$B%;%-%e%j%F%#%[!<%k(B memo - 2007.08

Last modified: Sat Dec 22 23:23:01 2007 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2007.08.31

$B"#(B $BDI5-(B

[Users] SECURITY: root privilege escalation / trivial reveal of stored passwords

$B!!",$N(B 0.83 beta $B$O(B 0.8.2 beta $B$N4V0c$$(B$B$@$C$?LOMM!#(B

$B!!(BSSHKeychain 0.8.2 $B@5<0HG$,8x3+$5$l$F$$$k(B: $B%"%J%&%s%9(B$B!#(B PassphraseRequester $B%f!<%F%#%j%F%#$N7o$O=$@5$5$l$?LOMM!#(BTunnelRunner $B%f!<%F%#%j%F%#$N7o$K$D$$$F$O!"(B0.8.2 $B$N%$%s%9%H!<%i$,(B 1024 $B$h$j>.$5$$%]!<%H$rL58z$K$9$k$3$H$G0l;~E*$JBP1~$H$7$F$$$kLOMM!#(B $B@5<0$J=$@5$O

$B"#(B Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities
(iDefense, 2007.08.30)

$B!!(BYahoo Messenger 8.1 for Windows $B$K7g4Y!#(BYVerInfo.dll ActiveX $B%3%s%H%m!<%k$KJ#?t$N(B buffer overflow $B7g4Y$,B8:_$9$k$?$a!"96N,(B Web $B%Z!<%8$K$h$C$FG$0U$N%3!<%I$rCVE-2007-4515

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(BYahoo! ActiveX Control Update (yahoo.com) $B$r;2>H!#(B

$B"#(B Internet Explorer 7 $B$N<+F099?7$K$h$kG[I[(B
(Microsoft, 2007.08.24 $B99?7(B)

$B!!@>;3$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

Internet Explorer 7 $B$NG[I[M=DjF|(B
($BCfN,(B)
$BF|K\8l!"4Z9q8l!"4JBN;zCf9q8l!"HKBN;zCf9q8l!"%X%V%i%$8l(B : 2008 $BG/0J9_(B ($B>\:Y$JM=DjF|$O8eF|8x3+(B)

$B!!4XO"(B: $B<+F099?7$K$h$k(BInternet Explorer 7$B$NG[I[3+;O$O2?F|$+$i!)(B (hotfix.jp)$B!#$I$3$^$G1d$P$;$k$+%F%9%HCf$J$N$@$m$&$+!#$N$S!A$k$N$S!A$k$N$S!A$k!D!D$H8@$($P!"(B$B%9%H%l%C%A%^%s(B 2 $B$@$h$J$"!#(B

$B"#(B APPLE-SA-2007-08-29 AirPort Extreme Base Station Firmware version 7.2.1
(Apple, 2007.08.30)

$B!!(BAirPort Extreme 802.11n* $BMQ$N%U%!!<%`%&%'%"%P!<%8%g%s(B 7.2.1 $B$,EP>l$7$?$=$&$G$9!#(BIPv6 Type 0 Route Header $BOC(B (CVE-2007-2242) $B$KBP1~$7$?$=$&$G$9!#(B

$B"#(B $B$$$m$$$m(B (2007.08.31)
(various)

2007.09.11 $BDI5-(B:

$B!!(BCVE-2007-3847 $B$O(B Apache 2.2.6 / 2.0.61 $B$G=$@5$5$l$F$$$k!#(B

2007.12.22 $BDI5-(B:

$B!!(BSendmail with clamav-milter < 0.91.2 Remote Root Exploit (milw0rm)$B!#B?J,(B CVE-2007-4560 $B$N(B exploit $B!#$3$s$J$K4JC1$J$s$G$9$M!#(B


$B"#(B 2007.08.30

$B"#(B $B$$$m$$$m(B (2007.08.30)
(various)

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B

$B!!(BMS07-044, MS07-045, MS07-046, MS07-047 $B$,2~D{$5$l$F$$$^$9!#(B

$B!!$*$^$1(B: Technical Tips and Insights on MS07-049 and MS07-044 (MSRC blog, 2007.08.23)

[SA26570] MSN Messenger Video Conversation Buffer Overflow Vulnerability

$B!!4XO"(B:

Double Whammy! Another Sony Case (And it's Not BioShock)

$B!!4XO"(B:


$B"#(B 2007.08.29

$B"#(B $B!V@$3&N&>e!W$N??$NIqBfN"!"1?1D$,$`$A$c$/$A$c$G8=>l$OBg:.Mp(B
(gigazine, 2007.08.29)

$B!!@$3&%H%C%W%/%i%9$N%"%9%j!<%H$r%[%F%k$N>2$K%6%3?2$5$;$F$$$k;v

$BBg2qAH?%0Q$NFb;3BYGn9-Js<2$G?2$?$3$H$OJs9p$b

$B;vpJs%7%9%F%`$,Jx2u$7$F$$$k$i$7$$!D!D!#$$$d!"$9$4$$$G$9!#4XO"(B:

$B"#(B [SA26570] MSN Messenger Video Conversation Buffer Overflow Vulnerability
(secunia, 2007.08.28)

$B"#(B $BDI5-(B

BIND 9 DNS Cache Poisoning

$B!!(Bbind 8 $B$K$bF1MM$N7g4Y$,$"$j!"(BBIND 8.4.7-p1 $B$,=P$F$$$k!#(B

$B!!$?$@$7!"(Bbind 8 $B$O$b$O$d(B$B%a%s%F%J%s%9$,=*N;$7$F$$$k(B$B$?$a!"(Bbind 9 $B$N:G?7HG$X0\9T$9$k$3$H$,K>$^$7$$!#(B

Double Whammy! Another Sony Case (And it's Not BioShock)

$B!!4XO"(B:

Targeted Zero-day Attack Against Free Tools - LHAZ

$B!!(B2007.08.23 $BIU$G(B Lhaz 1.34 $B$,@5<0$K%j%j!<%9$5$l$F$$$^$9!#J#?t$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$^$9!#(B

$B!&(Bgzip$B=q8K$G$N@H $B!&(Bgzip$B=q8K$N(Bdirectory traversal$BLdBj$KBP=h!#(B
$B!&(BLZH$B=q8K$G$N@H

$B!!4XO"(B: JVNVU#492799 - Lhaz $B$KG$0U$N%3!<%I$,


$B"#(B 2007.08.28

$B"#(B $B$$$m$$$m(B (2007.08.28)
(various)

$B"#(B $BDI5-(B

Yahoo! Messenger$B$K%<%m%G%$$N@H

$B!!F|K\8lHG$N(B Yahoo! $B%a%C%;%s%8%c!<$K$b7g4Y$,$"$C$?$h$&$G!"99?7$N0FFb$,=P$F$$$^$9!#(B

$B!!1Q8lHG$O$3$A$i(B:

$B"#(B Double Whammy! Another Sony Case (And it's Not BioShock)
(F-Secure blog, 2007.08.27)

$B!!$^$?%=%K!<$J$N(B?! $B:#EY$O(B USB $B;XLfG'>Z%G%P%$%9$N%=%U%H$@$=$&$G!#(B Sony MicroVault USM-F $B$H$$$&$N$O!"F|K\$G8@$&$H(B PocketBit USM-F $B$d(B PocketBit USM-FL $B$N$3$H$+(B?

