$B%;%-%e%j%F%#%[!<%k(B memo - 2005.09

Last modified: Wed Feb 15 11:32:43 2006 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2005.09.30

$B"#(B JVN#31226748: $BJ#?t$N%&%'%V%V%i%&%6$K$*$$$F%j%/%(%9%HJ,3d967b$,2DG=$J@H
(JVN, 2005.09.29)

$B!!(BXMLHttpRequest $B%X%C%@$N56Au(B $B$N7o$@$H;W$&(B ($B!V$3$NLdBj$O(B Tim Altman $B;a$H(B Yutaka Oiwa $B;a$K$h$C$F8DJL$KJs9p$5$l$^$7$?!W$H$"$k$7(B) $B$N$G$9$,!"6=L#?<$$$N$O!"(B

$B%^%$%/%m%=%U%H!!!!(B$B3:Ev@=IJ$J$7(B$B!!!!(B2005/09/29

$B$G$9$M!#8=$BN`;w$N7g4Y$NB8:_$,;XE&$5$l$F$$$k(B (ITmedia) $B$o$1$G$9$,!D!D!#(B

$B!!$"$H!"(BOpera 8.02 $B0JA0$K$b$3$N7g4Y$,$"$k(B (Opera) $B$=$&$G!":G?7HG$N(B Opera $B$K%"%C%W%0%l!<%I$7$^$7$g$&!"$@$=$&$G$9!#(B


$B"#(B 2005.09.29


$B"#(B 2005.09.28

$B"#(B $BDI5-(B

Firefox 1.0.7 Release Notes

$B!!(BMozilla Suite 1.7.12 $BF|K\8lHG$,=P$F$$$^$9!#(B mozilla-japan.org $B$J$I$+$i$I$&$>!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $B%=%K!<(BPSP$B$N@E;_2h%G!<%?I=<(5!G=$K%;%-%e%j%F%#!&%[!<%k(B
($BF|7P(B IT Pro, 2005.09.27)

$B!!(BSony PSP Photo Viewer TIFF File Handling Buffer Overflow (secunia) $B$+$i$?$I$l$k(B 2.0 Overflow Found and Working (pspupdates.qj.net) $B$r$_$k$H96N,

$B!VDL>o$N;HMQ$G$O1F6A$r

$B$H$$$&$N$O!"0l7b$G$d$i$l$k$3$H$O$J$$$H$$$&0UL#$G$O$=$&$J$N$@$m$&!#(B

$B!!=$@5HG%U%!!<%`%&%'%"$N8x3+$,M=Dj$5$l$F$$$k$b$N$N!"M=Dj$OL$Dj$N$h$&$@!#(B

$B"#(B RealPlayer$B$H(BHelix Player$B$KG$0U$N%3!<%I$r
($BF|7P(B IT Pro, 2005.09.28)

$B!!(BAn open security advisory #13 - RealPlayer and Helix Player Remote Format String Exploit (open-security.org) $B$NOC!#(B Linux / UNIX $BHG(B RealPlayer / Helix Player $B$K7g4Y$,H/8+$5$l$?LOMM!#(B .rp (relpix) $B$*$h$S(B .rt (realtext) $B%U%!%$%k$N=hM}$K(B format $B%P%0$,$"$j!"(B $B96N,(B .rp / .rt $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$re$N(B RealPlayer 10.0.5.756 Gold $B$G3NG'$7$?$H$7$F$$$k!#(B RealNetworks $B$+$i$N@5<0$JH/I=$O$^$@$J$$!#(B

$B!!4XO"(B:


$B"#(B 2005.09.27

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B [SA16935] Qpopper poppassd Insecure Trace File Creation Vulnerability
(secunia, 2005.09.27)

$B!!(BQpopper 4.0.8 $B0JA0$K7g4Y!#(BQpopper $B$K4^$^$l$k(B poppassd $B$r:n@.!&%$%s%9%H!<%k$7$?>l9g(B ($B%G%U%)%k%H$G$O:n@.$7$J$$(B)$B!"(BQpopper $B$N%G%U%)%k%H$G$O(B poppassd $B$O(B suid root $B$G%$%s%9%H!<%k$5$l$k!#$3$N>l9g$K!"(B-t $B%*%W%7%g%s$N=hM}$K7g4Y$,$"$j!"(B local user $B$,(B root $B8"8B$r

$B!!(B$B85$M$?(B$B$K$O(B FreeBSD $BMQ$N(B exploit $B$J$k$b$N$,E:IU$5$l$F$$$k$,!"(B FreeBSD $B$N(B ports $B$+$i(B WITH_POPPASSD=yes $B$G%$%s%9%H!<%k$7$?>l9g$K$O!"(Bpoppassd (qpoppassd) $B$O(B suid root $B$G$O%$%s%9%H!<%k$5$l$J$$$N$G!"$3$N7g4Y$O1F6A$7$J$$$O$:!#(B $B$b$7(B suid root $B$K$J$C$F$$$k$h$&$J$i!"(Bsuid root $B$r$H$C$Q$i$C$F$7$^$($P$h$$!#(B


