$B%;%-%e%j%F%#%[!<%k(B memo - 2005.05

Last modified: Mon Jan 16 14:27:23 2006 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2005.05.31

$B"#(B $B=EMW(B: PowerChute Business Edition v6.x.x $B=$@5BP1~$N$40FFb(B
(APC)

$B!!(BAPC PowerChute Business Edition v6.x.x $B$K7g4Y!#(B 2005.07.28 06:43 $B0J9_$K(B PowerChute $B%5!<%P(B / $B%(!<%8%'%s%H%5!<%S%9$r5/F0$7$h$&$H$7$F$b5/F0$G$-$J$$!#(B $B$3$l$O!"(BSun $B$N(B Java JDK/JRE $B$K4^$^$l$k!V0E9f2=%3%s%]!<%M%s%H$N0lIt4|8B@Z$l!W$,860x$@$H$$$&!#(B PowerChute Business Edition v7.0 $B$K$O$3$N7g4Y$O$J$$!#(B

$B!!BP1~J}K!$H$7$F$O!"0J2<$NJ}K!$,$"$k!#(B

$B!!F#0f$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#4XO"(B:

2005.06.03 $BDI5-(B:

$B!!(BAPC$B ($B%f%K%7%9(B, 6/3)

2005.06.11 $BDI5-(B:

$B!!(B$B=EMW(B: PowerChute Business Edition v6.x.x $B=$@5BP1~$N$40FFb(B (APC) $B$,2~D{$5$l$F$$$^$9!#(B $B860x$O!"(BSun $B$N(B Java JDK/JRE $B$K4^$^$l$k!V0E9f2=%3%s%]!<%M%s%H$N0lIt4|8B@Z$l!W(B $B$G$O$J$/!"!V(BPowerChute Business Edition v6.x.x$B$N>ZL@=q$N4|8B@Z$l!W$@$=$&$G$9!#(B $B$^$?!"(B APC Security Advisory - Denial of Service Vulnerability with PowerChute Business Edition (apc.com) $B$OA4A34X78$J$$OC$G$7$?!#$9$$$^$;$s!#(Borz

$B!!F`NI$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2005.07.14 $BDI5-(B:

$B!!(BPowerChute Business Edition v6.x.x $B$NLdBj$K4X$9$k(B Q&A$B=8(B (APC) $B$,$G$-$F$$$^$7$?!#(B

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

Windows 98$B!?(BMe$B!\%&%$%k%9%P%9%?!<(B2004$B$G(BWindows$B%(%i!<$,I=<($5$l$kIT6q9g(B

$B!!(B$B%&%$%k%9%P%9%?!<(B2004: $B%"%C%W%G!<%H8e!"!V(BPCCPFW$B$,860x$G(Bkernel32.dll$B$K%(%i! ($B%H%l%s%I%^%$%/%m(B)$B!#=$@5%W%m%0%i%`$,!V(B1029$B!W$KJQ99$5$l$F$$$^$9!#(B $B$^$C$A$c$@$$$U$/$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

Computer Associates Vet Antivirus engine heap overflow vulnerability

$B!!(BBrightStor ARCserve Backup r11.1 $B$K$O!"$3$N7g4Y$O$J$$$=$&$@(B: RE: CAID 32896 - Computer Associates Vet Antivirus engine heap overflow vulnerability

*BSD, SCO OpenServer / UnixWare Hyper-Threading Considered Harmful

$B!!(BJVNVU#911878: simultaneous multithreading $B%W%m%;%C%5$K$*$1$k5!L)>pJsO31L$N2DG=@-(B

$B!!(B(typo fixed: $B7'G-$5$/$i$5$s46

$B"#(B [SA15486] BEA WebLogic Multiple Vulnerabilities
(secunia, 2005.05.24)

$B!!(BBEA WebLogic Server 6.x / 7.x / 8.x, BEA WebLogic Express 6.x / 7.x, BEA WebLogic Portal 8.x $B$KJ#?t$N7g4Y!#(B $B:G?7$N(B Service Pack $B$G=$@5$5$l$F$$$k$+!"(B patch $B$,MQ0U$5$l$F$$$k!#(B

2005.06.01 $BDI5-(B:

$B!!(B$B%;%-%e%j%F%#%"%I%P%$%6%j(B (beasys.co.jp) $B$KF|K\8lHG$,=P$F$$$^$9!#(Bvulcan $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2005.05.30

$B"#(B Sentinel Chicken Networks Security Advisory #04: ClamAV: Local Privilege Escalation Vulnerability On MacOS
(sentinelchicken.com, 2005.05.27)

$B!!(BClamAV 0.80rc4 $B!A(B 0.84rc2 $B$r(B Mac OS X $B>e$GMxMQ$9$k>l9g$K7g4Y!#(B $BFbItE*$KMxMQ$7$F$$$k(B ditto $B%3%^%s%I$N8F$S=P$7$K7g4Y$,$"$j!"(B $B:Y9)$r;\$7$?%U%!%$%kL>$r;XDj$9$k$3$H$K$h$jG$0U$N%7%'%k%3%^%s%I$r

$B!!(BClamAV 0.84 $B0J9_$G=$@5$5$l$F$$$k!#(B

$B"#(B $BDI5-(B

*BSD, SCO OpenServer / UnixWare Hyper-Threading Considered Harmful

$B!!(B$B!V(BOS$B%Y%s%@!<3F (CNET, 2005.05.30)


$B"#(B 2005.05.29

$B"#(B $BDa55%a!<%k(B Version 4.15$B;~E@$G8+$D$+$C$?@H
($B=($^$k$*$N%[!<%`%Z!<%8(B, 2005.05.27)

$B!!(B$BDa55%a!<%k(B 3.53$B!A(B4.15 $B$K7g4Y!#FCpJs$,O31L$7$?$H4*0c$$$9$kEy!K$rH/@8$5$;$k62$l$,$"!W$k$H$$$&!#>\:Y$O8x3+$5$l$F$$$J$$!#!V56Au!W$H$$$&$H(B XSS $B$rO"A[$7$F$7$^$&$N$@$,!"$O$F$5$F!D!D!#(B

$B!!Da55%a!<%k(B 4.16 $B$G=$@5$5$l$F$$$k!#$^$?Da55%a!<%k(B 4.16 $B$G!V$7!W$r$7!W$N7k2L$,0[$J$k(B)$B!#(B

$B"#(B $BDI5-(B

Windows 98$B!?(BMe$B!\%&%$%k%9%P%9%?!<(B2004$B$G(BWindows$B%(%i!<$,I=<($5$l$kIT6q9g(B

$B!!$^$C$A$c$@$$$U$/$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):

Trend$B$N%Z!<%8$G$O!"(B1.2.0.1027$B$,LdBj$N$"$k%b%8%e!<%k$@$=$&$G$9$,!"0J2pJs(B]$B%@%$%"%m%0%\%C%/%9Fb$KI=<($5$l$k!V%U%!%$%"%&%)!<%k%I%i%$%P!W(B
$B$N%P!<%8%g%s$r3NG'$7!"!V(B1.2.0.1027$B!W$H$J$C$F$$$l$P:#2s$NLdBj$K3:Ev$7$^$9!#(B
---

$B%@%&%s%m!<%I$G$-$k=$@5%b%8%e!<%k$O(Bvb24_TM_CFW_1020.exe$B$G$9!#(B
$B$3$l$C$F!"$b$7$d!"(B1.2.0.1020$B$N8E$$%b%8%e!<%k!)!*$H;W$C$FD4$Y$F$_$k$H(B
---
strings TM_CFW.VXD
<SNIP>
VxD TM_CFW (VtoolsD)
_The_DDB
VS_VERSION_INFO
StringFileInfo
040904E4
ProductVersion
1.2.0.1020
ProductName
Trend Micro Common Firewall 1.2
---
$B$"$!!"!"!"=$@5%b%8%e!<%k$8$c$J$/$C$F!"La$9%b%8%e!<%k$+$$!*!*!*!*!*!*!*(B
$B$H$j$"$($:$NBP=h$J$N$G$7$g$&$,$J$$$G$9$+$M!#(B
      
$B$G$b!"$3$l$O7h$7$F=$@5%b%8%e!<%k$H$O8F$P$J$$!*$H(B $B$^$C$A$c$O;W$C$?$N$G$7$?!#(B

$B"#(B 2005.05.28


$B"#(B 2005.05.27

$B"#(B Windows 98$B!?(BMe$B!\%&%$%k%9%P%9%?!<(B2004$B$G(BWindows$B%(%i!<$,I=<($5$l$kIT6q9g(B
(ITmedia, 2005.05.27)

$B!!(BWindows 98 ($BB?J,(B 98 SE $B$b(B) / Me + $B%&%$%k%9%P%9%?!<(B 2004 + 2005.05.26 20:20 $B!A(B 2005.05.27 02:30 $B$N4V$K%"%C%W%G!<%H$7$??M!"(B $B$N>l9g$K%(%i!<$,=P$k$=$&$G!#$A$$$A$c$s$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(Bsolution 11404 $B$+$i=$@5%b%8%e!<%k$rF~

% unzip -l vb24_TM_CFW_1020.exe 
Archive:  vb24_TM_CFW_1020.exe
warning [vb24_TM_CFW_1020.exe]:  75232 extra bytes at beginning or within zipfile
  (attempting to process anyway)
  Length     Date   Time    Name
 --------    ----   ----    ----
   759931  11-05-04 16:07   TM_CFW.VXD
    98304  11-05-04 16:08   tmCfwApi.dll
 --------                   -------
   858235                   2 files

$B!!2?$,=$@5$5$l$?$s$@$m$&$J$"!#(B

2005.05.29 $BDI5-(B:

$B!!$^$C$A$c$@$$$U$/$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):

Trend$B$N%Z!<%8$G$O!"(B1.2.0.1027$B$,LdBj$N$"$k%b%8%e!<%k$@$=$&$G$9$,!"0J2pJs(B]$B%@%$%"%m%0%\%C%/%9Fb$KI=<($5$l$k!V%U%!%$%"%&%)!<%k%I%i%$%P!W(B
$B$N%P!<%8%g%s$r3NG'$7!"!V(B1.2.0.1027$B!W$H$J$C$F$$$l$P:#2s$NLdBj$K3:Ev$7$^$9!#(B
---

