+H/Cf$@$=$&$@!#(B

2005.05.20 $BDI5-(B:

$B!!(B$B!V(BTCP$B ($BF|N)(B)

$B"#(B $BDI5-(B

$B%i%$%;%s%9(B $B%m%0(B $B%5!<%S%9$N@H

$B!!(B$BF|K\8lHG(B MS05-010 $B$O99?7$5$l$F$$$J$$$h$&$@$,!"(B $B1Q8lHG(B MS05-010 $B$O(B 2 $BEY99?7$5$l$F$$$k!#$3$N$"$?$j(B:

Mitigating Factors for License Logging Service Vulnerability - CAN-2005-0050:
($BCfN,(B)
On Windows 2000 Server Service Pack 4 and Windows Server 2003, only authenticated users or programs can establish a connection to the License Logging service. However, this does not apply to installations of Windows 2000 Server where Service Pack 4 has been `slipstreamed' into the operating system directory. For more information, see Microsoft Knowledge Base Article 896658.
PNG $B=hM}$N@H

$B!!(BMS05-009 $B$,(B 2005.04.13 $BIU$G99?7$5$l$F$$$k!#(B

$B$J$<%^%$%/%m%=%U%H$O$3$N%;%-%e%j%F%#>pJs$r(B2005$BG/(B4$B7n(B13$BF|$K99?7$7$?$N$G$9$+(B?

$B$3$N%;%-%e%j%F%#>pJs$N%j%j!<%98e!"(BWindows Messenger version 4.7.0.2009 (Windows XP Service Pack 1 $B$Gl9g(B) $B$N99?7$,(B SMS $B$^$?$O<+F099?7$r2p$7G[I[$5$l$?>l9g!"%$%s%9%H!<%k$,<:GT$9$k$3$H$,3NG'$5$l$^$7$?!#(B $B99?7$5$l$?%Q%C%1!<%8$O$3$NF0:n$r=$@5$7$^$9!#(B

$BA02s$N99?7$,@5>o$K%$%s%9%H!<%k$5$l!"8=:_(B Windows Messenger $B$N%P!<%8%g%s(B 4.7.0.2010$B$r
$B%+!<%=%k$*$h$S%"%$%3%s$N%U%)!<%^%C%H$N=hM}$N@H

$B!!(BMS05-002 $B$N(B Windows 98 / 98 SE / Me $BMQ(B patch $B$,99?7$5$l$^$7$?!#(B

2005 $BG/(B 4 $B7n(B 13 $BF|$K$3$N%;%-%e%j%F%#>pJs$r99?7$7$?$N$O$J$<$G$9$+(B?

$B%;%-%e%j%F%#>pJs(B MS05-002 $B$r%j%j!<%98e!"%^%$%/%m%=%U%H$O(B Windows 98$B!"(B98SE $B$*$h$S(B ME $BMQ$N%;%-%e%j%F%#99?7%W%m%0%i%`$rE83+$7$?$*5RMM$K1F6A$rM?$($kLdBj$r3NG'$7$^$7$?!#$[$H$s$I$N>l9g$O$3$NLdBj$K$h$j!"%3%s%T%e!<%?!<$,M=4|$7$J$$$H$-$K:F5/F0$7$^$9!#(B

$B%^%$%/%m%=%U%H$O$3$NLdBj$rD4::$7!"$3$l$i$N%W%i%C%H%U%)!<%`MQ$N2~D{HG$N%;%-%e%j%F%#99?7%W%m%0%i%`$rMQ0U$7$^$7$?!#$3$l$i$N2~D{HG$N%;%-%e%j%F%#99?7%W%m%0%i%`$O!"(BWindows Update $B$*$h$S%^%$%/%m%=%U%H(B $B%@%&%s%m!<%I(B $B%;%s%?!<$+$iF~
$B4{$K%*%j%8%J%k$N%P!<%8%g%s$N(B Windows 98$B!"(B98SE $B$*$h$S(B ME $BMQ$N%;%-%e%j%F%#99?7%W%m%0%i%`$rE,MQ$7$?$*5RMM$b!"(BWindows Update $B$+$i8=:_$N2~D{HG$N99?7%W%m%0%i%`$r%$%s%9%H!<%k$9$k$3$H$r?d>)$7$^$9!#(B