$B"#(B 2005.09.26


$B"#(B 2005.09.25

$B"#(B $BDI5-(B

JVN#62914675: Ruby $B$K$*$$$F%;!<%U%l%Y%k(B 4 $B$,%5%s%I%\%C%/%9$H$7$F5!G=$7$J$$@H

$B!!4XO"(B:


$B"#(B 2005.09.23

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

$B=;L1L14pK\BfD"%+!<%IMQ$N%/%i%$%"%s%H%=%U%H$rG[I[$9$k$H(B Path $B4D6-JQ?t$,>C$($k(B

$B!!%*%U%#%7%c%k>pJs$h$&$d$/EP>l(B: $BMxMQ ($B8xE*8D?MG'>Z%5!<%S%9(B $B%]!<%?%k%5%$%H(B, 2005.09.20)$B!#(B $BF?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!MW$O!"4D6-JQ?t$NJ8;zNsD9$rL5;k$7$?%=!<%9$@$C$?$H$$$&$3$H$G$9$J!"$3$l$O!#(B $B$*$^$1$K!"(B$BMxMQ$B$G$O>u67$H2sHrJ}K!$N@bL@$K=*;O$7$F$*$j!"=$@5HG$rMQ0U$7$FBP1~$9$k$D$b$j$,A4$/$J$$$h$&$@!#(B

$B!!$$$d$O$d!"!V$5$9$,EE;R@/I\!W$H$7$+8@$$$h$&$,$"$j$^$;$s$J!#(B $B%V%i%\!

Firefox 1.0.7 Release Notes

$B!!(BFirefox 1.0.7 / Mozilla 1.7.12 $B$G=$@5$5$l$?7g4Y(B:

$B!!96N,%3!<%I(B:


$B"#(B 2005.09.22

$B"#(B $BDI5-(B

Firefox 1.0.7 Release Notes

$B!!(BLinux/UNIX$BMQ(BMozilla$B$K$b4m81$J@H (Internet Watch, 2005.09.22) $B$@$=$&$G$9!#(B

SYM05-014: VERITAS Storage Exec DCOM Server Buffer Overflows

$B!!(BSYM05-014: VERITAS Storage Exec DCOM $B%5!<%P!<$K%P%C%U%!(B $B%*!<%P!<%U%m!<$N@H ($B%7%^%s%F%C%/(B)$B!#(BStorageCentral 5.2 ($B$NF|K\8lHG(B) $B$K$D$$$F$O!V(BStorage Exec 5.3 $B$X%"%C%W%0%l!<%I$7!"$9$Y$F$N:G?7$N(B Hotfix $B$r%$%s%9%H!<%k$7$F$/$@$5$$!W$H=q$+$l$F$$$^$9$M!#(B


$B"#(B 2005.09.21

$B"#(B Infected files found on mozilla site
(viruslist.com Analyst's Diary, 2005.09.20)

$B!!(Bmozilla-1.7.6.ko-KR.linux-i686.installer.tar.gz $B$H(B thunderbird-1.0.2.tar.gz $B$H$K!"(BLinux.RST.B $B%&%$%k%9$K46@w$7$?%P%$%J%j$,4^$^$l$F$$$?!"$H$$$&OC!#(B

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

[Clamav-announce] announcing ClamAV 0.87

$B!!(B[SA16848] ClamAV UPX and FSG Handling Vulnerabilities

JVN#40940493: Webmin $B$*$h$S(B Usermin $B$K$*$1$kG'>Z2sHr$N@H

$B!!(B SNS Advisory No.83: Webmin/Usermin PAM Authentication Bypass Vulnerability (LAC)

$B"#(B Opera 8.50 for Windows Changelog
(Opera, 2005.09.20)

$B!!(BOpera 8.50 $BEP>l!#(B$B9-9p%P%J!<$,>CLG(B$B$7$?B>!"(BOpera Mail Client Attachment Spoofing and Script Insertion $B$J$I%;%-%e%j%F%#4XO"$N=$@5$b4^$^$l$F$$$k$=$&$J!#(B

$B"#(B Firefox 1.0.7 Release Notes
(mozilla.org, 2005.09.21)

$B!!(BFirefox 1.0.7 $BEP>l!#(BIDN $B7g4Y(B$B$d(B $B%3%^%s%I%i%$%sMxMQ;~$N7g4Y(B (SA16869) $B$N=$@5$NB>$K$b$$$m$$$mD>$C$F$k$C$]$$$N$@$,!"(BKnown Vulnerabilities in Mozilla Products $B$K$O$^$@(B 1.0.7 $B$N>pJs$O$J$$!#(B

2005.09.22 $BDI5-(B:

$B!!(BLinux/UNIX$BMQ(BMozilla$B$K$b4m81$J@H (Internet Watch, 2005.09.22) $B$@$=$&$G$9!#(B

2005.09.23 $BDI5-(B:

$B!!(BFirefox 1.0.7 / Mozilla 1.7.12 $B$G=$@5$5$l$?7g4Y(B:

$B!!96N,%3!<%I(B:

2005.09.28 $BDI5-(B:

$B!!(BMozilla Suite 1.7.12 $BF|K\8lHG$,=P$F$$$^$9!#(B mozilla-japan.org $B$J$I$+$i$I$&$>!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B JVN#62914675: Ruby $B$K$*$$$F%;!<%U%l%Y%k(B 4 $B$,%5%s%I%\%C%/%9$H$7$F5!G=$7$J$$@H
(JVN, 2005.09.21)

$B!!(BRuby 1.6.8 $B0JA0$N(B 1.6.x / 1.8.2 $B0JA0$N(B 1.8.x / 2005-09-01$BHG0JA0$N(B 1.9.0 $B$K7g4Y!#(B Ruby $B$N%;%-%e%j%F%#%b%G%k(B$B$N$R$H$D!V%;!<%U%l%Y%k!W$rE,MQ$7$?>l9g$KH/@8$9$k@)8B$r2sHr$7$F!"G$0U$N%3!<%I$r

$B!!3FHG$K$*$1$kBP1~$O0J2<$N$H$*$j!#(B

2005.09.25 $BDI5-(B:

$B!!4XO"(B:

$B"#(B SYM05-014: VERITAS Storage Exec DCOM Server Buffer Overflows
(Symantec, 2005.09.19)

$B!!(BVERITAS Storage Exec 5.3 $B0JA0!"$*$h$S(B StorageCentral 5.2 $B0JA0$K7g4Y!#(B DCOM $B%5!<%P$,(B ActiveX $B7PM3$G8F$P$l$?>l9g$K(B buffer overflow $B$9$k$?$a!"(B $B96N,(B web $B%5%$%H$K%"%/%;%9$9$k$HG$0U$N%3!<%I$,

$B!!(BVERITAS Storage Exec 5.3 $B$O(B Hotfix 9 $B$G!"(B StorageCentral 5.2 $B$O(B Hotfix Q323003.ism Hot Fix 2 $B$GBP1~$5$l$F$$$k!#(B $B3F(B hotfix $B$N%Z!<%8$G$O(B Languages: English (US), Japanese $B$H$J$C$F$$$k$+$i!"F|K\8lHG$K$bE,MQ$G$-$k$N$+$J(B?

2005.09.22 $BDI5-(B:

$B!!(BSYM05-014: VERITAS Storage Exec DCOM $B%5!<%P!<$K%P%C%U%!(B $B%*!<%P!<%U%m!<$N@H ($B%7%^%s%F%C%/(B)$B!#(B StorageCentral 5.2 ($B$NF|K\8lHG(B) $B$K$D$$$F$O!V(BStorage Exec 5.3 $B$X%"%C%W%0%l!<%I$7!"$9$Y$F$N:G?7$N(B Hotfix $B$r%$%s%9%H!<%k$7$F$/$@$5$$!W$H=q$+$l$F$$$^$9$M!#(B


$B"#(B 2005.09.20

$B"#(B JVN#40940493: Webmin $B$*$h$S(B Usermin $B$K$*$1$kG'>Z2sHr$N@H
(JVN, 2005.09.20)

$B!!(BWebmin 1.220 $B0JA0(B / Usermin 1.150 $B0JA0$K7g4Y!#(BAuthentication $B%Z!<%8$G(B Support full PAM conversations? $B$rM-8z$K$7$F$$$?>l9g$K7g4Y$,$"$j!"(B remote $B$+$i(B root $B8"8B$GG$0U$N%3%^%s%I$r

$B!!(BWebmin 1.230 / Usermin 1.160 $B$G=$@5$5$l$F$$$k!#(B

2005.09.21 $BDI5-(B:

$B!!(B SNS Advisory No.83: Webmin/Usermin PAM Authentication Bypass Vulnerability (LAC)

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $B8m2r$5$l$k!V<+F0E*$K%@%$%"%m%0$rI=<(!W$N0UL#(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2005.09.18)

$B!!$3$N@_Dj9`L\$,$o$+$j$K$/$$$N$O!"!V>pJs%P!pJs%P!<$G9T$&!W$H$$$C$?FbMF$J$i!"8m2r$5$l$K$/$$$h$&$J5$$,!#(B

$B!!(BMicrosoft $B$N@bL@$b$*$b$$$C$-$jITB-$7$F$$$F!"$?$H$($P(B

$B$r8+$F$b!V$I$N$h$&$K@_Dj$9$k$H$=$&$J$k$N$+!W$O$5$C$Q$j$o$+$i$J$$$7!"(B

$B$r8+$F$b!"$d$C$Q$j$o$+$i$J$$$G$9$M!#(B $B$$$A$P$s$o$+$j$d$9$$$N$O!"(BIE $B%X%k%W$N!V(BInternet Explorer $B$N>pJs%P!