$B%@%&%s%m!<%I$G$-$k=$@5%b%8%e!<%k$O(Bvb24_TM_CFW_1020.exe$B$G$9!#(B
$B$3$l$C$F!"$b$7$d!"(B1.2.0.1020$B$N8E$$%b%8%e!<%k!)!*$H;W$C$FD4$Y$F$_$k$H(B
---
strings TM_CFW.VXD
<SNIP>
VxD TM_CFW (VtoolsD)
_The_DDB
VS_VERSION_INFO
StringFileInfo
040904E4
ProductVersion
1.2.0.1020
ProductName
Trend Micro Common Firewall 1.2
---
$B$"$!!"!"!"=$@5%b%8%e!<%k$8$c$J$/$C$F!"La$9%b%8%e!<%k$+$$!*!*!*!*!*!*!*(B
$B$H$j$"$($:$NBP=h$J$N$G$7$g$&$,$J$$$G$9$+$M!#(B

$B$G$b!"$3$l$O7h$7$F=$@5%b%8%e!<%k$H$O8F$P$J$$!*$H(B $B$^$C$A$c$O;W$C$?$N$G$7$?!#(B

2005.06.01 $BDI5-(B:

$B!!(B$B%&%$%k%9%P%9%?!<(B2004: $B%"%C%W%G!<%H8e!"!V(BPCCPFW$B$,860x$G(Bkernel32.dll$B$K%(%i! ($B%H%l%s%I%^%$%/%m(B)$B!#=$@5%W%m%0%i%`$,!V(B1029$B!W$KJQ99$5$l$F$$$^$9!#(B $B$^$C$A$c$@$$$U$/$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B Extreme Networks Field Notice - FN0215: Extreme Networks Security Alert on ExtremeWare XOS Based Systems
(Extreme Networks, 2005.05.12)

$B!!(BBlackDiamond 8800 / 10808 (10K) Switch $B>e$N(B ExtremeWare XOS 10.x / 11.x $B$K7g4Y!#(B $B%f!<%6%l%Y%k%"%+%&%s%H$+$i4IM}

$B!!(BExtremeWare XOS 11.0.2.4 $B$*$h$S(B 11.1.3.3 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B $BDI5-(B

$B2A3J(B.com$B%5%$%H$,IT@5%"%/%;%9Ho32$GJD:?Cf(B

$B!!F1MM;vNc(B:

ASP.NET $B%Q%98!>Z$N@H

$B!!(BInstallation of .NET Framework service packs is not completed if you first install security update MS05-004 (Microsoft)$B!#(B

Windows Kernel $B$N@H:3J$*$h$S%5!<%S%95qH]$,$*$3$k(B (890859) (MS05-018)

$B!!(BYou receive a "STOP 0x0000001E" error after you install security update MS05-018 on a Windows 2000-based computer (Microsoft)$B!#%5%]!<%H7PM3$G(B hotfix $B$rF~

JVN#FCAD9BD8: $B%a!<%k%/%i%$%"%s%H%=%U%H$K$*$1$k(B mailto URL scheme $B$NITE,@Z$J2r

$B!!(BBecky! Internet Mail Ver.2.21.02 (Bcc $BL5;kHG(B) $BEP>l$K$"$o$;$F5-=R$r=$@5!#(B

$B!!4XO"(B: mailto: URL $B$G(B Bcc: $B$,;XDj$G$-$F$7$^$&LdBj(B ($B?eL57n$P$1$i$N$($SF|5-(B, 2005.05.26)


$B"#(B 2005.05.26

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B NISCC Vulnerability Advisory DNS - 589088: Vulnerability Issue in Implementations of the DNS Protocol
(UNIRAS, 2005.05.24)

$B!!J#?t%Y%s%@$N(B DNS $B%G!<%?=hM}$K7g4Y!#(B RFC1035 $B$N(B 4.1.4 $B$GDj5A$5$l$F$$$k!"(B $B05=L$5$l$?(B DNS $B%a%C%;!<%8$NE83+=hM}$K7g4Y$,$"$j!"0[>o=*N;$dG$0U$N%3!<%I$Nl9g$,$"$k!#(B $B7g4Y$,$"$k$H$5$l$F$$$k$N$O0J2<$N$b$N(B:

$B!!$^$?(B NISCC Vulnerability Advisory DNS - 589088 $B$K$O5-:\$5$l$F$$$J$$$,!"(BCisco $B$+$i(B Cisco Security Notice: Crafted DNS Packet Can Cause Denial Of Service (Cisco) $B$,=P$F$$$k!#(B Cisco IP Phones 7902/7905/7912, Cisco ATA (Analog Telephone Adaptor) 186/188, Cisco Unity Express, Cisco ACNS (Application and Content Networking System) devices $B$K7g4Y$,$"$j!"(BDoS $B>uBV$K$J$kLOMM!#(B

$B!!4XO"(B: NISCC-589088: DNS $B%Q%1%C%H$K4^$^$l$k05=L$5$l$?%G!<%?$NE83+=hM}$K4X$9$k@H (JVN)

$B"#(B Keynote 2.0.2: Security enhancements
(Apple, 2005.05.26)

$B!!(BKeynote 2 / 2.0.1 $B$K7g4Y!#:Y9)$7$?(B Keynote $B%W%l%<%s%F!<%7%g%s$H(B keynote: URI $B%O%s%I%i$NMxMQ$K$h$j!"(Blocal file $B$rFI$_CAN-2005-1408

$B!!(BKeynote 2.0.2 $B$G=$@5$5$l$F$$$k!#(BKeynote 2.0.2 $B$G$O!"30It%j%=!<%9$N;2>H$,@)8B$5$l!"(Bkeynote: URI $B%O%s%I%i$O:o=|$5$l$?!#(B

$B!!(B$B%=%U%H%&%'%"(B $B%"%C%W%G!<%H(B$B$+$i(B Keynote 2.0.2 $B$rF~Keynote $B%@%&%s%m!<%I%Z!<%8(B$B$G$O$^$@(B Keynote 2.0.1 $B$,G[I[$5$l$F$$$k!#(B

$B"#(B Netscape 8$B$r%$%s%9%H!<%k$9$k$H(BIE$B$N(BXML$B5!G=$K0[>o(B
(Internet Watch, 2005.05.26)

IEBlog$B$K$h$k$H!"LdBj$r2r7h$9$k$K$O(BNetscape 8$B$r%"%s%$%s%9%H!<%k$7$?8e!"%l%8%9%H%j%(%G%#%?$r5/F0$7$F!V(BHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension$B!W$N9`L\$K$"$k!V(Bxml$B!W$H5-$5$l$?%N!<%I$r:o=|$7$J$1$l$P$J$i$J$$$H$$$&!#$=$N8e!"(BIE$B$r:F5/F0$9$k$H(BIE$B$N(BXML$B%l%s%@%j%s%05!G=$,@5>o$KF/$/$h$&$K$J$k!#(BNetscape 8$B$,%$%s%9%H!<%k$5$l$?>uBV$G$O@d$($:$3$N%l%8%9%H%j$r5-F~$7B3$1$k$?$a!"(BIE$B$N(BXML$B%l%s%@%j%s%05!G=$rI|5l$9$k$3$H$,$G$-$J$$$H$7$F$$$k!#(B

$B!!$@$=$&$J$N$G!"(BNetscape 8 $B$rMxMQ$9$k>l9g$O$4Cm0U!#(B

2005.06.22 $BDI5-(B:

$B!!(BNetscape 8.02 $B$G=$@5$5$l$?$=$&$G$9(B: IE$B$K0[>o$r$b$?$i$7$?!H(BNetscape 8$BLdBj!I$r=$@5!"!V(BNetscape 8.02$B!W8x3+(B (Internet Watch, 2005.06.20)

$B"#(B JVN#FCAD9BD8: $B%a!<%k%/%i%$%"%s%H%=%U%H$K$*$1$k(B mailto URL scheme $B$NITE,@Z$J2r
(JVN, 2005.05.26)

$B!!(BCc: $B$d(B Bcc: $B$r4^$^$;$?(B mailto: URL $B$r$?$I$C$?>l9g$K!"(BCc: $B$d(B Bcc: $B$,B8:_$9$k$3$H$K5$$,$D$+$J$$(B ($BI=<($5$l$J$$!"5$$,$D$-$K$/$$Ey(B) $B$^$^%a!<%k$rAw$C$F$7$^$&%a!<%k%=%U%H$,$"$k!"$H$$$&OC$NLOMM!#(B RFC2368: The mailto URL scheme $B$K$O$3$s$JJ8>O$b$"$k$=$&$G(B:

Note that some headers are inherently unsafe to include in a message generated from a URL. For example, headers such as "From:", "Bcc:", and so on, should never be interpreted from a URL. In general, the fewer headers interpreted from the URL, the less likely it is that a sending agent will create an unsafe message.

$B!!(Bmailto: URL $BCf$N!">/$J$/$H$b(B Bcc: $B$O!"L5;k$9$k$N$,E,@Z$JF0:n$J$N$G$7$g$&!#(B Cc: $B$bL5;k$7$F$$$$$h$&$J5$$,$9$k$1$I!#(B

$B!!>u67(B:

2005.05.27 $BDI5-(B:

$B!!(BBecky! Internet Mail Ver.2.21.02 (Bcc $BL5;kHG(B) $BEP>l$K$"$o$;$F5-=R$r=$@5!#(B

$B!!(B$BDa55%a!<%k$G$N(Bmailto:$B%W%m%H%3%k$K4X78$7$?@H (maruo.co.jp) $B$X$N%j%s%/$rDI2C!#(B

$B!!4XO"(B: mailto: URL $B$G(B Bcc: $B$,;XDj$G$-$F$7$^$&LdBj(B ($B?eL57n$P$1$i$N$($SF|5-(B, 2005.05.26)

$B"#(B $BDI5-(B

TCP/IP $B$N@H

$B!!(BMicrosoft Security Advisory (899480) $B$NF|K\8lHG$,=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (899480) TCP $B$N@H (Microsoft)


$B"#(B 2005.05.25

$B"#(B Computer Associates Vet Antivirus engine heap overflow vulnerability
(CA, 2005.05.23)

$B!!(BCA $B$N(B eTrust Antivirus $B$d(B BrightStor ARCserve Backup r11.1$B!"(BZonelabs $B$N(B ZoneAlarm SecuritySuite / AntiVirus $B$J$I$K4^$^$l$k(B Vet $B%(%s%8%s$N(B 11.9.1 $B$h$jA0$NHG$K7g4Y!#(BOLE $B%9%H%j!<%`$N2r@O;~$K(B integer overflow $B$r5/0x$H$9$k(B heap overflow $B$,H/@8!"96N,(B Office $B%I%-%e%a%s%H$K$h$jG$0U$N%3!<%I$rpJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BVet $B%(%s%8%s(B 11.9.1 $B$G=$@5$5$l$F$$$k!#<+F099?7$5$l$k@=IJ(B (eTrust EZ Antivirus 7.x $B$J$I(B) $B$H!"