$B!!$J$*!"(B$B%^%$%/%m%=%U%H!'!V(BWindows$BMQ%Q%C%A$K@H (CNET, 2005.04.01) $B$@$,!"(BMicrosoft $B$,G'<1$7$F$$$?$N$O$"$/$^$G!V5l(B patch $B$rE,MQ$9$k$H(B OS $B$,IT0BDj$K$J$k!W;v$G$"$C$F!"!V(BMS05-002 $B5l(B patch $B$,%;%-%e%j%F%#E*$KIT==J,!W$H$$$&;v

$B"#(B 2005 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2005.04.13)

$B!!=P$^$7$?!#(BMS05-016 $B$+$i(B MS05-023 $B$^$G$N(B 8 $B$D$G$9!#(B $B$U$D$&$N$R$H$O!"$3$s$J

$B!!$J$*!"(BOS Kernel $B$OJQ$o$C$F$k(B$B$o!"(BTCP/IP $B%W%m%H%3%k%9%?%C%/$OJQ$o$C$F$k(B$B$o!"(BIE $B$OJQ$o$C$F$k(B$B$o$J$N$G!"$$$D$b$h$jCm0U?<$/%F%9%H$7$^$7$g$&!#(B $B%G%U%)%k%H$N5sF0$,JQ99$K$J$kOC$b$"$k$h$&$G$9!#(B KB 893066 $B$H$+!#(B

$B!!$3$l$K$"$o$;$F!"!V(BMicrosoft Windows $B%$%s%9%H!<%i(B 3.1$B!W$H!V%P%C%/%0%i%&%s%I(B $B%$%s%F%j%8%'%s%HE>Aw%5!<%S%9(B (BITS) 2.0 $B$*$h$S(B WinHTTP 5.1 $BMQ$N99?7%W%m%0%i%`!W$b8x3+$5$l$F$$$k$h$&$G$9$M!#(B

$B!!$J$*!";DG0$J$,$i:#2s$N(B patch $B$G$O(B Upcoming Advisories (eEye) $B$N(B EEYEB-20050316 $B$H(B EEYEB-20050329 $B$O>C$($F$$$^$;$s!#(B

2005.04.14 $BDI5-(B:

$B!!IT6q9g>pJs$,=P$F$-$F$$$^$9!#(B

2005.04.20 $BDI5-(B:

$B!!(BWindows Update$B ($B%^%+%U%#!<(B, 2005.04.15)$B!#(BVirusScan for Client 4.5.1 SP1 $B$H(B Windows Installer 3.1 $B$,7v2^$r$9$k$=$&$G$9!#(BVirusScan Enterprise $B$X%"%C%W%0%l!<%I$9$l$P2r7h$9$k$=$&$G$9!#(B

2005.04.27 $BDI5-(B:

$B!!(BWindows $B%$%s%9%H!<%i(B 3.1 $B$r%$%s%9%H!<%k$9$k$H!"=$@5%W%m%0%i%`$K$h$C$F$OE,MQ$K<:GT$9$k2DG=@-$,$"$k(B (updatecorp.co.jp)$B!#(B

Windows $B%$%s%9%H!<%i$N8F$S=P$7;~$K40A4%5%$%l%s%H(B $B%$%s%9%H!<%k$N$?$a$N%*%W%7%g%s$r;XDj$9$k$H!"E,MQ$K<:GT$7$^$9!#(B

$B!!(B4 $B7n$N(B Windows Update $B$NF|$K(B Windows $B%$%s%9%H!<%i(B 3.1 $B$bG[I[$5$l$F$$$^$9$,!"8_49@-$K>/!9Fq$,$"$k$h$&$G$9!#(B

2005.05.19 $BDI5-(B:

$B!!(BWindows $B%$%s%9%H!<%i(B 3.1(v2) $B$H!"(BWindows 2003 SP1 $B$*$h$S(B 64bit $BHG(B Windows XP $BMQ$N(B Windows $B%$%s%9%H!<%i(B 3.1 $B%"%C%W%G!<%H$,8x3+$5$l$F$$$^$9!#(B


$B"#(B 2005.04.12

$B"#(B Microsoft$B$N(BJet$B%G!<%?%Y!<%9%(%s%8%s$K@H
(Internet Watch, 20005.04.12)

$B!!$3$NOC(B:

2005.04.21 $BDI5-(B:

$B!!(BExploit-MSJet.gen ($B%^%+%U%#!<(B)

2005.10.04 $BDI5-(B:

$B!!(BMS Office$B$N@H (ITmedia, 2005.10.04)

$B"#(B $BDI5-(B

March 2005 DNS Poisoning Summary

$B!!(B$B!V0-!u$HBP:v!J>e!K(B ($BF|7P(B IT Pro, 4/12)


$B"#(B 2005.04.11

$B"#(B $BDI5-(B

ppBlog $B8!:w%b%8%e!<%k$K(BXSS$B$N@H

$B!!(BppBlog 1.4.0 $B$,@5<08x3+$5$l$F$$$^$9!#(B

$B"#(B SIG^2 G-TEC - AN HTTPD Server cmdIS.DLL Buffer Overflow and LogFile Arbitrary Character Injection Vulnerabilities
(SIG^2 G-TEC, 2005.04.07)

$B!!(BAN HTTP 1.42n $B0JA0$K(B 2 $B$D$N7g4Y!#(B

$B!!=$@5HG$O$^$@$J$$!#(BAN HTTP $B%[!<%`%Z!<%8(B $B$G$O(B

$B%P!<%8%g%s(B 1.42n $B$*$h$S$=$l0JA0$N$9$Y$F$N%P!<%8%g%s$N%5%s%W%k%9%/%j%W%H$K=EBg%;%-%e%j%F%#%[!<%k$,$"$j$^$9!#(B scripts $B%U%)%k%@$N(B cmdIS.dll $B$r:o=|$7$F$/$@$5$$!#(B(2005/4/7)

$B$H8F$S$+$1$F$$$k!#(B


$B"#(B 2005.04.08

$B"#(B MPSB05-02 - Workaround available for ColdFusion MX 6.1 Updater file disclosure
(Macromedia, 2005.04.07)

$B!!(BColdFusion MX 6.1 $B$N(B Updater 1 $B$K7g4Y$,$"$j!"%U%!%$%k$^$k$_$(7O$N;v>]$,H/@8$9$kLOMM!#2sHr:v$,7G:\$5$l$F$$$k!#(B

$B"#(B Critical Patch Updates and Security Alerts
(oracle, 2005.04.08)

Critical Patch Update - April 2005 (scheduled for release at noon PDT on 12 April 2005)

$B!!(BOracle $B$+$i!"(B2005.04.12 12:00 -0700 (PDT) $B$KN_@QE*(B patch $B$,8x3+$5$l$k$=$&$G$9!#(BJST $B$@$H(B 2005.04.13 04:00 $B$+$J!#(B

$B"#(B $B%^%$%/%m%=%U%H%;%-%e%j%F%#>pJs$N;vA0DLCN(B
(Microsoft, 2005.04.08)

$B!!(B4 $B7n$N(B Windows Update $B$NF|(B ($BF|K\$G$O(B 4/13) $B$K$O

$B!!$b$j$@$/$5$s$G$9$M!#(B $B$3$l$K$"$o$;$F!V0-0U$N$"$k%=%U%H%&%'%"$N:o=|%D!<%k!W$,99?7$5$l!"$5$i$K(B

Windows Update $B%5%$%H$G(B Windows $BMQ$N%;%-%e%j%F%#0J30$NM%@hEY9b$N99?7%W%m%0%i%`$r%j%j!<%9$9$kM=Dj$G$9!#$3$l$i$O(B Software Update Services $B$KG[I[$5$l$kM=Dj$G$9!#(B