$B!!$^$?!"2?$,0BA4B&$J$N$+$K$D$$$F$O!"!V@)8B:Q$_%5%$%H%>!<%s!W$G$I$N$h$&$K@_Dj$5$l$F$$$k$+$r8+$k$H;29M$K$J$k$H;W$$$^$9!#$3$NE@$G$O!"(B$B%0%k!<%W(B $B%]%j%7!<$r;HMQ$7$?(B Windows XP Service Pack 2 $B$N5!G=$N4IM}(B (Microsoft) $B$b;29M$K$J$j$^$9!#(B

$B!!$"$H!"!V(BActiveX$B%3%s%H%m!<%k$KBP$7$F<+F0E*$K%@%$%"%m%0$rI=<(!W$N?F@L$K!V%U%!%$%k$N%@%&%s%m!<%I;~$K<+F0E*$K%@%$%"%m%0$rI=<(!W$H$$$&$N$,$$$k$N$G$9$,!"$3$l$K$D$$$F?($l$k?M$O$"$^$j$$$J$$$G$9$+$M!#(B


$B"#(B 2005.09.19

$B"#(B Secunia Research: Ahnlab V3 Antivirus Multiple Vulnerabilities
(Secunia, Thu, 15 Sep 2005 21:22:48 +0900)

$B!!(BAhnlab V3Pro 2004 / V3 VirusBlock 2005 / V3Net for Windows Server 6.0 $B$K(B 3 $B$D$N7g4Y!#(B

$B!!=$@5HG(B (6.0.0.457 $B0J9_(B) $B$,MQ0U$5$l$F$*$j!"%*%s%i%$%s%"%C%W%G!<%H$K$h$C$FE,MQ$G$-$k!#(B

$B!!4XO"(B:


$B"#(B 2005.09.17

$B"#(B IE$B$K$^$??7$?$J@H
(ITmedia, 2005.09.17)

$B!!(BEEYEB-20050915 $B$NOC!#(BWindows XP (SP2 $B4^$`(B) $B$N(B IE $B$K(B Remote Code Execution $B$J7g4Y$,$"$k$i$7$$!#(B patch $B$O$b$A$m$s$^$@$J$$$,!"(B eEye Blink $B$rF~$l$F$"$k$HKI$2$k$i$7$$!#(B $B%*%s%i%$%s$GGc$($k(B$B$3$H$K$J$C$F$k$C$]$$$N$@$1$I!"

$B!!(BUpcoming Advisories (eEye)$B!"$^$?$>$mL$2r7h7g4Y$,N/$C$F$-$F$^$9$M!D!D!#(B

$B"#(B [Clamav-announce] announcing ClamAV 0.87
(ClamAV, 2005.09.16)

$B!!(BClamAV 0.87 $B$,=P$^$7$?!#(B $B>\:Y$O$o$+$j$^$;$s$,!"!V(BThis version fixes vulnerabilities in handling of UPX and FSG compressed executables$B!W$@$=$&$G$9!#%"%C%W%0%l!<%I$7$^$7$g$&!#(B

2005.09.21 $BDI5-(B:

$B!!(B[SA16848] ClamAV UPX and FSG Handling Vulnerabilities

2005.09.22 $BDI5-(B:

$B!!(BCVE: CAN-2005-2919 CAN-2005-2920


$B"#(B 2005.09.16


$B"#(B 2005.09.15

$B"#(B $B%?%$%T%s%0$N!V2;!W$G%Q%9%o!<%I$r!VEpD0!W!=!=$I$&$7$?$iKI$2$k!)(B
(ITmedia, 2005.09.14)

$B!!E}7WE*

$B!!4XO"(B: $B%-!<%\!<%I$NF~NO2;$G>pJsN.=P$N2DG=@-(B! $B<~0O$K;(2;$G$b2r@O2D(B (MYCOM PC WEB, 2005.09.15)


$B"#(B 2005.09.14

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B $BDI5-(B

Update Rollup 1 for Windows 2000 SP4 $B$r%$%s%9%H!<%k$9$k$HIT0BDj$K$J$k;vNc(B

$B!!(B891861: Update Rollup 1 for Windows 2000 SP4 and known issues (Microsoft) $B$,2~D{$5$l$F(B revision 18.0 $B$K$J$C$F$$$^$9!#(B $B:#F|!"(BUpdate Rollup 1 $B$N?7HG(B (v2) $B$,%j%j!<%9$5$l$?$h$&$G$9!#(B v1 $B$K$"$C$?LdBj$N$&$A!"