$B!!4XO"(B:

2005.05.31 $BDI5-(B:

$B!!(BBrightStor ARCserve Backup r11.1 $B$K$O!"$3$N7g4Y$O$J$$$=$&$@(B: RE: CAID 32896 - Computer Associates Vet Antivirus engine heap overflow vulnerability

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

JVN#465742E4: Wiki $B%/%m!<%s$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H

$B!!(B$B%U%!%$%kE:IU$N@H ($B$U$'$_$K$sF|5-(B, 5/21)$B!#(BHiki $B$G


$B"#(B 2005.05.24

$B"#(B $BDI5-(B

JVN#465742E4: Wiki $B%/%m!<%s$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H

$B!!(BFreeStyleWiki $B$K$bF1MM$N7g4Y$,$"$C$?$h$&$G!"(B3.5.8 $B$G=$@5$5$l$F$$$k$=$&$G$9(B:


$B"#(B 2005.05.23

$B"#(B iBook G4$B$*$h$S(BPowerBook G4$B%P%C%F%j!<8r49%W%m%0%i%`(B
(Apple, 2005.05.21?)

$B!!(B12 $B%$%s%A(B iBook G4$B!"(B12 $B%$%s%A(B PowerBook G4$B!"(B15 $B%$%s%A(B PowerBook G4 $B$N%P%C%F%j$N0lIt$K!"2aG.$7H/2P$9$k2DG=@-$,$"$k$=$&$G!"L5=~8r49$r9T$C$F$$$k$=$&$G$9!#(B iBook G4 / PowerBook G4 $BMxMQ]$H$J$k%P%C%F%j$N7?HV$O0J2<$N$H$*$j$G$9!#(B

$B%3%s%T%e!<%?%b%G%k(B $B%P%C%F%j!<$N(B Model No. $B%7%j%"%kHV9f(B ($B%P!<%3!<%IItJ,(B) $B$N>e(B 4 $B7e$NHO0O(B
12 $B%$%s%A(B iBook G4 A1061 HQ441$B!A(BHQ507
12 $B%$%s%A(B PowerBook G4 A1079 3X446$B!A(B3X510
15 $B%$%s%A(B PowerBook G4 A1078 3X446$B!A(B3X509

$B!!$7$+$7!"$3$&$$$&=EMW$J%K%e!<%9$,(B $B%[%C%H%K%e!<%9(B (Apple) $B$K7G:\$5$l$J$$$N$O$J$s$G$@$m$&!#(B


$B"#(B 2005.05.21

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

Vulnerability Note VU#637934: TCP does not adequately validate segments before updating timestamp value

$B!!(BFreeBSD $B$N9`$K>pJs$rDI2C$7$^$7$?!#(B

$B!V(BFirefox$B!W$KG$0U%3!<%I$,

$B!!(BMozilla 1.7.8 $BF|K\8lHG$,EP>l$7$F$$$^$9!#>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B About the security content of the Mac OS X 10.4.1 Update
(Apple, 2005.05.20)

$B!!@hF|EP>l$7$?(B Mac OS X 10.4.1 (Client, Server) $B$K$OJ#?t$N%;%-%e%j%F%#7g4Y$KBP$9$k=$@5$,4^$^$l$F$$$k$=$&$G$9!#(B

$B!!4XO"(B:


$B"#(B 2005.05.20

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

OLE $B$*$h$S(B COM $B$N@H

$B!!IT6q9g>pJs(B: 894391 - [FIX] $B%;%-%e%j%F%#99?7%W%m%0%i%`(B MS05-012 $B$r%$%s%9%H!<%k8e!"%j%C%A%F%-%9%H7A<0$NEE;R%a!<%k%a%C%;!<%8$G(B 2 $B%P%$%HJ8;z%;%C%H$NE:IU%U%!%$%kL>$,I=<($5$l$:!"%(%i!<%a%C%;!<%8(B "Generic Host Process" $B$,I=<($5$l$k$3$H$,$"$k(B (Microsoft)$B!#(B patch $B$b8x3+$5$l$F$$$k(B: $B%-!<%o!<%I(B "894391" (Microsoft $B%@%&%s%m!<%I%;%s%?!<(B)$B!#(B $B$3$N(B patch $B$G

$B!!(B896648 - $B%;%-%e%j%F%#99?7%W%m%0%i%`(B 873333 $B!J(BMS05-012$B!K(B $B$N%$%s%9%H!<%k8e(B svchost.exe $B%(%i!<$,H/@8$9$k$3$H$,$"$j$^$9(B (Microsoft) $B$K$D$$$F$O!V(BWindows XP COM+ $B=$@5%W%m%0%i%`%m!<%k%"%C%W%Q%C%1!<%8(B 9 $B$r!W$N$^$^$@$,!"(B 894391 $B$r%$%s%9%H!<%k$9$k$H8F$S=P$5$lB&$N(B ole32.dll $B$,99?7$5$l$k$N$G!">u67$,JQ2=$9$k$+$b$7$l$J$$!#(B

$B!!%U%m!<%H$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

TCP/IP $B$N@H

$B!!(BMS05-019 patch $B$K$O!"(BVulnerability Note VU#637934: TCP does not adequately validate segments before updating timestamp value $B$KBP$9$k=$@5$b4^$^$l$F$$$k$=$&$@!#(B

$B!!$^$?(B Microsoft Security Advisory (899480) $B$K$O!"(BMS05-019 patch $B$,(B 6 $B7n$K:F%j%j!<%9$5$l$kM=Dj$G$"$k!"$H$b5-:\$5$l$F$$$k!#(B KB898060 $BLdBj$,=$@5$5$l$k$h$&$@!#(B

NISCC Vulnerability Advisory ICMP - 532967: Vulnerability Issues in ICMP packets with TCP payloads

$B!!(B$B!V(BTCP$B ($BF|N)(B)

$B"#(B Vulnerability Note VU#637934: TCP does not adequately validate segments before updating timestamp value
(cert.org, 2005.05.19)

$B!!J#?t%Y%s%@$N(B TCP $BRFC1323: TCP Extensions for High Performance $B$GDj5A$5$l$F$$$k(B TCP Timestamps $B%*%W%7%g%s$H!"$3$l$b(B RFC1323 $B$G2r@b$5$l$F$$$k(B PAWS (Protect Against Wrapped Sequence Numbers) $B$NN>J}$,M-8z$K$5$l$?>l9g$r9M$($k!#(B $B$3$N$H$-!"%[%9%H$N(B IP $B%"%I%l%9!&%]!<%HHV9f$NB>$K!"FbIt%?%$%^CM$H(B TCP $B%7!<%1%s%9HV9f$rCN$k$3$H$,$G$-$k$H!"(B $B!V(BTCP Timestamps > $BFbIt%?%$%^!"(BTCP $B%7!<%1%s%9HV9f(B < $B8=:_$N(B TCP $B%7!<%1%s%9HV9f!W$H$$$&%Q%1%C%H$rA^F~$9$k$3$H$K$h$C$F!"(B PAWS $B5!9=$r0-MQ$7$?(B TCP $B%j%;%C%H967b$r9T$&$3$H$,2DG=!#(B $B$3$3$^$G$O;EMM$J$N$@$,!"(B $B0lIt$N(B TCP $BZ$7$F$$$J$$$?$a!"(B PAWS $B5!9=$r0-MQ$7$?(B TCP $B%j%;%C%H967b$r$h$jMF0W$KCAN-2005-0356

$B!!2sHr:v$H$7$F!"(BRAWS $B$NL58z2=$,5s$2$i$l$F$$$k!#(B

$B!!7g4Y$N$"$k%Y%s%@$H$7$F!"(BCisco, Microsoft, FreeBSD, OpenBSD, $BF|N)$J$I$,5s$2$i$l$F$$$k!#(B

$B!!4XO"(B:

2005.05.21 $BDI5-(B:

$B!!(BFreeBSD $B$N9`$K>pJs$rDI2C$7$^$7$?!#(B

2005.06.02 $BDI5-(B:

$B!!(BCVE: CAN-2005-0356$B!"(B BIG-IP TCP Timestamp Denial of Service $B$rDI2C!#(B

2005.07.04 $BDI5-(B:

$B!!(BFreeBSD $B$N9`$K(B FreeBSD-SA-05:15.tcp - TCP connection stall denial of service $B$rDI2C$7$^$7$?!#(B


$B"#(B 2005.05.19

$B"#(B JVN#465742E4: Wiki $B%/%m!<%s$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H
(JVN, 2005.05.19)

$B!!(BWiki $B$H$$$&$N$O!"$U$D$&$OG$0U$N%?%0$H$+%9%/%j%W%H$H$+$O=q$1$J$$$h$&$K$J$C$F$$$k$H;W$&$N$@$1$I!"!V%U%!%$%kE:IU5!G=!W$,$"$k(B Wiki $B%/%m!<%s$K$*$$$F!"%9%/%j%W%H$D$-$N%U%!%$%k$rE:IU$5$;$k$3$H$G!"$=$N%9%/%j%W%H$r(B Wiki $B%5!<%P$N%;%-%e%j%F%#%>!<%s8"8B$G

$B!!$H$j$"$($:2sHr$9$k$K$O!"!V%U%!%$%kE:IU5!G=!W$rL58z$K$9$l$P$h$$!#(B

$B!!(BJVN#465742E4 $B$G$O(B AsWiki $B$H(B Hiki $B$O!V3:Ev@=IJ$J$7!W$H$J$C$F$$$k$N$@$,!"

$B!!(BWiki$B$b$I$-(B $B%;%-%e%j%F%#>pJs(B$B$K$O!VE:IU%U%!%$%k5!G=$NMxMQ@)8B!W$H$$$&$b$N$b7G:\$5$l$F$$$k$N$@$,!"(BInternet Explorer $B$_$?$$$J%V%i%&%6(B (Content-Type $B$G$O$J$/Cf?H$r8+$F>!