2007.08.29 $BDI5-(B:

$B!!4XO"(B:

2007.08.30 $BDI5-(B:

$B!!4XO"(B:

2007.09.03 $BDI5-(B:

2007.09.04 $BDI5-(B:

2007.09.06 $BDI5-(B:

$B!!4XO"(B: $B;XLfG'>Z%O!<%I%&%'%"$H!V(BRTKT_XCP.B$B!W(B ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2007.08.31)

$B$9$G$KF|K\9qFb$NJ#?t%Y%s%@!<$,Ds6!$9$k;XLfG'>Z%O!<%I%&%'%"$K$*$$$F!"(BFineart Technology$B

$B!!(BSONY $B$@$1$G$O$J$$LOMM!#(B

2007.09.07 $BDI5-(B:

$B!!%=%K!<$+$i%*%U%#%7%c%k%j%j!<%9(B: $B;XLfG'>Z5!G=$D$-%]%1%C%H%S%C%HIUB0%=%U%H%&%'%"$N(B $B@H (SONY, 2007.09.07)$B!#(BSONY $B@=IJ$GBP>]$H$J$k$N$O(B USM128F, USM512FL $B$G$"$j!"=$@5%W%m%0%i%`$r(B 9 $B7n2<=\$K8x3+M=Dj$@$=$&$G$9!#(B

$B!!4XO"(B: JVN#35677737: $B%=%K!<@=;XLfG'>Z5!G=$D$-!V%]%1%C%H%S%C%H!WIUB0%=%U%H%&%'%"$K$*$1$k@H$B!#(B $BBP>]$H$J$k(B SONY $B$N3$30@=IJ$O(B USM64C, USM128C, USM256F, USM512FL $B$@$=$&$G$9!#(B

2007.10.09 $BDI5-(B:

$B!!(B9/28 $BIU$G(B patch $B=P$F$$$^$9(B: $B;XLfG'>Z5!G=$D$-%]%1%C%H%S%C%HIUB0%=%U%H%&%'%"$N@H ($B%=%K!<(B, 2007.09.28)

$B!!F1$8%M%?$+(B?! UD-SecurityII$B!J(BHUD-SC256J2$B!K$N@H ($B%O%.%o%i%7%9%3%`(B, 2007.10.05)

2007.10.30 $BDI5-(B:

$B!!:F%$%s%9%H!<%kMQ%=%U%H%&%'%"0l<0$,8x3+$5$l$F$$$^$9!#(B


$B"#(B 2007.08.27

$B"#(B $B$$$m$$$m(B (2007.08.27)
(various)

$B"#(B $BDI5-(B

64-bit Driver Signing on Windows Vista $B!>!F(BComputer Says No$B!G(B

$B!!4XO"(B:

Trend Micro ServerProtect 5.58 for Windows $B$K(B 2 $B$D$N7g4Y(B

$B!!(BTrend Micro management exploit payload perhaps? (SANS ISC, 2007.08.23) $B$O!":#2s$N7g4Y$G$O$J$/!"(B 2007 $BG/(B 2 $B7n$KH/8+$5$l$?$b$N(B (TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities) $B$r96N,$9$k$b$N$@$C$?LOMM!#(B

$B"#(B Advisory: Sophos Anti-Virus vulnerabilities reported by n.runs
(Sophos, 2007.08.23)

$B!!(BSophos Anti-Virus $B$N%&%$%k%9%(%s%8%s(B 2.47.x $B0JA0$N$b$N$K(B 2 $B$D$N7g4Y!#(B

$B!!(BSophos Anti-Virus $B%&%$%k%9%(%s%8%s(B 2.48.0 $B0J9_$G=$@5$5$l$F$$$k!#:G?7$O(B 2.49.x $B$NLOMM!#(B


$B"#(B 2007.08.26


$B"#(B 2007.08.25


$B"#(B 2007.08.24

$B"#(B $B0-pJsN.=P;v7o(B
(ITmedia, 2007.08.24)

$B!!5a?M>pJs%5%$%H(B monster.com $B$,$d$i$l$?OC!"$I$&$d$i$3$&$$$&N.$l$@$C$?LOMM!#(B

  1. $B=>6H0w$,I8E*7?967b$rInfostealer.Monstres $B$r?"$($D$1$i$l$k!#(B

    $BI8E*7?967b$H$O$I$3$K$b=q$+$l$F$$$J$$$1$I!"(BInfostealer.Monstres $B$NH/8+F|(B (2007 $BG/(B 8 $B7n(B 16 $BF|(B) $B$H!V4m81EY(B 1: $B$[$H$s$I1F6A$J$7!W$r9M$($l$P!"I8E*7?967b$@$C$?$H2r

  2. $B967bpJs$KE~C#!"8D?M>pJs$rEp$_=P$9!#(B

  3. $B967bpJs$r;H$C$F%9%T%"!&%U%#%C%7%s%0$r9T$&!#(B

$B!!$$$h$$$hI8E*7?967b$X$NBP:v$,5^L3!"$H$$$&$3$H$G$9$h$M!D!D!#(B $B6qBNE*$K$OL$CN%^%k%&%'%"$N8!=P$,$G$-$F$[$7$$$N$G$7$g$&$,!"$O$F$5$F!#(B

$B"#(B [Users] SECURITY: root privilege escalation / trivial reveal of stored passwords
(SSHKeychain.org, 2007.08.22)

$B!!(BSSHKeychain 0.82 beta $B0JA0$K(B 2 $B$D$N7g4Y!#(B

  • TunnelRunner $B%f!<%F%#%j%F%#$K7g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rCVE-2007-4500
  • PassphraseRequester $B%f!<%F%#%j%F%#$K7g4Y$,$"$j!"(BSSHKeychain $B$GJ]B8$7$?%Q%9%o!<%I$r(B ($BB>$N(B local user $B$,(B?) $B2sI|$G$-$F$7$^$&!#(B CVE-2007-4501

$B!!(BSSHKeychain 0.83 beta $B$G=$@5$5$l$F$$$k!#(B

2007.08.31 $BDI5-(B:

$B!!",$N(B 0.83 beta $B$O(B 0.8.2 beta $B$N4V0c$$(B$B$@$C$?LOMM!#(B

$B!!(BSSHKeychain 0.8.2 $B@5<0HG$,8x3+$5$l$F$$$k(B: $B%"%J%&%s%9(B$B!#(B PassphraseRequester $B%f!<%F%#%j%F%#$N7o$O=$@5$5$l$?LOMM!#(BTunnelRunner $B%f!<%F%#%j%F%#$N7o$K$D$$$F$O!"(B0.8.2 $B$N%$%s%9%H!<%i$,(B 1024 $B$h$j>.$5$$%]!<%H$rL58z$K$9$k$3$H$G0l;~E*$JBP1~$H$7$F$$$kLOMM!#(B $B@5<0$J=$@5$O