  • $B
  • MSXML3.DLL $B%U%!%$%k$,8+$D$+$j$^$;$s(B
  • $B%(%i!$B%(%i!
  • $B%(%i!<%a%C%;!<%8(B "Stop 0x000001E" $B$,I=<($5$l$k(B
  • $B%@%$%J%_%C%/%G%#%9%/$r;HMQ$9$k%3%s%T%e!<%?$K%$%s%9%H!<%k$9$k$H!"%7%9%F%`(B $B%I%i%$%V$,(B 2 $B$DI=<($5$l$k$3$H$,$"$k(B
  • Microsoft Office $B%W%m%0%i%`$+$i%U%m%C%T!<(B $B%G%#%9%/$K%U%!%$%k$rD>@\J]B8$G$-$J$$(B

$B"#(B 2005.09.13

$B"#(B JVNVU#102441: X server $B$KJ#?t$N@0?t%P%C%U%!%*!<%P!<%U%m!<$N@H
(JVN, 2005.09.13)

$B!!$@$=$&$G$9!#(BCVE: 2005-2495

$B"#(B Google $B$O%f!<%6$N9TF0$r<}=8$7$F$$$kLOMM(B
($B$/$i$5$P(B, 2005.09.07)

$B!!@N!"(BJWORD $B$O%9%Q%$%&%'%"$+(B? (google $B$X$N%j%s%/$J$N$GCm0U(B :-)) $B$H$$$&OC$,$"$C$?$H$-$K!"!V$=$s$J$3$H8@$C$?$i(B google $B$@$C$F%9%Q%$%&%'%"$8$c$s!W$H$$$&0U8+$,;68+$5$l$?$,!"$d$C$Q$j$=$&$$$&J}8~$K$"$k$s$G$9$+$M!#(B

$B!!8!:w7k2L2hLL$G$N9TF0DI@W$K$D$$$F$O!"(BJavaScript $B$rL58z$K$9$l$P2sHr$G$-$k$=$&$G$9!#(B $B$^$?(B cookie $B$K$D$$$F$O!"(Bcookie $B$rDj4|E*$K:o=|$9$k!"(Bgoogle.com / google.co.jp $B$KBP$9$k(B cookie $B$NMxMQ$r6X;_$9$k!"(Bcookie $B$N(B ID $BItJ,$r%/%j%"$9$k(B$B!"$H$$$C$?J}K!$,$"$k$h$&$G$9!#(B $B$"$H!"(Bcookie $B$NMxMQ$r6X;_$9$k$H(B www.google.com $B$+$i(B www.google.co.jp $B$K%j%@%$%l%/%H$5$l$k(B $B$H$$$&I{:nMQ$,$"$k$=$&$G$9(B ($B2sHrJ}K!$b$"$k$=$&$G$9$,!#$"$H!"%V%i%&%6$N8@8l@_Dj$K0MB8$9$k$h$&$JM=46$,(B)$B!#(B

$B!!(BFirefox / Mozilla $B$J$i!"(Babout:config $B$G(B network.cookie.lifetime.days $B$r@_Dj$7!"(Bnetwork.cookie.lifetimePolicy $B$r(B 3 $B$K$9$l$P!"%5%$%HB&$,!V(B2038 $BG/$^$GM-8z(B!$B!W$H8@$C$F$-$F$b!"(Bcookie $B$Nl9g$O@_Dj$9$k$3$H$r$*$9$9$a$7$^$9!#(B $B$?$@$7$3$l$r@_Dj$9$k$H!"$?$H$($P!"(Bcookie $B$r;H$C$?G'>Z$r$7$F$$$k(B web $B%Z!<%8$K$*$$$F!"(B network.cookie.lifetime.days $B$N4|4VKh$K:FG'>Z$,I,MW$K$J$C$?$j$^$9!#(B

$B"#(B $BDI5-(B

JVN#257C6F28$B!'(B Internet Explorer $B%3%s%]!<%M%s%H$r;HMQ$9$k%"%W%j%1!<%7%g%s$K$*$1$k%;%-%e%j%F%#%>!<%s$N07$$$K4X$9$k@H

$B!!IY;NDL$N(B SIMPLIA/TF-WebTest $B$K$b$3$N7g4Y$,$"$C$?$=$&$@(B: WEB$B%"%W%j%1!<%7%g%s%F%9%H;Y1g%D!<%k!V(BSIMPLIA/TF-WebTest$B!W$N(B $B%;%-%e%j%F%#$N@H ($BIY;NDL(B, 2005.09.09)

$B"#(B Remote Vulnerability Found in Snort - Fix and Workaround Available
(snort.org, 2005.09.12)

$B!!(BSnort $B$N(B snort-2.4.0/src/log.c $B$K7g4Y!#(BPrintTcpOptions() $B$K7g4Y$,$"$j!"96N,(B TCP/IP $B%Q%1%C%H$K$h$C$F(B DoS $B967b$,2DG=!#(B $B$3$N7g4Y$O(B verbose mode $B;~$K$N$_1F6A$9$k!#(B Snort Denial of Service Vulnerability (SANS ISC) $B$G$O(B 2.4.0 $B$@$1$G$J$/(B 2.x $BA4HL$K1F6A$"$j!"$H$7$F$$$k!#(B

$B!!(BCVS $BHG$G$O4{$K=$@5$5$l$F$*$j!"