$B!!$"$H!"$?$H$($P(B FreeStyleWiki $B$K$b!V%U%!%$%kE:IU5!G=!W$,$"$k$h$&$J$N$@$,!"K\7o$K$D$$$F$I$&$J$C$F$$$k$N$+!"$O!"$h$/$o$+$i$J$$!#(B

$B!!4XO"(B:

2005.05.24 $BDI5-(B:

$B!!(BFreeStyleWiki $B$K$bF1MM$N7g4Y$,$"$C$?$h$&$G!"(B3.5.8 $B$G=$@5$5$l$F$$$k$=$&$G$9(B:

2005.05.25 $BDI5-(B:

$B!!(B$B%U%!%$%kE:IU$N@H ($B$U$'$_$K$sF|5-(B, 5/21)$B!#(BHiki $B$G

$B"#(B $BDI5-(B

2005 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BWindows $B%$%s%9%H!<%i(B 3.1(v2) $B$H!"(BWindows 2003 SP1 $B$*$h$S(B 64bit $BHG(B Windows XP $BMQ$N(B Windows $B%$%s%9%H!<%i(B 3.1 $B%"%C%W%G!<%H$,8x3+$5$l$F$$$^$9!#(B

bid 9986: OpenSSH SCP Client File Corruption Vulnerability

$B!!(BCVE: CAN-2004-0175


$B"#(B 2005.05.18

$B"#(B $BDI5-(B

*BSD, SCO OpenServer / UnixWare Hyper-Threading Considered Harmful

$B!!$I$&$d$i(B OS $B$K$O0MB8$7$J$$$*OC$@$C$?$h$&$G!D!D!#(B

$B!!$"$H!"(BFreeBSD-SA-05:09.htt [REVISED] $B$H(B SCOSA-2005.24: OpenServer 5.0.7 UnixWare 7.1.4 UnixWare 7.1.3 : Hyper-Threading information leakage $B$,=P$?$N$G!"$3$l$^$G$N5-;v$N$H$3$m$KDI2C$7$F$*$-$^$7$?!#(B

Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (867282) (MS05-014)

$B!!I{:nMQ>pJs(B:

$B!!(BMS05-020 $B$GBP1~$7$F$$$k$=$&$@!#(B

$B!V%&%$%k%9%;%-%e%j%F%#!W$K$*$1$k%R!<%W%*!<%P!<%U%m!

$B!!(BLAC SNS $B$+$i>pJs$,8x3+$5$l$^$7$?!#(B

$B2A3J(B.com$B%5%$%H$,IT@5%"%/%;%9Ho32$GJD:?Cf(B

$B!!F1MM;vNc(B:

$B!!$7$+$7!"$=$s$JDxEY$G$O:Q$^$J$$$+$b!#$$$H$A$c$s$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):

Google$B$G!V(BPowered by phpBB 2.0.11$B!W!JF|K\8l$G!K$r8!:w$7$F!"(BphpBB$B%5%$%H(B
http://www.ptexchange.net $B!J=$I|:Q$_!K(B
http://www.hobbyjapan.co.jp/dd/ddbbs
http://www.princess2.com/phpbb2/index.php
http://granadoespada.sub.jp/php/phpbb2/index.php
$B!J$^$G3NG'!#0J2<$b$"$k$+$b$7$l$^$;$s!#!K(B
$B$K2A3J%3%`$HF1$8$H;W$o$l$k2~$6$s$,$"$kLOMM$G$9!#(B
$B!J(Bj4sb.com$B$X$N(Biframe$B!K(B

$B!!$D!<$+(B phpBB 2.0.11 $B!D!D!#!V(BPowered by phpBB 2.0.11 $B$N8!:w7k2L$N$&$A(B $BF|K\8l$N%Z!<%8(B $BLs(B 1,010 $B7oCf(B 1 - 10 $B7oL\(B (0.30 $BIC(B) $B!W$C$F8@$o$l$k$7!#(B $B1Q8l$@$H8!:w$r%V%m%C%/$7$F$$$k$1$I!"F|K\8l$@$H(B ok $B$J$N$M(B > google$B!#$C$F!"(B[$B

$B!!(BSophos $B$,(B Troj/LegMir-AE (2005.05.17 19:45:48) $B$H$7$FBP1~$7$^$7$?!#(B $B%9%/%j%W%HItJ,$O(B Troj/Jfor-A (2005.05.18 04:31:50) $B$G$9!#(B $B4\;3$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!!D!D$=$N8e(B:

$B!!(Bhttp://www.princess2.com/phpbb2/index.php $B$d(B http://granadoespada.sub.jp/php/phpbb2/index.php $B$bBP1~$5$l$?$h$&$G$9!#(B

$B!!4XO"JsF;(B:

$B"#(B $B$$$m$$$m(B
(various)


$B"#(B 2005.05.17

$B"#(B $BDI5-(B

TCP/IP $B$N@H

$B!!(BWindows (XP, 2k3, Longhorn) is vulnerable to IpV6 Land attack. (ntbugtraq)$B!#(B patch $BE,MQ8e$b!"(BIPv6 $B$K$D$$$F$O(B land $B%"%?%C%/$,M-8z$G$"$k!"$H$$$&;XE&!#(B

$B2A3J(B.com$B%5%$%H$,IT@5%"%/%;%9Ho32$GJD:?Cf(B

$B!!%"%s%A%&%$%k%9%=%U%H$G$N%F%9%H7k2L$r2~D{$7$^$7$?!#%^%+%U%#!<$H%7%^%s%F%C%/$O(B a02.css $B$r%&%$%k%9$@$HH=Dj$9$k$h$&$K$J$j$^$7$?!#(B $B%^%+%U%#!<$N>l9g$O!"(Bhttp://www.j4sb.com/count/counter.ap?id=a05 $B$K%"%/%;%9$9$k$H=P$F$/$k%9%/%j%W%H$K$b(B Exploit-MhtRedir.gen $B$H$7$FBP1~$7$F$$$^$9!#(BMYST jellyfish $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!%7%^%s%F%C%/$+$i$b:o=|%D!<%k$,8x3+$5$l$F$$$^$9!#(B MYST jellyfish $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!2A3J(B.com $B$HF1MM$N>u67$,!"(BWindowsCE FAN: PocketPC WindowsCE $B%7%0%^%j%*%s(B $BAm9g>pJs%5%$%H(B$B$G$bH/@8$7$F$$$?$h$&$G$9!#@6?e$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B Firefox 1.0.4 / Mozilla 1.7.8 $B$G=$@5$5$l$?7g4Y(B
(mozilla.org, 2005.05.11)

$B!!(BFirefox 1.0.4 / Mozilla 1.7.8 $B$G=$@5$5$l$?7g4Y$O!"(B $B!V(BFirefox$B!W$KG$0U%3!<%I$, $B$N7o(B (MFSA2005-42) $B$@$1$8$c$J$+$C$?$s$G$9$M!#(B

$B!!$I$A$i$b!V=EMWEY(B: $B:G9b!W$G$9!#(B2005.05.18 $B0J9_$K>\:Y$,8x3+$5$l$k$h$&$G$9!#(B

$B!!(B($B%?%$%H%k=$@5(B: $B$J$+$@$5$s46


$B"#(B 2005.05.16

$B"#(B $B2A3J(B.com$B%5%$%H$,IT@5%"%/%;%9Ho32$GJD:?Cf(B
(slashdot.jp, 2005.05.15)

$B!!2A3J(B.com $B$,!"CY$/$H$b(B 5/11 $B$^$G$KIT@5%"%/%;%9$5$l$F%3%s%F%s%D$N0lIt$,2~$6$s$5$l!"(B5/14 $B$KJD:?$5$l$k$^$G$N4V!"%&%$%k%9$D$-%5%$%H$K$J$C$F$$$?LOMM!#(B $B$*$*$+$o$5$s!"$f$&!#$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B$3$N2~$6$s$K$h$j!"2?

$B!!(BNOD32 $B$J$s$F%^%$%J!<$J%"%s%A%&%$%k%9%=%U%H$N>u67$@$12r@b$5$l$F$b!D!D(B(T_T)$B!#(B $BB(9o%a%8%c!<(B 3 $Bu67$r3NG'$9$k$N$,6Z$J$s$8$c$J$$$N$+!#(B

$B$=$NB>%;%-%e%j%F%#%=%U%H3F

$B!!$=$NDxEY$N$3$H$K2?;~4V$+$+$k$s$@$m$&!#(B 2ch.net $B$N$^$H$a%Z!<%8$@$H$$$&(B $B2A3J(B.com$B$,%/%i%C%-%s%0$G0l;~JD:?!"1\Mw%f!<%6!<$O%&%$%k%946@w$b!J!-!&&X!&!K(B $B$NJ}$,$h$C$]$I>\$7$$!#(B

879 $BL>A0!'(B $BL>L5$7$5$s!w#5<~G/(B [sage] $BEj9FF|!'(B 2005/05/16($B7n(B) 06:30:58 ID:8NCW1riY
PSW.Delf.FZ$B$N8!=PG=NO$N3NG'!#(B
ttp://www.j4sb.com/count/counter.ap?id=a02
ttp://www.j4sb.com/count/data/a02.css
$B>e5-(BURL$B$+$i(Ba02.css$B$rJ]B8$7$F$3$l$r%9%-%c%s(B

$B!!$d$C$F$_$^$7$?!#(B

NOD32 1.1097 (20050515) >>CHM >>/# - Win32/TroyanDownloader.Small.AAO $B%H%m%$(B
>>CHM >>/#.exe - Win32/PSW.Delf.FZ $B%H%m%$(B
F-Secure Anti-Virus for Linux Servers version 4.63 build 4110
Database version: 2005-05-14_01
Trojan-PSW.Win32.Delf.fz
Virus Scanner v3.1, VSAPI v7.510-1002
Trend Micro Inc. 1996,1997
Pattern number 2.631.00
$B8!=P$;$:(B ($B"((B)
$B%H%l%s%I%^%$%/%m(B $B%&%$%k%9%P%9%?!<(B 2005
$B%W%m%0%i%`%P!<%8%g%s(B: 12.2.1021
$B8!:w%(%s%8%s(B: 7.510.1002
$B%Q%?!<%s(B: 2.631.00
$B8!=P$;$:(B ($B"((B)
ClamAV 0.85/881/Tue May 17 06:13:31 2005 $B8!=P$;$:(B
Sophos AntiVirus 3.93.2 Troj/LegMir-AE (2005.05.17 19:45:48)
$B%^%+%U%#!<(B VirusScan Enterprise 8.0i + engine 4400 + dat 4492 PWS-Lineage
$B%7%^%s%F%C%/(B Norton AntiVirus 2005 + 20050516.022 Trojan.Jasbom

$B!!(BNOD32 $B$O(B a02.css $B$KBP$7$F(B 2 $B$D$N!V%&%$%k%9!W$r8!=P$7$F$$$k$N$G$9$M!#(B $B$J$*(B a02.css $B$O(B HTML HELP (.CHM) $B7A<0$N%U%!%$%k$N$h$&$G$9!#(B