$B"#(B $BDI5-(B

CSRSS $B$N@H

$B!!(BEmpty message box appears when you do not have administrative credentials and you use the Certificate Import Wizard to try to install a root certificate on a Windows XP SP2-based computer that has security update MS07-021 installed (Microsoft)$B!#(B $BM-=~(B patch $B$,$"$k$=$&$G$9!#(B

Trend Micro ServerProtect 5.58 for Windows $B$K(B 2 $B$D$N7g4Y(B

$B!!(BCVE-2007-4490 $B$b(B ServerProtect 5.58 for Windows $B%S%k%I(B 1185 $B$G=$@5$5$l$F$$$k$h$&$G$9!#(B $B$"$H!"(B $B$3$s$J$N(B:

Yahoo! Messenger$B$K%<%m%G%$$N@H

$B!!(B$BJF%d%U! (CNET, 2007.08.24)

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B

$B!!(BTechNet Webcast: $B:#7n$N%o%s%]%$%s%H(B $B%;%-%e%j%F%#>pJs(B (Microsoft) $B$K$h$k$H!"(BWindows Media Player 10 / 11 + Flash Player 6 $B$N>l9g$K:G?7$N(B Flash Player $B$N%$%s%9%H!<%k$rMW5a$5$l$k$3$H$,$"$k$N$G!"$=$N>l9g$K$O:G?7$N(B Flash Player $B$rF~$l$F$*$1!"$H$$$&$3$H$_$?$$$G$9!#$9$:$-$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $B$$$m$$$m(B (2007.08.24)
(various)

$B"#(B $B!V(BXbox 360 $B%o%$%d%l%9(B $B%l!<%7%s%0(B $B%[%$!<%k!W$N;HMQ$K4X$9$k(B $B=EMW$J$*CN$i$;(B
(xbox.com, 2007.08.23)

$B!!(BXbox 360 $B%o%$%d%l%9(B $B%l!<%7%s%0(B $B%[%$!<%k(B$B$K(B AC $B%"%@%W%?$r$D$1$F;HMQ$9$k$HH/1l$K;j$k$3$H$,$"$kLOMM!#(BAC $B%"%@%W%?$r$D$1$J$$(B ($BEECS$d%P%C%F%j!<%Q%C%/$GMxMQ$9$k(B) $B$3$H$G$3$NLdBj$r2sHr$G$-$k!#(B

$B!!BP1~$O8eF|2~$a$F!#EPO?$,I,MW$K$J$k$,!"EPO?3+;O$O(B 8/27 $B$@$=$&$@!#(B


$B"#(B 2007.08.23

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B

$B!!(BMS07-047 patch (936782) $B$rE,MQ$9$k$H!"(BWindows Media Player $B$G(B .swf $B%U%!%$%k$r3+$1$J$/$J$kI{:nMQ$,$"$k$N$@$=$&$G$9!#(B

$B!!$3$l$r2sHr$9$k$K$O!"!V?7$7$$%P!<%8%g%s$N(B Adobe Flash Player $B$r%$%s%9%H!<%k!W$9$k$N$@$=$&$G$9!#2?$HHf$Y$F!V?7$7$$%P!<%8%g%s!W$J$N$+$,$I$3$K$bL@5-$5$l$F$$$^$;$s$,(B (OS $BI8=`E:IUIJ$G$9$+$M$'(B)$B!">/$J$/$H$b:G?7HG$G$"$k(B Flash Player v.9.0.47 $B$G$"$l$PLdBj$J$$$h$&$G$9!#(B Benjamin $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B%&%$%k%9%P%9%?!<(B2007 $B%H%l%s%I(B $B%U%l%C%/%9(B $B%;%-%e%j%F%#(B $B%;%-%e%j%F%#%Q%C%A8x3+$N$*CN$i$;(B

$B!!>\:Y=P$^$7$?(B: iDefense Security Advisory 08.20.07: Trend Micro SSAPI Long Path Buffer Overflow Vulnerability (iDefense, 2007.08.22)$B!#(B vstlib32.dll $B$K7g4Y$,$"$j!"D9Bg$J%Q%9L>$N%U%!%$%k$K$h$C$F(B buffer overflow $B$,H/@8!"(BSYSTEM $B8"8B$GG$0U$N%3!<%I$rCVE-2007-3873

Targeted Zero-day Attack Against Free Tools - LHAZ

$B!!4XO"(B:

$B"#(B Trend Micro ServerProtect 5.58 for Windows $B$K(B 2 $B$D$N7g4Y(B
(iDefense, 2007.08.21)

$B!!%H%l%s%I%^%$%/%m(B ServerProtect 5.58 for Windows $B$K(B 2 $B$D$N7g4Y!#(B

$B!!(BServerProtect 5.58 for Windows $B%S%k%I(B 1185 $B$G=$@5$5$l$F$$$k!#(B

$B!!$3$N7g4Y!"$5$C$=$/(B scan $B$5$l$F$$$k$h$&$G!#(B

$B!!967b$b$-$F$$$k$N$+$b!#(B

2007.08.24 $BDI5-(B:

$B!!(BCVE-2007-4490 $B$b(B ServerProtect 5.58 for Windows $B%S%k%I(B 1185 $B$G=$@5$5$l$F$$$k$h$&$G$9!#(B $B$"$H!"$3$s$J$N(B:

2007.08.27 $BDI5-(B:

$B!!(BTrend Micro management exploit payload perhaps? (SANS ISC, 2007.08.23) $B$O!":#2s$N7g4Y$G$O$J$/!"(B 2007 $BG/(B 2 $B7n$KH/8+$5$l$?$b$N(B (TSRT-07-02: Trend Micro ServerProtect eng50.dll Stack Overflow Vulnerabilities) $B$r96N,$9$k$b$N$@$C$?LOMM!#(B


$B"#(B 2007.08.22


$B"#(B 2007.08.21

$B"#(B $BDI5-(B

Targeted Zero-day Attack Against Free Tools - LHAZ

$B!!(BLhaz $B$N=$@5HG(B v1.34$B&B(B3 $B$,8x3+$5$l$F$$$k!#%;%-%e%j%F%#=$@5<+BN$O(B v1.34$B&B(B1 $B$G9T$o$l$F$*$j!"!V(Bgzip$B=q8K$G$N@H

$B!!4XO"(B:

  • TROJ_LZDROPPER.A (trendmicro)
  • CVE-2007-4428
    Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116.