$B$@$=$&$G$9!#$J$s$@$m$&!D!D!#(B


$B"#(B 2005.04.07

$B"#(B CISCO $BJ}LL(B
(CISCO, 2005.04.07)

$B"#(B $B%M%C%H$r?*$`$N$O%U%#%C%7%s%0$@$1$8$c$J$$!"(BDDoS$B967b$b!V9bEY$J$b$N$@$1$G(B1$BF|(B60$B7o!W(B
($BF|7P(B IT Pro, 2005.04.06)

$B!!(BNTT $B%3%_%e%K%1!<%7%g%s%:$,07$C$F$$$k%H%i%s%8%C%H!&%5!<%S%9$@$1$G$b!V%O%$%l%Y%k$J$b$N$@$1$G(B1$BF|$K(B60$B7o!W$G$9$+!#$=$&$$$&;~Be$K$J$C$F$7$^$C$?$N$G$9$M!#(B

$B"#(B $BDI5-(B

Microsoft Windows Server 2003 "Shell Folders" Directory Traversal Vulnerability

$B!!(BWindows Server 2003 SP1 $B1Q8lHG$G=$@5$5$l$F$$$k$3$H$,3NG'$5$l$?(B: penetration technique research site $B;2>H!#(B $B$^$?(B PivX $B$K$h$k$H!"(Bbid 7826 $B$N(B exploit $BMs(B$B$K$"$k(B ftpexp.html $B$K$D$$$F$O(B Windows Server 2003 $B$@$1$G$J$/(B Windows XP (SP2 $B4^$`(B) $B$K$b1F6A$9$k$H$$$&!#(B

March 2005 DNS Poisoning Summary

$B!!(BHandler's Diary April 7th 2005: DNS cache poisoning update (SANS ISC)$B!#7g4Y$"$j$N(B Windows NT / 2000 DNS $B%5!<%P$+$i(B BIND $B$d>e0L(B Windows NT / 2000 DNS $B%5!<%P$K(B forward $B$7$F$$$?>l9g$K$I$&$J$k$+!"$H$$$&OC$,=P$F$$$k!#(B

  • Windows DNS $B"*(B BIND 9 $B$X(B forward: BIND 9 $B$,%4%_$r=|5n$7$F$/$l$k$N$G!"(Bcache $B1x@w$OH/@8$7$J$$!#(B

  • Windows DNS $B"*(B BIND 4 $B$^$?$O(B BIND 8 $B$X(B forward: BIND 4 / 8 $B$O%4%_$r=|5n$7$F$/$l$J$$$N$G!"(Bcache $B1x@w$,H/@8!#(B

  • Windows DNS $B"*(B Windows DNS: $B>e0L$N(B Windows DNS $B$K(B KB241352 $B$N@_Dj$,$5$l$F$$$l$P!"2<0L(B Windows DNS $B$K$O(B cache $B1x@w$OH/@8$7$J$$!#$=$&$G$J$1$l$P!"(Bcache $B1x@w$,H/@8!#(B

$B!!(BHandler's Diary $B$G$O!">e0L(B DNS $B%5!<%P$,(B BIND $B$N>l9g$O!"(BBIND 9 $B$X$N%"%C%W%0%l!<%I$r?d>)$7$F$$$k!#(B

$B$$$m$$$m(B (2005.03.30)

$B!!F|K\8l(B KB $B=P$^$7$?(B: 889323 - $B4IM} (Microsoft)

SHA-1 Broken

$B!!(B$B2rFI$5$l$?(BSHA-1: $B!V(BCRYPTO-GRAM$B!!(BMarch 15, 2005$B!W$h$j(B ($BF|7P(B IT Pro, 2005.04.07)


$B"#(B 2005.04.06

$B"#(B iDEFENSE Security Advisory 04.05.05: Computer Associates eTrust Intrusion Detection System CPImportKey DoS
(iDEFENSE, 2005.04.05)