$B!!(B($B"((B) a02.css $B$=$N$b$N$G$O$J$/!"96N,%9%/%j%W%H$HAH$_$"$o$5$l$?7k2L@8@.$5$l$k%U%!%$%k$r8!=P$9$k%W%m%@%/%H$b$"$k$h$&$G$9!#(B

  • $B%H%l%s%I%^%$%/%m$N>l9g!"(B2.631.00 $B$G!"@8@.$5$l$?(B c:\winnt\system32\explorer.exe, RUNDLL32.EXE, htdll.dll $B$r(B TROJ_DELF.RM $B$H$7$F8!=P$9$k$=$&$G$9!#$A$$$A$c$s$5$s!"(BMYST jellyfish $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!F1MM;vNc(B: $B%;%-%e%j%F%#BP:v(B $B!J46@w8;%5%$%H!K(B: J-RMT (bne.jp)$B!#(B J-RMT $B$H$$$&$N$O(B http://j-rmt.com/ $B$N$h$&$G$9!#(Bhttp://j-rmt.com/ $B$K$O:#$G$b(B <iframe src=http://www.j4sb.com/count/counter.ap?id=a05 width=0 height=0></iframe> $B$H$+=q$+$l$F$$$^$9$N$G!";n$9>l9g$O==J,$4Cm0U$r!#(B J-RMT $B$O4Z9q$N%5%$%H$J$s$G$9$M!#(B

2005.05.16 $BDI5-(B:

$B!!%H%l%s%I%^%$%/%m$+$i(B TROJ_DELF.RM $B$N6n=|%D!<%k$,8x3+$5$l$F$$$^$9!#(B

$B!!5-;v$$$m$$$m(B:

$B!!$U$D$&$N4k6H$G$OH/@8$7$J$$>u67$K$J$C$F$$$k$K$b$+$+$o$i$:!V:G9b%l%Y%k$N%;%-%e%j%F%#$,GK$i$l$?!W$H$+!V:#2s$N967b$O!"%l%Y%k$N9b$$$b$N$@$C$?!W$H$+8@$($F$7$^$&!"$=$NH=CG4p=`$,M}2r$G$-$J$$!#(B $BK\Ev$K!V:G9b%l%Y%k$N%;%-%e%j%F%#!W$@$C$?$N$+!"$=$l$H$b!"(B $B85Cf$N?M$+$i8@$o$;$k$H!"<+6H<+F@$G$9(B (slashdot.jp) $B$,@5$7$$$N$+!#(B $BEv (kakaku.com) $B$G!V%5%$%P!<%F%m!W$H$$$&!"0B0W$K;H$&$Y$-$G$O$J$$8@MU$r;H$C$F$$$k$N$bBg$$$K5$$K$J$k!#(B

2005.05.17 $BDI5-(B:

$B!!%"%s%A%&%$%k%9%=%U%H$G$N%F%9%H7k2L$r2~D{$7$^$7$?!#%^%+%U%#!<$H%7%^%s%F%C%/$O(B a02.css $B$r%&%$%k%9$@$HH=Dj$9$k$h$&$K$J$j$^$7$?!#(B $B%^%+%U%#!<$N>l9g$O!"(Bhttp://www.j4sb.com/count/counter.ap?id=a05 $B$K%"%/%;%9$9$k$H=P$F$/$k%9%/%j%W%H$K$b(B Exploit-MhtRedir.gen $B$H$7$FBP1~$7$F$$$^$9!#(BMYST jellyfish $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!%7%^%s%F%C%/$+$i$b:o=|%D!<%k$,8x3+$5$l$F$$$^$9!#(B MYST jellyfish $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!2A3J(B.com $B$HF1MM$N>u67$,!"(BWindowsCE FAN: PocketPC WindowsCE $B%7%0%^%j%*%s(B $BAm9g>pJs%5%$%H(B$B$G$bH/@8$7$F$$$?$h$&$G$9!#@6?e$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2005.05.18 $BDI5-(B:

$B!!F1MM;vNc(B:

$B!!$7$+$7!"$=$s$JDxEY$G$O:Q$^$J$$$+$b!#$$$H$A$c$s$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B):

Google$B$G!V(BPowered by phpBB 2.0.11$B!W!JF|K\8l$G!K$r8!:w$7$F!"(BphpBB$B%5%$%H(B
http://www.ptexchange.net $B!J=$I|:Q$_!K(B
http://www.hobbyjapan.co.jp/dd/ddbbs
http://www.princess2.com/phpbb2/index.php
http://granadoespada.sub.jp/php/phpbb2/index.php
$B!J$^$G3NG'!#0J2<$b$"$k$+$b$7$l$^$;$s!#!K(B
$B$K2A3J%3%`$HF1$8$H;W$o$l$k2~$6$s$,$"$kLOMM$G$9!#(B
$B!J(Bj4sb.com$B$X$N(Biframe$B!K(B

$B!!$D!<$+(B phpBB 2.0.11 $B!D!D!#!V(BPowered by phpBB 2.0.11 $B$N8!:w7k2L$N$&$A(B $BF|K\8l$N%Z!<%8(B $BLs(B 1,010 $B7oCf(B 1 - 10 $B7oL\(B (0.30 $BIC(B) $B!W$C$F8@$o$l$k$7!#(B $B1Q8l$@$H8!:w$r%V%m%C%/$7$F$$$k$1$I!"F|K\8l$@$H(B ok $B$J$N$M(B > google$B!#$C$F!"(B[$B

$B!!(BSophos $B$,(B Troj/LegMir-AE (2005.05.17 19:45:48) $B$H$7$FBP1~$7$^$7$?!#(B $B%9%/%j%W%HItJ,$O(B Troj/Jfor-A (2005.05.18 04:31:50) $B$G$9!#(B $B4\;3$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!!D!D$=$N8e(B:

$B!!(Bhttp://www.princess2.com/phpbb2/index.php $B$d(B http://granadoespada.sub.jp/php/phpbb2/index.php $B$bBP1~$5$l$?$h$&$G$9!#(B

$B!!4XO"JsF;(B:

2005.05.19 $BDI5-(B:

$B!!(B$B%M%C%H?/F~!!>eLS?7J9$b%&%$%k%946@w(B ($BKhF|(B, 5/19)$B!#(B

2005.05.28 $BDI5-(B:

$B!!F1MM;vNc(B:


$B"#(B 2005.05.15


$B"#(B 2005.05.13

$B"#(B *BSD, SCO OpenServer / UnixWare Hyper-Threading Considered Harmful
(daemonology.net, 2005.05.13)

$B!!(B*BSD $B$H(B SCO OpenServer / UnixWare $B$K7g4Y!#(BHyper-Threading $B$r%5%]!<%H$9$k(B CPU ($B%$%s%F%k(B Pentium Extreme Edition, Pentium 4, Mobile Pentium 4, Xeon) $B$K$*$$$F!"FC8"%f!<%6$K$7$+pJs$r(B local $B$N0lHL%f!<%6$,BSDCan 2005 $B$G>\:Y$,8x3+$5$l$k$=$&$@!#(B $B>>_7$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!2sHr$9$k$K$O(B Hyper-Threading $B$rL58z$K$9$l$P$h$$!#(B

2005.05.18 $BDI5-(B:

$B!!$I$&$d$i(B OS $B$K$O0MB8$7$J$$$*OC$@$C$?$h$&$G!D!D!#(B

$B!!$"$H!"(BFreeBSD-SA-05:09.htt [REVISED] $B$H(B SCOSA-2005.24: OpenServer 5.0.7 UnixWare 7.1.4 UnixWare 7.1.3 : Hyper-Threading information leakage $B$,=P$?$N$G!"$3$l$^$G$N5-;v$N$H$3$m$KDI2C$7$F$*$-$^$7$?!#(B

2005.05.30 $BDI5-(B:

$B!!(B$B!V(BOS$B%Y%s%@!<3F (CNET, 2005.05.30)

2005.05.31 $BDI5-(B:

$B!!(BJVNVU#911878: simultaneous multithreading $B%W%m%;%C%5$K$*$1$k5!L)>pJsO31L$N2DG=@-(B

2005.06.02 $BDI5-(B:

$B!!(B101739: Simultaneous Multi-Threading Processors May Leak Information (Sun)$B!#(BSun Solaris $B$G$N$*OC!#(BSolaris 10 $B$K$O(B Zones $B$J$s$F5!G=$,$"$k$N$G$9$+!#(B

$B"#(B $BDI5-(B

$B!V(BFirefox$B!W$KG$0U%3!<%I$,

$B!!:#2s$N7g4Y$,=$@5$5$l$?(B Mozilla 1.7.8 $B$bEP>l$7$F$$$^$9!#(B $B$^$?F|K\8lHG$N(B Firefox 1.0.4 $B$bEP>l$7$F$$$^$9!#(B $B>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B Mozilla 1.7.8 $B$NF|K\8lHG$O!"$^$@$J$$$h$&$@!#(B


$B"#(B 2005.05.12

$B"#(B $B!V%&%$%k%9%;%-%e%j%F%#!W$K$*$1$k%R!<%W%*!<%P!<%U%m!
(IPA, 2005.05.12)

$B!!%=!<%9%M%/%9%H$N(B$B%&%$%k%9%;%-%e%j%F%#(B$B$K7g4Y!#%P!<%8%g%s(B 2.0.0.7 $B0JA0$N!V(Be$B%a!<%k<+F04F;k!W(B(K7EmlPxy.exe) $B$K7g4Y$,$"$j!"(B

$B!!=$@5%b%8%e!<%k$,MQ0U$5$l$F$$$k!#%&%$%k%9%;%-%e%j%F%#$N(B$B%"%C%W%G!<%H5!9=(B$B$r;H$C$F%"%C%W%G!<%H$9$l$P$h$$!#(B

2005.05.18 $BDI5-(B:

$B!!(BLAC SNS $B$+$i>pJs$,8x3+$5$l$^$7$?!#(B

$B"#(B MT $B$K@H
($B?eL57n$P$1$i$N$($SF|5-(B, 2005.05.12)

$B!!(Bblog $B%D!<%k(B Movable Type $B$N(B 3.16 $B$h$jA0$N(B 3.x $B$K7g4Y!#%;%C%7%g%s4IM}$K7g4Y$,$"$j!"Bh;0

$BDL>o$N%;%C%7%g%s%O%$%8%c%C%/$N>l9g!"%?!<%2%C%H$,%m%0%"%&%H$7$F$7$^$($P%5!<%PB&$G(B Cookie $B$,L58z$K$J$j$^$9!#$9$k$H967bl9g$OEpD0$J$j967b$J$j$r$b$&0lEY@.8y$5$;$J$1$l$P$J$j$^$;$s!#$,!"(B Cookie $B$,915WE*$K;H$($l$P967b

$B!!(BMovable Type 3.16 $B$G=$@5$5$l$F$$$k!#(B $BF|K\8lHG$G$"$k(B Movable Type 3.16-ja $B$O(B 6 $B7n>e=\$KEP>l$9$kM=Dj!#(B Movable Type 3.16 Changelog $B$K$O(B

Security
* Made several important improvements with regards to application authentication and security.