$B"#(B 2007.08.20

$B"#(B $B$$$m$$$m(B (2007.08.20)
(various)

$B"#(B $BDI5-(B

BIND 9 DNS Cache Poisoning

$B!!(B[EXPL] DNS Cache Poison (BIND 9) (SecuriTeam, 2007.08.07)

Targeted Zero-day Attack Against Free Tools - LHAZ

$B!!4XO"(B:

$B"#(B $B%&%$%k%9%P%9%?!<(B2007 $B%H%l%s%I(B $B%U%l%C%/%9(B $B%;%-%e%j%F%#(B $B%;%-%e%j%F%#%Q%C%A8x3+$N$*CN$i$;(B
($B%H%l%s%I%^%$%/%m(B, 2007.08.20)

$B!!%&%$%k%9%P%9%?!<(B 2007 ($BDL>oHG$H7n3[HG(B) $B$K7g4Y!#%9%Q%$%&%'%"%H%i%C%W%(%s%8%s$,D9Bg$J%Q%9L>$K$h$C$F(B buffer overflow $B$9$k!#1F6A$OITL@$@$,!"=$@5FbMF$O!V%;%-%e%j%F%#%Q%C%A!W$G$"$k$HL@8@$5$l$F$$$k!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$h$$!#(Bpatch $B$O

$B%"%C%W%G!<%H5!G=$K$h$kG[?.$O!"(B2007$BG/(B9$B7n>e=\$rM=Dj$7$F$$$^$9!#(B

$B!!4XO"(B:

2007.08.23 $BDI5-(B:

$B!!>\:Y=P$^$7$?(B: iDefense Security Advisory 08.20.07: Trend Micro SSAPI Long Path Buffer Overflow Vulnerability (iDefense, 2007.08.22)$B!#(B vstlib32.dll $B$K7g4Y$,$"$j!"D9Bg$J%Q%9L>$N%U%!%$%k$K$h$C$F(B buffer overflow $B$,H/@8!"(BSYSTEM $B8"8B$GG$0U$N%3!<%I$rCVE-2007-3873


$B"#(B 2007.08.19

$B"#(B SYM07-023: Symantec Enterprise Firewall Username Enumeration
(symantec, 2007.08.16)

$B!!(BSymantec Enterprise Firewall 6.x $B$K7g4Y!#(B $B%j%b!<%H%"%/%;%9(B VPN $B$r;vA06&M-80(B (pre-shared key) $BG'>Z$GMxMQ$7$F$$$k>l9g$K7g4Y$,$"$j!"@5Ev$J%f!<%6L>$H$=$&$G$J$$%f!<%6L>$H$N5sF0$K0c$$$,$"$k$?$a!"(Bremote $B$+$i@5Ev$J%f!<%6L>$r?dB,$G$-$k!#(B

$B!!$3$N7g4Y$O!"%f!<%6L>$r(B default-ikeuser $B$H@_Dj$7$F!VF0E*%f!<%6!Z!W$rMxMQ$9$l$P2sHr$G$-$k!#(B

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B

$B!!4XO"(B: Detection and deployment guidance for the August 14, 2007 security release (Microsoft)


$B"#(B 2007.08.18

$B"#(B Targeted Zero-day Attack Against Free Tools - LHAZ
(mcafee blog, 2007.08.17)

$B!!(BLhaz v1.33 $B$N(B 0-day $B7g4Y$rFM$/96N,(B zip $B%U%!%$%k$,EP>l!#(B $B%^%+%U%#!<@=IJ$G$O(B Exploit-LHAZ.a $B$H$7$F8!=P$9$k!#(B

2007.08.20 $BDI5-(B:

$B!!4XO"(B:

2007.08.21 $BDI5-(B:

$B!!(BLhaz $B$N=$@5HG(B v1.34$B&B(B3 $B$,8x3+$5$l$F$$$k!#%;%-%e%j%F%#=$@5<+BN$O(B v1.34$B&B(B1 $B$G9T$o$l$F$*$j!"!V(Bgzip$B=q8K$G$N@H

$B!!4XO"(B:

2007.08.23 $BDI5-(B:

$B!!4XO"(B:

2007.08.29 $BDI5-(B:

$B!!(B2007.08.23 $BIU$G(B Lhaz 1.34 $B$,@5<0$K%j%j!<%9$5$l$F$$$^$9!#J#?t$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$^$9!#(B

$B!&(Bgzip$B=q8K$G$N@H $B!&(Bgzip$B=q8K$N(Bdirectory traversal$BLdBj$KBP=h!#(B
$B!&(BLZH$B=q8K$G$N@H

$B!!4XO"(B: JVNVU#492799 - Lhaz $B$KG$0U$N%3!<%I$,


$B"#(B 2007.08.17

$B"#(B JVNVU#428207: JRE (Java Runtime Environment) $B$N%U%)%s%H2r@O%3!<%I$K8"8B>:3J$N@H
(JVN, 2007.08.17)

$B!!(BJDK / JRE 5.0 Update 9 $B0JA0(B, SDK / JRE 1.4.2_14 $B0JA0$K7g4Y!#(B $B%U%)%s%H2r@O%3!<%I$K7g4Y$,$"$j!"$3$l$rMxMQ$9$k$H%"%W%l%C%H$+$i(B local file $B$NFI$_=q$-$dG$0U$N%3!<%I$N

$B!!(BJDK / JRE 5.0 Update 10 $B0J9_(B, SDK / JRE 1.4.2_15 $B0J9_$G=$@5$5$l$F$$$k!#(B

$B"#(B IBM DB2 $B$M$?(B
(iDefense, 2007.08.16)

$B!!$$$C$Q$$=P$F$^$9!#(B

$B!!(Bversion V9 Fix Pack 3 / version V8 FixPak 15 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B


$B"#(B 2007.08.16

$B"#(B Attacking Log analysis tools
(OSSEC, 2007.06.07?)

$B!!0[>o$JF~NO$r9T$$!"DL>o$O$"$jF@$J$$$h$&$J%m%0$r0U?^E*$K=PNO$5$;$k$3$H$K$h$C$F!"%m%02r@O%D!<%k$rqY$7$F(B DoS $B$r0z$-$*$3$9OC!#7g4Y$,$"$k%D!<%k$NNc(B:

$B!!(BDenyHosts $B$K$O=$@5HG$,B8:_$7$J$$$,!"(BFreeBSD ports $B$N$b$N$O(B patch-DenyHosts_regex.py $B$G=$@5$5$l$F$$$k!#(B ($B855-;v$G<($5$l$F$$$k=$@5$HF10l$NFbMF(B)

$B"#(B SYM07-021: Symantec ActiveX Control Input Validation Error
(Symantec, 2007.08.09)

$B!!(B Norton AntiVirus 2006 / Norton Internet Security 2006 / Norton Internet Security, Anti Spyware Edition 2005 / Norton System Works 2006 $B$K7g4Y!#(B NAVCOMUI.DLL $B$KB8:_$9$k(B 2 $B$D$N(B ActiveX $B%3%s%H%m!<%k$K7g4Y$,$"$j!"(B $B96N,(B Web $B%Z!<%8$K$h$C$FG$0U$N%3!<%I$rCVE-2007-2955