$B!!(BeTrust Intrusion Detection 3.0 / 3.0 SP1 $B$K7g4Y!#(Bbuffer overflow $B$9$k7g4Y$,$"$j!"(BDoS $B967b$r$B$3$N%Z!<%8(B $B$K$OB8:_$7$J$$$h$&$@!#(B

$B"#(B iDEFENSE Security Advisory 03.31.05: PHP getimagesize() Multiple Denial of Service Vulnerabilities
(iDEFENSE, 2005.03.31)

$B!!(BPHP 4.3.10 / 5.0.3 $B0JA0$K(B 2 $B$D$N7g4Y!#(B

$B!!(BPHP 4.3.11 / 5.0.4 $B$G=$@5$5$l$F$$$k!#(B

2005.04.19 $BDI5-(B:

$B!!(B[SECURITY] [DSA 708-1] New PHP3 packages fix denial of service$B!#(BDebian $B$5$9$,$G$9!#$$$^$@$K(B PHP3 $B$,%a%s%F%J%s%9$5$l$F$$$^$9!#(B

$B"#(B FreeBSD $B4XO"(B
(various)

$B"#(B $BDI5-(B

Adaptive Server Enterprise - Companion TechNote to UCN entitled Urgent from Sybase: Security Issues in ASE 12.5.3 and Earlier.

$B!!>\:Y(B: [VulnWatch] Sybase ASE Multiple Security Issues (#NISR05042005) (NGSSoftware)

SYM05-006: Denial of Service in Symantec Norton AntiVirus AutoProtect

$B!!(B2004 $B%7%j!<%:$K$D$$$F$bBP1~$5$l$?$h$&$G!"(B SYM05-006: Symantec Norton AntiVirus $B$N(B AutoProtect $B5!G=$K%5!<%S%95qH]$N@H $B$,(B 4/5 $BIU$G!VK\7o$N1F6A$r

March 2005 DNS Poisoning Summary

$B!!(B316786 - DNS $B%5!<%P!<$N(B [Pollution $B$KBP$7$F%;%-%e%j%F%#$G%-%c%C%7%e$rJ]8n$9$k(B] $B@_Dj$K$D$$$F(B (Microsoft)

DNS $B%-%c%C%7%eGK2u$NKI;_$O!"(BWindows 2000 SP3 $B0J9_$G$O!"%G%U%)%k%H$GM-8z$K$5$l$^$9!#(B

$B!!$=$&$@$C$?$N$+!#$9$k$H!"967b$r


$B"#(B 2005.04.05


$B"#(B 2005.04.04

$B"#(B Adobe Reader$B!?(BAcrobat$B$K%;%-%e%j%F%#!&%[!<%k!$%O%s%0%"%C%W$5$;$i$l$k62$l$"$j(B
($BF|7P(B IT Pro, 2005.04.04)

$B!!(BAdobe Reader 7.0 / Adobe Acrobat 7.0 $B0JA0(B for Windows $B$K!"(BDoS $B$H$J$k7g4Y$H%Q%9>pJs$,O31H$9$k7g4Y!#(BAdobe Reader 7.0.1 / Adobe Acrobat 7.0.1 for Windows $B$G=$@5$5$l$F$$$k!#(Bpatch$B!#(B

$B!!L5=~$N(B Adobe Reader $B$O$H$b$+$/!"M-=~$N(B Adobe Acrobat 6.x $B$K$D$$$F$b!"(B7.0 $B$X$N%"%C%W%0%l!<%I$G$7$+BP1~$5$l$J$$LOMM!#$9$P$i$7$$2q

2005.04.28 $BDI5-(B:

$B!!(B$B%"%I%S%7%9%F%`%: ($BIY;NDL(B, 2005.04.21)$B!#@=IJE:IU(B CD-ROM $BFb$N(B Acrobat Reader / Adobe Reader $B$K4X$9$kJ8=q!#(B

$B"#(B March 2005 DNS Poisoning Summary
(SANS ISC, 2005.03.03$B!A(B)