$B$H$"$k$,!"K\7o$,$=$N(B 1 $B$D$@$C$?$H$$$&$o$1$+!#(B

$B"#(B $BDI5-(B

$B!V(BFirefox$B!W$KG$0U%3!<%I$,

$B!!:#2s$N7g4Y$,=$@5$5$l$?(B Firefox 1.0.4 $B$,EP>l$7$F$$$^$9(B ($B%j%j!<%9%N!<%H(B)$B!#$7$+$7(B Firefox 1.0.4 $BF|K\8lHG$O;DG0$J$,$i$^$@Ds6!$5$l$F$$$J$$$h$&$G$9!#(B

Microsoft Security Advisories

$B!!F|K\8lHG=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B ($B;n838x3+HG(B) (Microsoft)$B!#(B


$B"#(B 2005.05.11

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B Microsoft Security Advisories
(Microsoft, 2005.05.11)

$B!!(BMicrosoft Security Advisories$B!";n1?E>HG$@$=$&$G!#(B $B:#2s$O(B 2 $B7o(B:

2005.05.12 $BDI5-(B:

$B!!F|K\8lHG=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B ($B;n838x3+HG(B) (Microsoft)$B!#(B

$B"#(B $B!V(BiTunes 4.7$B!W$K(BMPEG-4$B4XO"$N?<9o$J@H
(Internet Watch, 2005.05.10)

$B!!(BiTunes 4.8 $B$h$jA0$NHG$K7g4Y!#(B MPEG4 $B%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k7g4Y$,$"$j!"96N,(B MPEG4 $B%U%!%$%k$K$h$jG$0U$N%3!<%I$rCAN-2005-1248

$B!!(BiTunes 4.8 $B$G=$@5$5$l$F$$$k!#(B Mac OS X $BMxMQ$B%=%U%H%&%'%"%"%C%W%G!<%H(B$B$+$i$bF~301596 - iTunes 4.8: Security enhancements (Apple) $B$K$O!V(Bwhich can be downloaded and installed using Software Update$B!W$HL@5-$5$l$F$$$k$N$@$,!D!D!#(B Ray $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BMac OS X $BMQ!&(BWindows $BMQ6&$K!"(BiTunes 4.8 $BF|K\8lBP1~HG$r(B$B%@%&%s%m!<%I%Z!<%8(B$B$+$iF~

$B"#(B $B!V(BWeb $B$NI=<(!W$N@H
(Microsoft, 2005.05.11)

$B!!(BWindows 2000 $B$K7g4Y!#(B Windows 2000$B$N%(%/%9%W%m!<%i$KG$0U$N%3!<%I$, $B$NOC!#(B CVE: CAN-2005-1191

$B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B $BDI5-(B

$B%H%l%s%I%^%$%/%m!"%Q%?!<%s%U%!%$%kDs6!%5%$%/%k$rEvLL!V7n!"?e!"6b!W$KJQ99(B

$B!!$5$-$[$IFO$$$?%H%l%s%I%^%$%/%m(B Support Information$B!J(B050511$B!K$h$j(B:

2005$BG/(B4$B7n(B29$BF|$+$i!"(B5$B7nCf=\$^$G%Q%?!<%s%U%!%$%k$N%j%j!<%9$r7nMKF|!"?eMKF|!"6bMKF|$H$H$5$;$F$$$?$@$$$F$*$j$^$7$?!#(B
$BEvLL$N4V!"F1%j%j!<%9%9%1%8%e!<%k$r7QB3$9$k$3$H$r$*CN$i$;$$$?$7$^$9!#(B
$B!V(BFirefox$B!W$KG$0U%3!<%I$,

$B"#(B MPSB05-03 - ColdFusion MX 7 cross-site scripting in default error page
(Macromedia, 2005.05.10)

$B!!(BColdFusion MX 7.0 $B$N%G%U%)%k%H(B 404 $B%(%i!<%Z!<%8$K(B XSS $B7g4Y$,$"$k!#(B patch $B$,MQ0U$5$l$F$$$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B In-depth investigation of the "Cabir-in-Cars" myth
(F-Secure, 2005.05.09)

$B!!!V(BBluetooth $B%&%$%k%9$,%H%h%?$N(B Lexus $B$K46@w$9$kEA@b(B$B!W$r8!>Z$9$k$?$a!"(B F-Secure $B$,!"(BLexus $B$HF1MM$N(B Bluetooth $B%7%9%F%`$rAuHw$9$k%H%h%?(B Prius $B$r%F%9%H!#(B

$B!!3$H4(B -42m $B$H$J$kCO2<<<$K%H%h%?(B Prius $B$r1?$SF~$l!"(BCabir.B $B$H(B Cabir.H $B%&%$%k%9$,46@w$9$k$+$I$&$+$r%F%9%H!#46@w$O$7$J$+$C$?$,!"46@w$7$h$&$H(B Cabir $B$,3hF0$9$k$H!"(B Prius $B$N(B Bluetooth $B%7%9%F%`$O(B Bluetooth $B%H%i%U%#%C%/$r

$B!!$5$i$K!"4{CN$N(B Bluetooth $B%"%?%C%/$r

CAUTION:
The transmission [P] lock mechanism is abnormal. Park your car on a flat surface, and fully apply the hand brake.

$B$HI=<($5$l$F$7$^$C$?!#(B $B%F%9%H$r7+$jJV$9$H:F8=$5$l!"$5$i$K7+$jJV$9(B (3 $B2sL\(B) $B$H(B Prius $B$N(B Bluetooth $B%7%9%F%`$O%/%i%C%7%e$7$F$7$^$C$?!#(B $B!D!D$H$$$&$N$O!"

$B!!(BF-Secure $B$O!"$5$i$K(B 1 $B$D$N%^%$%J!<$J7g4Y(B ($BIT@5$JEEOCL>$K$h$j%*%s%\!<%I%G%#%9%W%l%$$,%U%j!<%:$9$k(B) $B$rH/8+$7$?$,!"(B Prius $B$N(B Bluetooth $B%7%9%F%`$O7HBSEEOC$d(B PC $B$h$j$bMZ$+$K0BDj$7$F$$$k$H7kO@$E$1$F$$$k!#(B

$B!!4XO"(B: F-Secure$B!"!V(BCabir$B$,Z(B (ITmedia, 2005.05.10)


$B"#(B 2005.05.10

$B"#(B $B%0!<%0%k$N(BWeb Accelerator$B!"%W%i%$%P%7!<$d%;%-%e%j%F%#$NLdBjB3=P(B
(CNET, 2005.05.09)

$B!!$1$C$-$g$/$N$H$3$m$O!"$$$5$5$+$*9T57$,0-$$(B (?) $B8x3+(B proxy $B$J$o$1$G!D!D!#(B $B5$$K$J$k>l9g$O(B Web Accelerator $B%[%9%H(B ($B$C$F$I$3(B?) $B$X$N%"%/%;%9$r6X;_$7$?J}$,$h$$$+$b!#$^$?(B Web Accelerator $B%[%9%H$+$i$N%"%/%;%9$r6X;_$7$?$$>l9g$b$"$k$G$7$g$&$M!#(B

$B!!(BWeb Accelerator $B$N%Z!<%8(B$B$r8+$k$H!"!V(BWe have currently reached our maximum capacity of users and are actively working to increase the number of users we can support$B!W$H=q$+$l$F$$$k$J$"(B (11:05 AM)$B!#(B


$B"#(B 2005.05.09

$B"#(B $BJF(BApple$B$,(BMac OS X$BMQ%;%-%e%j%F%#=$@5$r8x3+!$!V$9$Y$F$N%f!<%6!<$,E,MQ$r!W(B
($BF|7P(B IT Pro, 2005.05.06)

$B!!(BSecurity Update 2005-005 $B$,=P$?$N$GE,MQ$7$^$7$g$&OC!#4XO"(B:

$B!!(BCVE $B$H$+(B:

$B!!$J$*!"(BCAN-2005-1271 (iDEFENSE Security Advisory 05.04.05: Apple Mac OS X vpnd Server_id Buffer Overflow Vulnerability) $B$O!"(BApple $BE*$K$O(B Mac OS X 10.3.9 $B$G=$@5$7$F$$$k$3$H$K$J$C$F$$$k$N$+$J!#(B

$B"#(B Tiger$B!'0-0U$N$"$k%5%$%H$,>!
($B1|B<@2I'$N(BWiki, 2005.05.09)

$B!!(BMac OS X 10.4 'Tiger' $B>e$N(B Safari $B$K7g4Y!#96N,(B web $B%Z!<%8$K%"%/%;%9$9$k$H!"(B $B%@%C%7%e%\!<%I%&%#%8%'%C%H$,<+F0E*$K%@%&%s%m!<%I$5$l!"$5$i$K<+F0E*$K%$%s%9%H!<%k$5$l$F$7$^$&!#(B

$B!!=$@5HG$O$^$@$J$$!#2sHr$9$k$K$O!"(BSafari $B$N4D6-@_Dj$G!V%@%&%s%m!<%I8e!$(B"$B0BA4$J(B"$B%U%!%$%k$r3+$/!W$N%A%'%C%/$r30$9!#(B $BI8=`$G$O%A%'%C%/$,F~$C$F$$$k$N$GCm0U!#(B

$B!!1|B<$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2005.05.21 $BDI5-(B:

$B!!(BMac OS X 10.4.1 $B$G=$@5$5$l$?$h$&$G$9!#(B About the security content of the Mac OS X 10.4.1 Update $B$b;2>H!#(B

$B"#(B $B!V(BFirefox$B!W$KG$0U%3!<%I$,
($BAk$NEN(B, 2005.05.09)

$B!!$3$N$"$?$j$NOC!#G$0U$N%3!<%I$r

$B!!=$@5HG$O$^$@$J$$!#2sHr$9$k$K$O(B JavaScript $B$rL58z$K$9$k!#(B

2005.05.11 $BDI5-(B:

2005.05.12 $BDI5-(B:

$B!!:#2s$N7g4Y$,=$@5$5$l$?(B Firefox 1.0.4 $B$,EP>l$7$F$$$^$9(B ($B%j%j!<%9%N!<%H(B)$B!#$7$+$7(B Firefox 1.0.4 $BF|K\8lHG$O;DG0$J$,$i$^$@Ds6!$5$l$F$$$J$$$h$&$G$9!#(B

2005.05.13 $BDI5-(B:

$B!!:#2s$N7g4Y$,=$@5$5$l$?(B Mozilla 1.7.8 $B$bEP>l$7$F$$$^$9!#(B $B$^$?F|K\8lHG$N(B Firefox 1.0.4 $B$bEP>l$7$F$$$^$9!#(B $B>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B Mozilla 1.7.8 $B$NF|K\8lHG$O!"$^$@$J$$$h$&$@!#(B

2005.05.21 $BDI5-(B:

$B!!(BMozilla 1.7.8 $BF|K\8lHG$,EP>l$7$F$$$^$9!#>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $BDI5-(B

FreeBSD $B$K(B 3 $B$D$N7g4Y(B

$B!!(BFreeBSD-SA-05:08.kmem [REVISED] $B$,=P$F$$$^$9!#(BRELENG_4_11 $B$GHf3S$9$k$H!"(B $B?7$?$K(B src/sys/kern/uipc_usrreq.c $B$H(B src/sys/netinet/tcp_subr.c $B$,=$@5$5$l$F$$$^$9!#(B $B5lHG$K=>$C$F(B kernel $B$r99?7$7$??M$O!"$^$?$^$?(B kernel $B$r99?7$9$kI,MW$,$"$k$h$&$G$9!#(B


$B"#(B 2005.05.08

$B"#(B $BDI5-(B

FreeBSD $B$K(B 3 $B$D$N7g4Y(B

$B!!(BFreeBSD-SA-05:06.iir - Incorrect permissions on /dev/iir [REVISED] $B$,=P$F$$$^$9!#(B

$B"#(B phpBB 2.0.15 released
(phpbb.com, 2005.05.08)

$B!!(BphpBB 2.0.15 $B=P$^$7$?!#=EBg$J%;%-%e%j%F%#7g4Y$N=$@5$r4^$`$=$&$G$9!#(B phpBB 2.0.14 $B0JA0$rMxMQ$7$F$$$k>l9g$O!"$H$j$$$=$.!"<($5$l$F$$$kJQ99$r;\$7$F$/$@$5$$(B (phpBB 2.0.15 $B$G$OJQ99:Q$G$9(B)$B!#(B


$B"#(B 2005.05.07

$B"#(B Ethereal 0.10.11 released
(ethereal.com, 2005.05.04)

$B!!(BEthereal 0.10.11 $BEP>l!#(B0.10.10 $B0JA0$K$"$C$?J#?t$N7g4Y$,=$@5$5$l$F$$$k!#(B enpa-sa-00019: Multiple problems in Ethereal versions 0.8.14 to 0.10.10 (ethereal.com) $B$b;2>H!#(B CVE: CAN-2005-1456 CAN-2005-1457 CAN-2005-1458 CAN-2005-1459 CAN-2005-1460 CAN-2005-1461 CAN-2005-1462 CAN-2005-1463 CAN-2005-1464 CAN-2005-1465 CAN-2005-1466 CAN-2005-1467 CAN-2005-1468 CAN-2005-1469 CAN-2005-1470

$B!!4XO"(B:


$B"#(B 2005.05.06

$B"#(B Moodle Security Center: Security bug with admin/delete.php
(moodle.org, 2005.05.06)

$B!!(Be-Learning $B%=%U%H(B Moodle $B$N(B 1.4.2 $B0JA0(B $B:G?7%j%j!<%9(B 1.4.4 $B$d3+H/HG(B 1.5dev $B$r4^$`A4%P!<%8%g%s$K7g4Y!#0-0U$"$kMxMQ

$B!!(Badmin/delete.php $B$r:o=|$9$k$3$H$G$3$N7g4Y$r2sHr$G$-$k!#(B $B$^$?!"(BMoodle 1.4.3 $B$G=$@5$5$l$F$$$k!#(B $B:G?7$N(B CVS $BHG$G$O=$@5$5$l$F$$$k!#(B

$B!!1|B<$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $B%H%l%s%I%^%$%/%m!"%Q%?!<%s%U%!%$%kDs6!%5%$%/%k$rEvLL!V7n!"?e!"6b!W$KJQ99(B
(ITmedia, 2005.05.06)

$B!!CN$i$J$+$C$?$>!D!D!#(B$BBg7?O"5Y4|4V!J(B4/29$B!A(B5/8$B!K$K$*$1$k!"%H%l%s%I%^%$%/%m@=IJ$N%Q%?!<%s%U%!%$%k%"%C%W%G!<%H$K4X$9$k$40FFb(B ($B%H%l%s%I%^%$%/%m(B) $B$h$j(B:

$B$3$N$?$a!"(B2005$BG/(B4$B7n(B29$BF|$h$j!"%Q%?!<%s%U%!%$%k$N%j%j!<%9!J"((B2$B!K$r7nMKF|!"?eMKF|!"6bMKF|$XJQ99$7!"IJe$KEX$a$F$^$$$j$^$9!#%W%m%;%92~A1$N7k2L$KLdBj$,L5$$$HH=CG$$$?$7$^$7$?;~E@!J(B5$B7nCf=\$rL\=h!K$G!"B.$d$+$KDL>o$N%j%j!<%9%5%$%/%k$NBN@)$r@0$(%Q%?!<%s%U%!%$%k$r%j%j!<%9$5$;$F$$$?$@$-$^$9!#(B

$B"((B2$B!!%&%$%k%9%"%i!<%H$NH/Na$J$I$N>l9g$K$O!"$3$N8B$j$G$O$4$6$$$^$;$s!#(B

$B!!$3$&$$$&OC$O!"JL$N%5%]!<%H>pJs$K$9$k$Y$-$@$H;W$&$1$I$J$"!D!D!#(B $BBg7?O"5Y4|4V$H4X78$J$$$8$c$s!#(B

2005.05.11 $BDI5-(B:

$B!!$5$-$[$IFO$$$?%H%l%s%I%^%$%/%m(B Support Information$B!J(B050511$B!K$h$j(B:

2005$BG/(B4$B7n(B29$BF|$+$i!"(B5$B7nCf=\$^$G%Q%?!<%s%U%!%$%k$N%j%j!<%9$r7nMKF|!"?eMKF|!"6bMKF|$H$H$5$;$F$$$?$@$$$F$*$j$^$7$?!#(B
$BEvLL$N4V!"F1%j%j!<%9%9%1%8%e!<%k$r7QB3$9$k$3$H$r$*CN$i$;$$$?$7$^$9!#(B

$B"#(B $BDI5-(B

NISCC Vulnerability Advisory ICMP - 532967: Vulnerability Issues in ICMP packets with TCP payloads

$B!!(BSYM05-008: $B%7%^%s%F%C%/$N%;%-%e%j%F%#!&%2!<%H%&%'%$(B ICMP $B$K%5!<%S%95qH]$N4m81@-(B ($B%7%^%s%F%C%/(B, 2005.05.02)$B!#(B $B0J2<$N%7%^%s%F%C%/@=IJ$K7g4Y$,$"$k$=$&$@!#(B

Symantec Gateway Security 5400 Series, v2.x
Symantec Gateway Security 5300 Series, v1.0
Symantec Enterprise Firewall, v7.0.x $B!J(BWindows $BHG$*$h$S(B Solaris $BHG!K(B
Symantec Enterprise Firewall v8.0 $B!J(BWindows $BHG$*$h$S(B Solaris $BHG!K(B
Symantec VelociRaptor, Model 1100/1200/1300 v1.5
Symantec Gateway Security 300 Series $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Symantec Gateway Security 400 Series $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Symantec Firewall/VPN Appliance 100/200/200R $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Nexland ISB SOHO Firewall Appliances $B!J$9$Y$F$N%U%!!<%`%&%'%"(I%$B%P!<%8%g%s!K(B
Nexland Pro Series Firewall Appliances

$B!!$3$N$&$A=$@5HG$,$"$k$N$O(B Symantec Gateway Security 300 Series$B!"(BSymantec Gateway Security 400 Series $B$@$1$G!"B>$K$D$$$F$O3+H/Cf$@$=$&$@!#(B

$B"#(B Alert: "swapfile is infected with Hacktool.Underhand"
(symantec, 2005.05.05)

$B!!(BMac $BHG(B Norton AntiVirus $B$G!V(Bswapfile $B$,(B Hacktool.Underhand $B$K46@w$7$F$$$k!W$H$$$&8m8!=P$,!"r7o$GH/@8$9$kLOMM!#(B

$B!!$3$N$H$-!V3VN%!W$rA*Br$9$k$H(B kernel panic $B$7$F$7$^$&(B ($B$=$j$c$=$&$@$m$&(B)$B!#(B

$B!!%&%$%k%9Dj5A%U%!%$%k$r99?7$9$k$3$H$GBP1~$G$-$k$=$&$@!#(B

$B!!$J$*!"!V3VN%!W$7$?%U%!%$%k$OLa$5$:$=$N$^$^:o=|$7$^$7$g$&!"$@$=$&$@!#(B $B$^$?(B Norton AntiVirus for Macintosh 7.x + Mac OS 9 $B$NAH$_$"$o$;$G$O$3$N8m8!=P$OH/@8$7$J$$$=$&$@!#(B

$B!!KLEg$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B
(Microsoft, 2005.05.06)

$B!!(BOS $BItJ,$G!V=EMW!W$,(B 1 $B7o!"$@$=$&$G$9!#(B

$B"#(B FreeBSD $B$K(B 3 $B$D$N7g4Y(B
(FreeBSD-security ML, 2005.05.06)

$B!!:G?7$N(B RELENG_4, RELENG_4_10, RELENG_4_11, RELENG_5, RELENG_5_3, RELENG_5_4 $B$G$O=$@5$5$l$F$$$k!#$^$?!"$^$b$J$/%j%j!<%9$5$l$k$O$:$N(B 5.4-RELEASE $B$K$O$3$l$i$N7g4Y$O$J$$!#(B

2005.05.06 $BDI5-(B:

$B!!(BFreeBSD-SA-05:08.kmem $B$G<($5$l$F$$$k(B patch $B$OJQ$@!"$H$$$&;XE&$,(B: Re: FreeBSD Security Advisory FreeBSD-SA-05:08.kmem$B!#(B

2005.05.08 $BDI5-(B:

$B!!(BFreeBSD-SA-05:06.iir [REVISED] $B$,=P$F$$$^$9!#(B

2005.05.09 $BDI5-(B:

$B!!(BFreeBSD-SA-05:08.kmem [REVISED] $B$,=P$F$$$^$9!#(BRELENG_4_11 $B$GHf3S$9$k$H!"(B $B?7$?$K(B src/sys/kern/uipc_usrreq.c $B$H(B src/sys/netinet/tcp_subr.c $B$,=$@5$5$l$F$$$^$9!#(B $B5lHG$K=>$C$F(B kernel $B$r99?7$7$??M$O!"$^$?$^$?(B kernel $B$r99?7$9$kI,MW$,$"$k$h$&$G$9!#(B


$B"#(B 2005.05.05


$B"#(B 2005.05.04


$B"#(B 2005.05.03

$B"#(B $BDI5-(B

$BEE;R?=@A(B $B9T@/%=%U%H$KIT6q9g(B

$B!!(B$BEE;R?=@A%7%9%F%`$NE@8!;X<((B (NHK, 2005.04.29)$B!#$9$G$K>C$($F$7$^$C$F$$$k(B (T_T) $B$N$G!"0J2<$KA4J80zMQ$5$;$F$$$?$@$-$^$9!#(B

$BAmL3>J$O9T@/$,7g4Y$N$"$k%=%U%H$rG[I[$7$F$$$?$3$H$OLdBj$@$H$7$F!"A49q$N<+<#BN$KBP$7!"F1$8$h$&$J7g4Y$N$"$k%=%U%H$rG[I[$7$F$$$J$$$+$I$&$+Mh7n#1#3F|$^$G$KE@8!$9$k$h$&;X<($7$^$7$?!#$^$?!"Fb3U41K<>pJs%;%-%e%j%F%#!<%;%s%?!<$G$b3F>JD#$KBP$7!"A49q$N=P@h5!4X$,;H$C$F$$$kEE;R?=@A%=%U%H$N0BA4@-$rE@8!$9$k$h$&;X<($7$^$7$?!#(B

$B!!$^$@A4$F$NBP1~$,=*$C$?$o$1$G$O$J$$!"$H$$$&$3$H$J$s$G$7$g$&$+!#(B $B$=$N3d$K$O!"$$$m$s$J<+<#BN$,>!pJs$r=P$7$F$7$^$C$F$$$F!"$J$+$J$+%"%l$J5$$,$7$^$9!#(B $B%$%s%7%G%s%HBP1~

$B!!$H$3$m$G!"(B$B%=%U%H%&%(%"Ey$N@HpJs$K4X$9$kFO=P>u67(B [2005$BG/Bh(B1$B;MH>4|!J(B1$B7n!A(B3$B7n!K(B] (IPA ISEC) $B$K$3$s$JJ8>O$,$"$k$N$G$9$,!"(B

2005$BG/Bh(B1$B;MH>4|$NFO=P;vNc$H$7$F!"(BJava$B%"%W%j%1!<%7%g%s!J(BJava$B%"%W%l%C%H!K$N%$%s%9%H!<%k%W%m%0%i%`Ey$,%$%s%9%H!<%k;~$K%/%i%$%"%s%H(BPC$B$N(BJava$B4D6-$N%;%-%e%j%F%#%]%j%7!<$r=q49$($F$7$^$$!"7k2L$H$7$F!"%/%i%$%"%s%H(BPC$B$N%;%-%e%j%F%#%l%Y%k$rDc2<$5$;$F$7$^$&!"$H$$$&$b$N$,J#?t$"$j$^$7$?!#(B(7)
$BCfN,(B
(7) $B$3$l$i$O!"%/%i%$%"%s%H(BPC$B$K%$%s%9%H!<%k$9$k%=%U%H%&%(%"$G$9$,!"%&%'%V%"%W%j%1!<%7%g%s$r;H$&$?$a$N$b$N$G$"$j!"$=$N%&%'%V%"%W%j%1!<%7%g%s$HFHN)$7$F5/F0$5$l!";HMQ$5$l$k$b$N$G$O$J$$$?$a!"%&%'%V%"%W%j%1!<%7%g%s$N0lIt$H$7$FB*$(!"%&%'%V%"%W%j%1!<%7%g%s$N@HpJs$NFO=P$H$7$F

$B%;%-%e%j%F%#LdBj$N>\:Y@bL@(B ($B$d$^$J$7?=@A!&M=Ls%]!<%?%k%5%$%H(B) $B$K(B

$B!!(B2005$BG/(B2$B7n(B16$BF|$N(B10$B;~(B33$BJ,$K!"(BIPA$B!JFHN)9T@/K!?M>pJs=hM}?d?J5!9=!K$N%;%-%e%j%F%#%;%s%?$+$i!"(Be-$B$d$^$J$7%5%]!<%H%;%s%?08$K!V$d$^$J$7?=@A!&M=Ls%]!<%?%k%5%$%H!W$N!V$*;H$$$N(BPC$B$N@_Dj!W(B-$B!V%f!<%6@_Dj%U%!%$%k!W$G%U%!%$%k$NAH$_9~$_$r9T$C$?>l9g!"%;%-%e%j%F%#>e$NLdBj$,@8$8$k2DG=@-$,$"$k$H$$$&$4;XE&$rD:$-$^$7$?!#(B
($BCfN,(B)
$B%;%-%e%j%F%#LdBj(B
$B!!EE;R?=@A%5!<%S%9$NEE;R=pL>$r9T$&>l9g$K$O!"$*;H$$$N%Q%=%3%s>e$K$"$k;q8;!J=pL>$KI,MW$J%U%!%$%kEy!K$NMxMQ$r9T$&$?$a$K!"%f!<%6@_Dj%U%!%$%k$NAH$_9~$_$r9T$C$F$$$?$@$$$F$$$^$9!#(B
$B!!$=$N%f!<%6@_Dj%U%!%$%k$N(B1$B$D$H$7$F!"!V(Bjava.policy$B!W%U%!%$%k$NAH$_9~$_$r9T$C$F$$$?$@$$$F$$$^$9$,!"(B2005$BG/(B2$B7n(B16$BF|0JA0$N!V(Bjava.policy$B!W%U%!%$%k$N5-=RFbMF$K8m$j$,$"$j$^$7$?!#(B
$B!!(B2005$BG/(B2$B7n(B16$BF|0JA0$K%f!<%6@_Dj%U%!%$%k$NAH$_9~$_$r9T$C$?%Q%=%3%s$G!"0-0U$N$"$k%5%$%H$rK,$l$?>l9g$K!"%f!<%6L>!"%m!<%+%k%U%!%$%k$NEp$_=P$7!&GK2u!"G$0U%3!<%I$N

$B$H$"$k$N$G!"$3$l$,$=$NOC$J$s$8$c$J$$$N$+$J!<$H$$$&5$$,$7$^$9!#(B

$B!!$7$+$7$3$NOC$N>l9g!"1F6AHO0O$,Ev3:(B web $B%5%$%H$K8B$i$l$k$o$1$G$O$J$$$N$G$9$+$i!"!V%&%'%V%"%W%j%1!<%7%g%s$N@HpJs$NFO=P$H$7$F


$B"#(B 2005.05.02

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B SMS SMTP 4.1.4 $B%S%k%I(B 30 $B$rF3F~$9$k$H(B CPU $B;HMQN($,(B 100% $B$K$J$k(B
($B%7%^%s%F%C%/(B, 2005.05.02)

$B!!(BSymanatec Mail Security for SMTP (SMS SMTP) 4.1.4 $B%S%k%I(B 30 $B$G!"(B $B!V$"$kFCDj$NF|K\8l$G5-=R$5$l$?EE;R%a!<%k$r

$B"#(B PKI$B$h$/$"$k4*0c$$(B(9)$B!V!X>\:Y@_Dj!Y%\%?%s$G>ZL@=q$N;HMQL\E*$r@)8B$G$-$k!W(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2005.04.10)

$B!!0J2<$K$D$$$F$O!":#$@$KD>$C$F$$$J$$$h$&$G$9!#(B

$B!!(BMS $B$N(B UI $B$,$o$+$j$K$/$9$.!"$H$$$&OC$O$"$j$^$9$,!D!D!#(B

$B"#(B $BDI5-(B

Google$B$N%9%Z%k%_%90-MQ%5%$%H!"%"%/%;%9$9$k$H(BPC$B>h$C

$B!!(BHandler's Diary April 30th 2005 (SANS ISC) $B$K$h$k$H!"Ev3:%I%a%$%s$N(B DNS $B%(%s%H%j$,:o=|$5$l$?LOMM!#(B googkle.com $B$NB>$K$b$$$m$$$m$"$C$?$_$?$$$G$9!#(B

$B"#(B $BFCDj$N%O!<%I%G%#%9%/$rEk:\$9$k(BHP xw Workstation$B%7%j!<%:$G(BOS$B$N5/F0;~$dF0:nCf$K%O%s%0%"%C%WEy$,H/@8$9$k$3$H$,$"$j$^$9(B
(HP, 2005.04.28)

$B!!(BHP Workstation xw4100, 4200, 5000, 6000, 6200, 8000, 8200 $B$KEc:\$5$l$F$$$k(B SCSI HDD $B$K7g4Y$,$"$j!"5/F0$G$-$J$+$C$?$j%V%k!<2hLL$K$J$C$?$j$9$k!#(B

$B!!%O!<%I%G%#%9%/$N%U%!!<%`%&%'%"$r99?7$9$k$3$H$GBP1~$G$-$k!#(B $B99?7%D!<%k(B (HP) $B$,8x3+$5$l$F$$$k!#(B

$B!!(B$B99?7%D!<%k$N%Z!<%8(B$B$K$h$k$H!"(B $BLdBj$N(B SCSI HDD $B$O(B Seagate Cheetah 10K.6 $B$H(B 15K.3 $B$@$=$&$G!#$3$l$+(B?: Ultra 320 Time-Out Firmware Upgrade (Seagate)$B!#(B


$B"#(B 2005.05.01

$B"#(B $BDI5-(B

mixi$B$K(BCSRF$B@H

$B!!(B$B%/%m%9%5%$%H%j%/%(%9%H%U%)!<%8%'%j!J(BCSRF$B!K$N@5$7$$BP:vJ}K!(B ($B9bLZ9@8w!w<+Bp$NF|5-(B, 2005.04.27)

$B%a%G%#%"!&#J#R$J$I#L#A#N>c32!"%&%$%k%9BP:v$GIT6q9g(B

$B!!4XO"5-;v(B:


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B