$B!!$3$N7g4Y$rMxMQ$7$?967b$O!"(B08-09-2007 $B0J9_$N%7%0%M%A%c$G(B Bloodhound.Exploit.148 $B$H$7$F8!=P$5$l$k!#$^$?(B 08-09-2007 $B0J9_$N(B IPS $B%7%0%M%A%c$G$O(B HTTP Symantec NAV NavComUI ActiveX BO $B$H$7$F8!=P$5$l$k!#(B

$B!!99?7$O(B LiveUpdate $B$K$h$C$F<+F0E*$KE,MQ$5$l$k!#(B

$B"#(B $B$$$m$$$m(B (2007.08.16)
(various)

$B"#(B $B#P#CEpFq!'45pJs5-O?!!El5~$NEl
($BKhF|(B, 2007.08.16)

$B!!(BPC $BEpFq$M$?!#(B

$B%Q%=%3%s$O5/F0;~$K%Q%9%o!<%I$NF~NO$,I,MW$J$?$a!"F1IB1!$O!VBh;0pJs$NIT@5;HMQ$J$I$N;v

$B!!El

$B"#(B Vulnerability Note VU#466601: Microsoft DirectX Media 6.0 Live Picture Corporation DirectTransform FlashPix ActiveX control buffer overflow
(CERT.org, 2007.08.12)

$B!!(BMicrosoft $B$N(B DirectX Media 6.0 SDK $B$K4^$^$l$k!"(BLive Picture Corporation $B@=$N(B DirectTransform FlashPix ActiveX $B%3%s%H%m!<%k(B DXTLIPI.DLL $B$K7g4Y!#(B SourceUrl() $B%W%m%Q%F%#$K$*$$$F(B buffer overflow $B$9$k$?$a!"0-0U$"$k(B web $B%5%$%H$,G$0U$N%3!<%I$r

$B!!(BCLSID {201EA564-A6F6-11D1-811D-00C04FB6BD36} $B$K(B kill bit $B$r@_Dj$9$k$3$H$G2sHr$G$-$k!#@_DjMQ$N(B .reg $B%U%!%$%k$,<($5$l$F$$$k!#(B

$B!!4XO"(B: MS$B$N(BDirectX Media SDK$B@Hl(B (ITmedia, 2007.08.15)

$B"#(B JVN#59851336: Apache Tomcat $B$N(B Host Manager $B$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H
(JVN, 2007.08.15)

$B!!(BTomcat 5.5.0 $B!A(B 5.5.24 / 6.0.0 $B!A(B 6.0.13 $B$K7g4Y!#(BHost Manager $B$K(B XSS $B7g4Y$,B8:_!#(BCVE-2007-3386

$B!!(BTomcat 6.0.14 $B$G=$@5$5$l$F$$$k!#$^$?(B Tomcat 5.5.x $B$G$O2sHr:v(B (Host Manager $B$G$N:n6H=*N;;~$K%m%0%"%&%H$9$k(B) $B$r

$B"#(B $BDI5-(B

Vulnerability Note VU#724968: RSA key reconstruction vulnerability

$B!!(BJVNVU#724968: RSA key reconstruction vulnerability

Apple $BJ}LL(B (2007.08.02)

$B!!(BAbout the security content of iPhone v1.0.1 Update $B$K$O(B 5 $B$D$N7g4Y$,7G:\$5$l$F$$$k$N$@$,!"$=$N$&$A(B CVE-2007-3944 $B$O!V8E$$%P!<%8%g%s$N(B PCRE (6.2) $B$r;H$C$F$$$?!W$N$,860x$J$N$@$=$&$@!#(B PCRE 6.7 $B$G=$@5$5$l$?7g4Y$rFM$+$l$?LOMM!#(B $B;2>H(B: Zero-day attacks on the iPhone via outdated applications (McAfee blog, 2007.08.13)$B!"(B iPhone$B$N@H (ITmedia, 2007.08.14)

Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (931768) (MS07-027)

$B!!>e5-$N(B "Temporary Internet Files" $B$NLdBj$O!"(B MS07-045 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (937143) (Microsoft) $B$G=$@5$5$l$^$7$?!#4XO"(B: IE August Security Update is Now Available (IEblog, 2007.08.14)

64-bit Driver Signing on Windows Vista $B!>!F(BComputer Says No$B!G(B

$B!!4XO"(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (932596) $B%+!<%M%k=$@5$NJ]8n$r2~A1$9$k99?7%W%m%0%i%`(B (Microsoft, 2007.08.15)

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B

$B!!40A4HGEP>l!#(B

$B!!4XO"(B: 8$B7n$N%^%$%/%m%=%U%H%;%-%e%j%F%#99?7$r3NG'$9$k(B (Internet Watch, 2007.08.15)

$B"#(B $B%&%$%k%9Dj5A%U%!%$%k$N99?7$r9T$&$H!"(BWindows$B$,DL>o%b!<%I$G5/F0$7$J$/$J$C$?(B
($B%8%c%9%H%7%9%F%`(B, 2007.08.15)

$B!!(BWindows Vista $B>e$N(B Kaspersky Internet Security 6.0 $B$K$*$$$F!"(B 2007$BG/(B8$B7n(B15$BF|(B17$B;~(B50$BJ,!A(B20$B;~(B10$BJ,$K%&%$%k%9Dj5A%U%!%$%k$N99?7$r9T$C$F$$$?>l9g!"(BWindows$B$,DL>o%b!<%I$G5/F0$7$J$/$J$C$F$$$?$=$&$G$9!#(BLaut $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#BP1~J}K!$H$7$F$O!"%;!<%U%b!<%I$G5/F0$7$F(B klif.sys $B$r:o=|$7!"DL>o%b!<%I$G:F5/F0$7$F$+$i(B Kaspersky Internet Security 6.0 $B$r%"%s%$%s%9%H!<%k$7!":F%$%s%9%H!<%k$9$k$9$k$N$@$=$&$G$9!#(B

$B"#(B Yahoo! Messenger$B$K%<%m%G%$$N@H
(ITmedia, 2007.08.15)

$B!!(BMcAfee blog $B$N5-;v(B:

$B!!!VCf9q8l%U%)!<%i%`!W$H$$$&$N$O(B xfocus.net $B$@$=$&$G$9!#(B

$B!!(BYahoo! Messenger $B%P!<%8%g%s(B 8.1.0.413 $B$K$*$$$F:F8=$K@.8y$7$?$=$&$G!#$I$&$d$i(B Yahoo! Messenger $B$N%3%s%]!<%M%s%H(B Yahoo! Webcam $B$K$*$1$k(B invite $B$N=hM}$K(B heap overflow $B$9$kLdBj$,$"$k$h$&$G$9!#=$@5%W%m%0%i%`$O$^$@$"$j$^$;$s!#(B

2007.08.24 $BDI5-(B:

$B!!(B$BJF%d%U! (CNET, 2007.08.24)

2007.08.28 $BDI5-(B:

$B!!F|K\8lHG$N(B Yahoo! $B%a%C%;%s%8%c!<$K$b7g4Y$,$"$C$?$h$&$G!"99?7$N0FFb$,=P$F$$$^$9!#(B