$B!!$3$N$4$mA{$.$K$J$C$F$$$k(B DNS $B%-%c%C%7%e1x@w$5$o$.$N35MW!#(B Microsoft $B$O:#$+$i$G$b!"(BWindows NT 4.0 / 2000 $B$N(B DNS $B%5!<%P$KBP$7$F!"(B KB241352 $B$N@_Dj$r<+F0E*$K9T$C$F:F5/F0$9$k$h$&$J!V%;%-%e%j%F%#=$@5%W%m%0%i%`!W$r!V=EMW$J99?7!W$H$7$F8x3+$9$Y$-$J$N$G$O$J$$$N$+!#(B

$B!!(BWindows $B$J(B DNS $B%/%i%$%"%s%HJ}LL$K$D$$$F$O!"(BVulnerability Note VU#458659: Microsoft Windows domain name resolver service accepts responses from non-queried DNS servers by default $B$NOC$b;2>H!#$^$?%-%c%C%7%e4|4V$K$D$$$F$O(B:

2005.04.06 $BDI5-(B:

$B!!(B316786 - DNS $B%5!<%P!<$N(B [Pollution $B$KBP$7$F%;%-%e%j%F%#$G%-%c%C%7%e$rJ]8n$9$k(B] $B@_Dj$K$D$$$F(B (Microsoft)

DNS $B%-%c%C%7%eGK2u$NKI;_$O!"(BWindows 2000 SP3 $B0J9_$G$O!"%G%U%)%k%H$GM-8z$K$5$l$^$9!#(B

$B!!$=$&$@$C$?$N$+!#$9$k$H!"967b$r

2005.04.07 $BDI5-(B:

$B!!(BHandler's Diary April 7th 2005: DNS cache poisoning update (SANS ISC)$B!#7g4Y$"$j$N(B Windows NT / 2000 DNS $B%5!<%P$+$i(B BIND $B$d>e0L(B Windows NT / 2000 DNS $B%5!<%P$K(B forward $B$7$F$$$?>l9g$K$I$&$J$k$+!"$H$$$&OC$,=P$F$$$k!#(B

$B!!(BHandler's Diary $B$G$O!">e0L(B DNS $B%5!<%P$,(B BIND $B$N>l9g$O!"(BBIND 9 $B$X$N%"%C%W%0%l!<%I$r?d>)$7$F$$$k!#(B

2005.04.14 $BDI5-(B:

$B!!(B4/12 $BDI5-J,$H$^$H$a$?!#(B

$B"#(B $BDI5-(B

$B%+!<%=%k$*$h$S%"%$%3%s$N%U%)!<%^%C%H$N=hM}$N@H

$B!!(B$B%^%$%/%m%=%U%H!'!V(BWindows$BMQ%Q%C%A$K@H (CNET, 2005.04.01)$B!#(B Windows 9x/Me $BMQ$N(B patch $B$O$I$&$d$iIT==J,$i$7$$!#(B $B%V%k!<$K$J$k>e$KIT==J,!D!D!#(B


$B"#(B 2005.04.01

$B"#(B $BDI5-(B

OLE $B$*$h$S(B COM $B$N@H

$B!!I{:nMQ>pJs(B: 896648 - $B%;%-%e%j%F%#99?7%W%m%0%i%`(B 873333 $B!J(BMS05-012$B!K(B $B$N%$%s%9%H!<%k8e(B svchost.exe $B%(%i!<$,H/@8$9$k$3$H$,$"$j$^$9(B (Microsoft)$B!#(B $BIT6q9g$NB8:_$r3NG'$7$F$$$k$=$&$G$9!#(B

SYM05-006: Denial of Service in Symantec Norton AntiVirus AutoProtect

$B!!(B2005 $B%7%j!<%:$K$D$$$F$OBP1~$5$l$?$h$&$G$9(B: $B%7%^%s%F%C%/!"(BNorton AntiVirus 2005$B$NF|K\HG=$@5%Q%C%A$rG[I[3+;O(B (Internet Watch, 2005.04.01)$B!#(B $B


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B