$B"#(B 2005.09.12

$B"#(B SFS3.02 $B$N?7$?$J%/%m%9%5%$%H%9%/%j%W%F%#%s%0@H
(IAJapan, 2005.06.10)

$B!!(BIAJapan $B$N%5!<%P7?%U%#%k%?%j%s%0%7%9%F%`(B SFS (Server-type Filtering System) 3.02 ($B0JA0(B?) $B$K%/%m%9%5%$%H%9%/%j%W%F%#%s%07g4Y$,$"$j!"(B3.02a $B$G=$@5$5$l$?!#(B

$B"#(B $BDI5-(B

[Full-disclosure] Secunia Research: NOD32 Anti-Virus ARJ Archive Handling Buffer Overflow

$B!!2O9g$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B)

$BF|K\8lHG$N>u67$r3NG'$7$F$_$^$7$?!#(B

> $B%"!<%+%$%V%5%]!<%H%P!<%8%g%s(B: 1.034 (20050902)
> $B%"!<%+%$%V%5%]!<%H%S%k%I(B: 1132

$B$*$=$i$/!"3F9q8lHG4X78$J$/!"F|K\8lHG$b4^$a%?%$%`%i%0$J$7$G99?7$G$-$F$$$?$N$G$O$J$$$+$H;W$$$^$9!#(B

$B!!


$B"#(B 2005.09.10

$B"#(B $B%I%-%e%a%s%H$$$m$$$m(B
(various)

$B"#(B $B$$$m$$$m(B
(various)

$B"#(B [Full-disclosure] Secunia Research: NOD32 Anti-Virus ARJ Archive Handling Buffer Overflow
(full-disclosure, Thu, 08 Sep 2005 19:40:45 +0900)

$B!!(BNOD32 2.5 $B$K7g4Y!#(BARJ $B%"!<%+%$%V$N8!::$K$*$$$F!"%"!<%+%$%VCf$ND9Bg$J%U%!%$%kL>$K$h$C$F(B heap buffer overflow $B$,H/@8!"G$0U$N%3!<%I$r

$B!!%*%s%i%$%s%"%C%W%G!<%H7PM3$G=$@5HG$,G[I[$5$l$F$$$k!D!D$H$5$l$F$$$k$,!"F|K\8lHG$N(B NOD32 $B$G$O$I$&$J$N$@$m$&!#(B

2005.09.12 $BDI5-(B:

$B!!2O9g$5$s$+$i(B ($B$"$j$,$H$&$4$6$$$^$9(B)

$BF|K\8lHG$N>u67$r3NG'$7$F$_$^$7$?!#(B

> $B%"!<%+%$%V%5%]!<%H%P!<%8%g%s(B: 1.034 (20050902)
> $B%"!<%+%$%V%5%]!<%H%S%k%I(B: 1132

$B$*$=$i$/!"3F9q8lHG4X78$J$/!"F|K\8lHG$b4^$a%?%$%`%i%0$J$7$G99?7$G$-$F$$$?$N$G$O$J$$$+$H;W$$$^$9!#(B

$B!!

$B"#(B IDN $B%P%C%U%!%*!<%P!<%U%m!<$N%;%-%e%j%F%#LdBj$K$D$$$F(B Firefox $B$*$h$S(B Mozilla Suite $B%f!<%6$,CN$C$F$*$/$Y$-$3$H(B
(mozilla-japan.org, 2005.09.09)

$B!!(B[Full-disclosure] Mozilla Firefox "Host:" Buffer Overflow $B$NOC!#(Bpatch $B$rE,MQ$9$k$+!"(BFirefox / Mozilla $B$N(B IDN $B%5%]!<%H$rL58z$K$9$l$P2sHr$G$-$k!#(B about:config $B$+$i(B network.enableIDN $B$r(B false $B$K@_Dj$9$l$P$h$$!#(B

2005.09.21 $BDI5-(B:

$B!!(BFirefox 1.0.7 $B$G=$@5$5$l$^$7$?!#(B

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B (2005.09)

$B!!(BMicrosoft Security Bulletin Advance Notification (Microsoft) $B$,99?7$5$l$F$$$^$9!#(B $B%;%-%e%j%F%#99?7%W%m%0%i%`$KIJe$NLdBj$,H/8+$5$l$?$?$a!"M=Dj$5$l$F$$$?%j%j!<%9$OCf;_$5$l$?$=$&$G$9!#(B $B>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2005.09.09

$B"#(B Zebedee DoS $B$N@H
(bugtraq-jp, Fri, 9 Sep 2005 14:09:42 +0900)