$B!!1Q8lHG$O$3$A$i(B:

$B"#(B Opera$B%V%i%&%6$K?<9o$J@H
(ITmedia, 2007.08.16)

$B!!(BOpera 9.23 $BEP>l!#(BAdvisory: a specially crafted JavaScript can make Opera execute arbitrary code (Opera) $B$G2r@b$5$l$F$$$k!"96N,(B JavaScript $B$K$h$C$FG$0U$N%3!<%I$rCVE-2007-4367

$B!!(B$B@hF|$N(B BlackHat $B$G8x3+$5$l$?(B fuzzer $B$r;H$C$FH/8+$5$l$?$=$&$G!#(B $B>\:Y(B: Bug 349611 (jsfunfuzz) - Jesse's JavaScript compiler/decompiler fuzzer


$B"#(B 2007.08.15

$B"#(B $BF|K\$K$*$1$k>>2
($B%N%-%"(B, 2007.08.14)

$B!!%N%-%"@=7HBSEEOC$KEc:\$5$l$F$$$k>>2oH/G.!W$,H/@8$9$k2DG=@-$,$"$j!"%o!<%k%I%o%$%I$G8r49$r9T$&!#(BVodafone 702NKII + BL-5C $B$G$N2$N0lIt$J$I$,>G$2$k!W$J$I$NHo32$,=P$F$$$k!#(B $B_@ED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2005$BG/(B12$B7n$+$i(B2006$BG/(B11$B7n$K>>2]$H$J$j$^$9!#$=$NB>$NEECS%Q%C%/$O<+]$G$O$"$j$^$;$s!#(B

$B!!BP>]%P%C%F%j$N>\:Y$K$D$$$F$O(B Product Advisory: Nokia BL-5C battery $B$r;2>H!#(B 4600 $BK|8D$G$9$+!D!D!#(B

$B!!4XO"(B: $B>>2 (slashdot.jp, 8/14)$B!#(B #1205303 $B$N%9%l%C%I$,6=L#?<$$!#(B


$B"#(B 2007.08.11

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2007 $BG/(B 8 $B7n(B
(Microsoft, 2007.08.10)

$B!!=P$F$^$9!#6[5^(B: 5$B!"=EMW(B: 3 $B$G$9$+!#(B

2007.08.16 $BDI5-(B:

$B!!40A4HGEP>l!#(B

$B!!4XO"(B: 8$B7n$N%^%$%/%m%=%U%H%;%-%e%j%F%#99?7$r3NG'$9$k(B (Internet Watch, 2007.08.15)

2007.08.19 $BDI5-(B:

$B!!4XO"(B: Detection and deployment guidance for the August 14, 2007 security release (Microsoft)

2007.08.23 $BDI5-(B:

$B!!(BMS07-047 patch (936782) $B$rE,MQ$9$k$H!"(BWindows Media Player $B$G(B .swf $B%U%!%$%k$r3+$1$J$/$J$kI{:nMQ$,$"$k$N$@$=$&$G$9!#(B

$B!!$3$l$r2sHr$9$k$K$O!"!V?7$7$$%P!<%8%g%s$N(B Adobe Flash Player $B$r%$%s%9%H!<%k!W$9$k$N$@$=$&$G$9!#2?$HHf$Y$F!V?7$7$$%P!<%8%g%s!W$J$N$+$,$I$3$K$bL@5-$5$l$F$$$^$;$s$,(B (OS $BI8=`E:IUIJ$G$9$+$M$'(B)$B!">/$J$/$H$b:G?7HG$G$"$k(B Flash Player v.9.0.47 $B$G$"$l$PLdBj$J$$$h$&$G$9!#(B Benjamin $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2007.08.24 $BDI5-(B:

$B!!(BTechNet Webcast: $B:#7n$N%o%s%]%$%s%H(B $B%;%-%e%j%F%#>pJs(B (Microsoft) $B$K$h$k$H!"(BWindows Media Player 10 / 11 + Flash Player 6 $B$N>l9g$K:G?7$N(B Flash Player $B$N%$%s%9%H!<%k$rMW5a$5$l$k$3$H$,$"$k$N$G!"$=$N>l9g$K$O:G?7$N(B Flash Player $B$rF~$l$F$*$1!"$H$$$&$3$H$_$?$$$G$9!#$9$:$-$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2007.08.30 $BDI5-(B:

$B!!(BMS07-044, MS07-045, MS07-046, MS07-047 $B$,2~D{$5$l$F$$$^$9!#(B

$B!!$*$^$1(B: Technical Tips and Insights on MS07-049 and MS07-044 (MSRC blog, 2007.08.23)

2007.09.28 $BDI5-(B:

$B!!(BMS07-042 - $B6[5^(B: XML $B%3%"(B $B%5!<%S%9$N@H $B$,2~D{$5$l$F$$$k!#(B

  1. $BBP>]%=%U%H%&%'%"$K0J2<$rDI2C(B

    • Word$B!"(BExcel $B$*$h$S(B PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/(B
    • Microsoft Expression Web

    $B$3$l$i$r%$%s%9%H!<%k$7$F$$$k>l9g$O!"4{$K(B Microsoft Update $B$J$I$rDL$8$F(B patch $B$,E,MQ$5$l$F$$$k$O$:!#(B

  2. Windows Vista $B$K$*$1$k(B Microsoft XML $B%3%"(B $B%5!<%S%9(B 4.0 $BMQ(B patch $B$N8_49@-$H0BDj@-$r2~A1$9$k(B patch $B$,=P$?$N$G!"$=$l$N0FFb!#(B

2007.10.19 $BDI5-(B:

$B!!(BMS07-043 $B$K4XO"$9$k(B KB $B$,(B: You experience application performance issues after you install the update from security bulletin MS07-043 on a computer that is running Windows Server 2003 or Windows XP Professional x64 Edition (Microsoft KB943172)$B!#(BMS07-043 $B$rE,MQ$7$?(B 64bit $BHG$N(B Windows Server 2003 / XP $B$K$*$$$F!"(BOleaut32.dll $B$^$?$O(B Asycfilt.dll $B$r;HMQ$9$k%"%W%j%1!<%7%g%s$G%Q%U%)!<%^%s%9$NLdBj$,H/@8$9$kLOMM!#(B $B3:Ev$9$k%"%W%j%1!<%7%g%sNc$O(B Microsoft SQL Server Analysis Services $B$@$=$&$G!#(B $BM-=~(B patch $B$,$"$k$=$&$G$9!#(B

2007.11.16 $BDI5-(B:

$B!!(BMS07-049 - $B=EMW(B: Virtual PC $B$*$h$S(B Virtual Server $B$N@H:3J$,5/$3$k(B (937986) $B$,2~D{$5$l$^$7$?!#=$@5%W%m%0%i%`$N%$%s%9%H!<%i$,99?7$5$l$F$$$^$9(B ($BCf?H$OF1$8$G$9(B)$B!#(B

Microsoft Virtual PC 2004$B!"(BMicrosoft Virtual PC 2004 Service Pack 1$B!"(BMicrosoft Virtual Server 2005 Standard Edition $B$*$h$S(B Microsoft Virtual Server 2005 Enterprise Edition $BMQ$N%;%-%e%j%F%#99?7%W%m%0%i%`$O!"%l%8%9%H%j(B $B%-!<$NLdBj$N$?$a!"@5$7$/(B Windows 2000 Service Pack 4 $B$K%$%s%9%H!<%k$5$l$^$;$s$G$7$?!#(B $B8=:_!"(BWindows Server 2000 Service Pack 4 $B$K%$%s%9%H!<%k$9$k2~D{HG$N%;%-%e%j%F%#99?7%W%m%0%i%`$,MxMQ2DG=$G$9!#%^%$%/%m%=%U%H$O$*5RMM$K$G$-$k8B$jAa4|$K$3$N99?7%W%m%0%i%`$rE,MQ$9$k$3$H$r?d>)$7$^$9!#%;%-%e%j%F%#99?7%W%m%0%i%`$,@5>o$K%$%s%9%H!<%k$5$l$?%3%s%T%e!<%?$K$D$$$F$O2?$NA`:n$bI,MW$"$j$^$;$s!#(B

2007.12.04 $BDI5-(B:

$B!!(BMS07-042 - $B6[5^(B: XML $B%3%"(B $B%5!<%S%9$N@H $B$N(B patch $B$rE,MQ$9$k$H!"(B Web$B%"%W%j%1!<%7%g%s$K@x$`%;%-%e%j%F%#%[!<%k!!(B $BBh(B4$B2s(B $B%(%i!<%a%C%;!<%8$N4m81@-(B (@IT) $B$N:G8e$K$"$k!"(BTRACE $B%a%=%C%I$r(B ($BL5M}LpM}(B?) $B;H$&%9%/%j%W%H$,pJs$"$j$,$H$&$4$6$$$^$9!#(B

2007.12.08 $BDI5-(B:

$B!!(BMS07-042 - $B6[5^(B: XML $B%3%"(B $B%5!<%S%9$N@H $B$N(B patch $B$H(B TRACE $B%a%=%C%I$N7o$@$,!"(B@IT $B$N%9%/%j%W%H$O(B

  • Windows XP SP2 / Server 2003 SP1 $B0J9_$G$O!":G=i$+$i;H$($J$$!#(B
  • Windows 2000 $B$G$O!"(BMS07-042 patch $B$rE,MQ$9$k$H;H$($J$/$J$k(B

$B$H$$$&>u67$@$=$&$G$9!#;38}$5$sDI2C$N>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2007.08.09

$B"#(B Vulnerability Note VU#724968: RSA key reconstruction vulnerability
(cert.org, 2007.08.01)

$B!!J#?t$N(B RSA $B

$B!!(BOpenSSL 0.9.8e $B0JA0$K7g4Y!#(Bcrypto/bn/bn_mont.c $B$N(B BN_from_montgomery $B4X?t$K7g4Y$,$"$j!"(BMontgomery multiplication $B$,@5$7$/9T$o$l$J$$$?$a$K!"(Blocal user $B$,(B side-channel attack $B$rCVE-2007-3108

$B!!(BOpenSSL $B$N3+H/HG$G$O=$@5$5$l$F$$$k!#(BOpenSSL 0.9.8e $BMQ$N(B patch

2007.08.16 $BDI5-(B:

$B!!(BJVNVU#724968: RSA key reconstruction vulnerability

$B"#(B $B$$$m$$$m(B (2007.08.09)
(various)

$B"#(B $BDI5-(B

$B0lB@O:$N@H

$B!!=$@5%W%m%0%i%`$,8x3+$5$l$^$7$?!#(B $B0lB@O:$N@H ($B%8%c%9%H%7%9%F%`(B) $B$+$iF~

$B!!4XO"(B: JVNVU#343727: $B0lB@O:%7%j!<%:$KG$0U$N%3!<%I$, (JVN)$B!"(BCVE-2007-4246

64-bit Driver Signing on Windows Vista $B!>!F(BComputer Says No$B!G(B

$B!!4XO"(B:

$B"#(B Cisco $BJ}LL(B
(various)

$B"#(B $B$[$s$H$&$OI]$$9q:]2=%I%a%$%sL>(B
($B?eL57n$P$1$i$N$($SF|5-(B, 2007.08.03)

$B!!(BJVN#16018033 $B!V(BSafari$B!W$K$*$1$k(B URL $B$NI=<(56Au$N@H $B$O!"(BIDN $B$r;H$C$F%5%V%I%a%$%sCf$N(B / $B$r56Au$9$kOC$@$C$?$N$G$9$+!#(B $B$($SF|5-$5$s$N%Z!<%8$G<($5$l$F$$$kNc$K%"%/%;%9$9$k$H!"(BOpera 9.22 $B$G$O(B opera:illegal-url-3 $B$,<($5$l$^$7$?!#(B


$B"#(B 2007.08.08

$B"#(B $BDI5-(B

64-bit Driver Signing on Windows Vista $B!>!F(BComputer Says No$B!G(B

$B!!4XO"(B: $B%^%$%/%m%=%U%H!"(BVista$B$N=pL>G'>Z2sHr%D!<%k$KBP93!=!=%D!<%k$N=pL>%-!<$rL58z2=(B (computerworld, 2007.08.07)


$B"#(B 2007.08.07

$B"#(B Atom $B$d(B RDF $B$rMxMQ$7$?(B XSS
($BMU$C$QF|5-(B, 2007.08.01)

$B!!(Bwith$B!V(BInternet Explorer $B$N0-L>9b$$(B Content-Type: $BL5;k$H$$$&;EMM!W!"$@$=$&$G$9!#(B

$B"#(B IE6$B$r0l9T$G%/%i%C%7%e$5$;$k%3!<%I(B
(slashdot.jp, 2007.08.06)

$B!!(BIE 6 / 7 DoS $B$M$?!#(BIE DoS $B$M$?$C$FB>$K$b$$$m$$$m$"$j$^$9$1$I!"%?%l9~$s$@?M$HJT=8$N%V%i%&%6$r;H$$$^$7$g$&!#(B $BB>$N%V%i%&%6$K$OJL$N(B DoS $B$M$?$,$"$k$+$b$7$l$^$;$s$1$I$M!#(B

$B$9$0%/%i%C%7%e>uBV$@$1$I!"%[%s%H$K(BHotfix$B=P$k$N$+$J!)(B

$B!!=P$k$o$1$J$$$N$G$40B?4$/$@$5$$!#$7$+$7!"$3$N7o$G$N%/%i%C%7%e%l%]!<%H$,;3$N$h$&$KMh$l$P!"$=$l$@$1=$@5$5$l$k2DG=@-$O9b$/$J$k$G$7$g$&!#$G$9$+$i!"!V$3$NLdBj$r(B Microsoft $B$KJs9p$7$F$/$@$5$$!W$J%@%$%"%m%0$G$O(B [$B%(%i!