$B!!(BZebedee 2.4.1 $B0JA0$K7g4Y!#E>Aw@h%]!<%HHV9f$H$7$F(B 0 $B$r;XDj$9$k$HDd;_$7$F$7$^$&$?$a!"(Bremote $B$+$i(B DoS $B967b$,2DG=!#(B $BE>Aw@h%]!<%H$r@)8B$9$k$3$H$K$h$j2sHr$G$-$k!#(B

$B!!(BZebedee 2.4.1A $B$GBP1~$5$l$F$$$k!#(B$B%j%j!<%9%"%J%&%s%9(B$B!#(B

$B!!$H$3$m$G!"(BSecurityFocus $B$N(B bugtraq-jp $B%"!<%+%$%V(B$B$C$F!"$^$?2u$l$A$c$C$F$k$s$G$9$+(B? $B0l;~4|D>$C$?$h$&$K5-21$7$F$$$k$N$G$9$,!#(B

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B (2005.09)
(Microsoft, 2005.09.09)

$B!!(B9 $B7n$N(B Windows Update $B$NF|$O(B 9/14 $B$G$9!#0J2<$N$b$N$,Ds6!$5$l$kM=Dj$@$=$&$G$9!#(B

$B!!$5$F!"(B$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (906267) COM $B%*%V%8%'%/%H(B (Msdds.dll) $B$K$h$j(B Internet Explorer $B$,M=4|$J$/=*N;$9$k2DG=@-$,$"$k(B $B$N7o!"$"$k$$$O(B Upcoming Advisories (eEye) $B$N7o$O!"$I$&$J$j$^$9$+$M$(!#(B

2005.09.10 $BDI5-(B:

$B!!(BMicrosoft Security Bulletin Advance Notification (Microsoft) $B$,99?7$5$l$F$$$^$9!#(B $B%;%-%e%j%F%#99?7%W%m%0%i%`$KIJe$NLdBj$,H/8+$5$l$?$?$a!"M=Dj$5$l$F$$$?%j%j!<%9$OCf;_$5$l$?$=$&$G$9!#(B $B>.=P$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2005.09.08

$B"#(B IIS 5.1 allows for remote viewing of source code on FAT/FAT32 volumes using WebDAV
(Inge Henriksen's Technology Blog, 2005.09.04)

$B!!(BIIS 5.1 $B$r(B FAT / FAT32 $B>e$GMxMQ$7$F$$$k>l9g$K7g4Y!#FCe$G(B IIS 5.1 $B$rMxMQ$7$F$$$k>l9g$K$b$3$N7g4Y$O$J$$$H$$$&!#(B

$B"#(B Windows / Linux $B%"%s%A%&%#%k%9@=IJ(B $B%[%C%H%U%#%C%/%9E,MQ$N$*4j$$!!(B
(F-Secure, 2005.09.08)

$B!!(BF-Secure $B$N(B Linux / Windows $BHG%"%s%A%&%#%k%9@=IJ$K7g4Y!#(B Windows $BHG$N>l9g$O!V(B2006$BG/(B1$B7n0J9_$N$"$k;~E@$+$i%Q%?!<%s%U%!%$%k99?7J}K!$N0l$D$,%(%i!<$H$J!W$j!"(BLinux $BHG$N>l9g$O!V(B2006$BG/(B1$B7n0J9_$N$"$k;~E@$+$i%Q%?!<%s%U%!%$%k99?7$,%(%i!<$H$J!W$k$=$&$G$9!#(BLinux $BHG$N>l9g$O5_$$$,$J$$$h$&$G!#(B

$B!!860x$O!V%&%#%k%9Dj5A%U%!%$%k99?7%W%m%0%i%`(B(getdbhtp)$B$K$*$$$F!"(B129$B8D0J>e$NDj5A%U%!%$%k$"$k>l9g$K99?7$G$-$J$$!W$?$a$@$=$&$G$9!#$3$l$O(B Linux $BHG(B hotfix $B$N@bL@$K$"$k8@MU$G!"(BWindows $BHG$@$H!V0lDj?t0J>e$N%Q%?!<%s%U%!%$%k$r07$($J$$$?$a!W$H$J$C$F$$$^$9$M!#(B

$B!!$$$:$l$K$;$h!"%[%C%H%U%#%C%/%9$,=P$F$$$k$N$GE,MQ$7$^$7$g$&!#(B


$B"#(B 2005.09.07


$B"#(B 2005.09.06

$B"#(B SYM05-013: $B%m!<%+%k(B LiveUpdate $B%5!<%P!<$N%f!<%6!!?%Q%9%o!<%I>pJs$,%/%i%$%"%s%H$K$h$j8x3+$5$l$k(B
($B%7%^%s%F%C%/(B, 2005.09.02)