$B"#(B $BDI5-(B

$B0lB@O:$N@H

$B!!4XO"(B:

$B"#(B 64-bit Driver Signing on Windows Vista $B!>!F(BComputer Says No$B!G(B
(Symantec blog, 2007.08.06)

$B!!(BWindows $B%+!<%M%k>e$KFH<+$N(B PE $B%m!<%@$rAtsiv $B$H$$$&$b$N$,$"$k$N$@$=$&$G$9!#(B

Atsiv is a command line tool that allows the user to load and unload signed or unsigned drivers on 32 bit (x86) and 64 bit (x64) versions of Windows XP, Windows 2K3 and Windows Vista. Atsiv is designed to provide compatibility for legacy drivers and to allow the hobbyist community to run unsigned drivers without rebooting with special boot options or denial of service under Vista.

$B!!$3$l$KBP93$9$k$?$a$K!"(BMicrosoft $B$O(B Atsiv $B<+?H$KBP$9$kG'>Z$rC$7$?$N$@$=$&$G$9!#(Bx64 Driver Signing Update (Windows Vista Security, 2007.08.03) $B$r;2>H!#(B

$B!!4XO"(B: Driver Signing on Vista 64-bit - Using the Process against Itself (symantec blog, 2007.07.27)

2007.08.08 $BDI5-(B:

$B!!4XO"(B: $B%^%$%/%m%=%U%H!"(BVista$B$N=pL>G'>Z2sHr%D!<%k$KBP93!=!=%D!<%k$N=pL>%-!<$rL58z2=(B (computerworld, 2007.08.07)

2007.08.09 $BDI5-(B:

$B!!4XO"(B:

2007.08.16 $BDI5-(B:

$B!!4XO"(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (932596) $B%+!<%M%k=$@5$NJ]8n$r2~A1$9$k99?7%W%m%0%i%`(B (Microsoft, 2007.08.15)

2007.08.27 $BDI5-(B:

$B!!4XO"(B:


$B"#(B 2007.08.06

$B"#(B $BDI5-(B

$B"#(B $B$$$m$$$m(B (2007.08.06)
(various)


$B"#(B 2007.08.05


$B"#(B 2007.08.04


$B"#(B 2007.08.03

$B"#(B $B0lB@O:$N@H
($B%8%c%9%H%7%9%F%`(B, 2007.08.03)

$B!!0lB@O:(B 11 / 12 / 13 / 2004 / 2005 / $BJ8i:(B / 2006 / $B%,%P%a%s%H(B 2006 / 2007 / 2007 $BBN83HG(B / $B%,%P%a%s%H(B 2007$B!"$*$h$S0lB@O:%S%e!<%"$K(B 0-day $B$J7g4Y!#(B $B4{$K$3$l$rMxMQ$9$k96N,0lB@O:%U%!%$%k$,Ln$KJ|$?$l$F$$$k(B: Unknown Exploit Compromises Ichitaro (symantec blog, 2007.08.02)$B!"(BTrojan.Tarodrop.D (Symantec)$B!#(B Trojan.Tarodrop.D $B$O(B Hacktool.Keylogger $B$r@_CV$7!"(BHacktool.Keylogger $B$O(B cvnxus.8800.org:443 $B$K>pJs$rO31H$5$;$k$=$&$G$9!#(B

$B!!=$@5%W%m%0%i%`$O8=:_3+H/Cf!#%$%s%?!<%M%C%H$r7PM3$9$k0lB@O:%U%!%$%k$K$O==J,Cm0U$5$l$?$$!#(B

2007.08.06 $BDI5-(B:

$B!!$h$/$h$/9M$($k$H!"%8%c%9%H%7%9%F%`$O:#$d(B Kaspersky $B$r07$C$F$$$k2qpJs$O0l@Z8x3+$5$l$F$$$J$$$h$&$K8+$($k!#(B $B$3$l$C$F$^$:$$$N$G$O(B > $B%8%c%9%H%7%9%F%`!#(B

2007.08.07 $BDI5-(B:

$B!!4XO"(B:

2007.08.09 $BDI5-(B:

$B!!=$@5%W%m%0%i%`$,8x3+$5$l$^$7$?!#(B $B0lB@O:$N@H ($B%8%c%9%H%7%9%F%`(B) $B$+$iF~

$B!!4XO"(B: JVNVU#343727: $B0lB@O:%7%j!<%:$KG$0U$N%3!<%I$, (JVN)$B!"(BCVE-2007-4246

2007.09.05 $BDI5-(B:

$B!!(BA Closer Look at Ichitaro (trendmicro blog, 2007.09.03)

2007.11.01 $BDI5-(B:

$B!!4XO"(B: $B0lB@O:(Bplug-in$B$r(BIE$B$H(BFirefox$B$GL58z$K(B $B!A(B $B%8%c%9%H%7%9%F%`$OK\Ev$N6<0R$r65$($F$/$l$J$$(B ($B9bLZ9@8w!w<+Bp$NF|5-(B, 2007.10.30) $B$NA0H>ItJ,!#(B

$B"#(B WordPress$B$H(BJoomla$B$N%F%s%W%l!<%H$K%9%Q%`$d%^%k%&%'%"$N%j%s%/$,:.F~(B
(gigazine, 2007.08.03)

$B!!FGF~$j%F%s%W%l!<%H$rG[$C$F$$$k%5%$%H$,$"$k$h$&$G$9!#(B

$B"#(B $BDI5-(B

$B"#(B Thunderbird 2.0.0.6 $B%j%j!<%9%N!<%H(B
(mozilla-japan.org, 2007.08.01)

$B!!(BThunderbird 2.0.0.6 $BEP>l!#(BFirefox 2.0.0.6 $B$HF1MM$N%;%-%e%j%F%#=$@5$,9T$o$l$F$$$k!#(B


$B"#(B 2007.08.02

$B"#(B Apple $BJ}LL(B (2007.08.02)
(Apple, 2007.08.01)

2007.08.16 $BDI5-(B:

$B!!(BAbout the security content of iPhone v1.0.1 Update $B$K$O(B 5 $B$D$N7g4Y$,7G:\$5$l$F$$$k$N$@$,!"$=$N$&$A(B CVE-2007-3944 $B$O!V8E$$%P!<%8%g%s$N(B PCRE (6.2) $B$r;H$C$F$$$?!W$N$,860x$J$N$@$=$&$@!#(B PCRE 6.7 $B$G=$@5$5$l$?7g4Y$rFM$+$l$?LOMM!#(B $B;2>H(B: Zero-day attacks on the iPhone via outdated applications (McAfee blog, 2007.08.13)$B!"(B iPhone$B$N@H (ITmedia, 2007.08.14)

$B"#(B FreeBSD $BJ}LL(B
(FreeBSD, 2007.08.02)

$B"#(B $BDI5-(B


$B"#(B 2007.08.01

$B"#(B $B$$$m$$$m(B (2007.08.01)
(various)


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B