$B!!(BLiveUpdate $B%/%i%$%"%s%H(B 2.7 $B%S%k%I(B 34 $B$K7g4Y!#(B $BG'>Z$NI,MW$J!"%m!<%+%k(B LiveUpdate $B%5!<%P$+$i99?7$9$k>l9g$K!"G'>Z>pJs$,J?J8$G(B "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Log.Liveupdate" $B%U%!%$%k$K5-O?$5$l$F$7$^$&!#(B LiveUpdate $B%/%i%$%"%s%H(B 2.5 / 2.6 $B$K$O$3$N7g4Y$O$J$$!#(B $B85$M$?(B: Vulnerability in Symantec Anti Virus Corporate Edition v9.x$B!#(B

$B!!1Q8lHG$N(B LiveUpdate $B%/%i%$%"%s%H(B 2.7 $B$K$D$$$F$O!"(B2.7 $B%S%k%I(B 38 (2.7.38) $B$GBP1~$5$l$F$$$k!#(Bhttp://www.symantec.com/techsupp/files/lu/lu.html $B$+$iF~$B%"%I%P%$%6%j(B$B$K$O1QLu$=$N$^$^!V(BLiveUpdate 2.7 $B%/%i%$%"%s%H$N99?7HG$,%j%j!<%9$5$l!"0J2<$N>l=j$+$i%@%&%s%m!<%I$9$k$3$H$,$G$-$^$9!W$H$"$k$N$@$,!"(Bhttp://www.symantec.com/region/jp/techsupp/files/lu/lu.html $B$Ghttp://www.symantec.com/region/jp/techsupp/enterprise/select_product_updates_nojs.html $B$b8+$F$_$?$,!"$d$C$Q$j(B LiveUpdate 2.6 $B$7$+$J$$$h$&$@!#(B

$B!!!D!D$"$l(B? $B%7%^%s%F%C%/@=IJ$K4X$9$k%;%-%e%j%F%#!&%"%I%P%$%6%j!<(B $B$N%Z!<%8$+$i>C$($A$c$C$?$h(B? $B$I$&$J$C$F$k$N(B? (9/6 14:40)$B!#(B $B$b$7$+$7$F!"F|K\$G$O(B LiveUpdate 2.7 $B$O$b$H$b$H=P$7$F$$$J$+$C$?$j$7$?$N$+$J!#(B

$B!!!D!D$U$?$?$S(B $B%7%^%s%F%C%/@=IJ$K4X$9$k%;%-%e%j%F%#!&%"%I%P%$%6%j!<(B $B$K:\$k$h$&$K$J$j$^$7$?$M(B (9/6 19:10)$B!#(B $B!VF|K\8lHG$G$OK\@H


$B"#(B 2005.09.05

$B"#(B $B$$$m$$$m(B
(various)


$B"#(B 2005.09.04


$B"#(B 2005.09.02


$B"#(B 2005.09.01

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (897663) Windows $B%U%!%$%"%&%)!<%k$NNc30$,%f!<%6!<(B $B%$%s%?!<%U%'%$%9$KI=<($5$l$J$$2DG=@-$,$"$k(B
(Microsoft, 2005.09.01)

$B!!(BWindows $B%U%!%$%"%&%)!<%k$K$*$$$F!"@_Dj(B GUI $B$+$i$O8+$($J$$$h$&$JNc30$r@_Dj$9$k$3$H$,2DG=!#(BWindows XP SP2 / Server 2003 SP1 $B$GH/@8$9$k!#(Bnetsh $B$+$i$O8+$($k$h$&$@!#4XO"(B: KB 897663$B!#(B

$B!!(BWindows XP SP2 $BBP1~$N=$@5%W%m%0%i%`(B$B$,MQ0U$5$l$F$$$k!#(BWindows Server 2003 SP1 $BMQ$O$^$@$N$h$&$@!#(B

$B"#(B $B=;L1L14pK\BfD"%+!<%IMQ$N%/%i%$%"%s%H%=%U%H$rG[I[$9$k$H(B Path $B4D6-JQ?t$,>C$($k(B
($BEP(B $BBgM7!wC^GHBg3X>pJs3XN`$N(B SoftEther VPN $BF|5-(B, 2005.08.31)

$B!!EP$5$s$b$*$C$7$c$C$F$$$i$C$7$c$$$^$9$,!"!V$5$9$,EE;R@/I\!W$H$7$+8@$$$h$&$,$"$j$^$;$s$M!D!D!#(B

$B!!$A$J$_$K!"(B

$B"#(B webif.cgi CSRF$B@H
($B%O%$%Q!

$B!!(B$B%O%$%Q! 2.19.5 $B0JA0$K7g4Y!#(B webif.cgi $B$r(B direct $B%b!<%I$GMxMQ$9$k>l9g$K(B CSRF $B7g4Y$,B8:_!#(B $B96N,(B web $B%Z!<%8$r1\Mw$9$k$H!"%O%$%Q!pJs$r:q

$B!!%O%$%Q!$B%@%&%s%m!<%I(B$B!#(B

$B!!4XO"(B:


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B