$B%;%-%e%j%F%#%[!<%k(B memo - 2008.01

Last modified: Mon Nov 24 12:00:34 2008 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2008.01.31


$B"#(B 2008.01.30

  • $B!U(B VirusScan Enterprise$B$G<+F0%"%C%W%G!<%H%?%9%/!&(BMirror$B%?%9%/$,<:GT$7$?;~$K3NG'$9$Y$-9`L\$O!)(B ($B%^%+%U%#!<(B, 1/29)

  • $B!U(B Name (mDNS) Poisoning Attacks inside the LAN (gnucitizen, 1/23)$B!#(BMulticast DNS $B$NOC!#(B

  • $B!U(B Google Hacking for Penetration Testers Second Edition (gnucitizen, 1/3) $B$H$$$&K\$,=P$F$$$k$=$&$G!#(B

  • $B!U(B Harada Writers Busted for Copyright Violations (trendmicro blog, 1/28)$B!#(B $B!V86ED%&%$%k%9!W$K$D$$$F(B ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 1/25) $B$NA}Jd1QLuHG$+$J!#(B

  • $B!U(B Tomcat$B$O$I$3$^$G!H0BA4!I$K$G$-$k$N$+!)!J(B4$B!K(B Tomcat$B$N%;%-%e%j%F%#$H%j%9%/$N4pK\(B $BJ,$+$C$F$k!)(B (@IT, 1/28)

  • $B!U(B $B!V%5%$%>! (SLAPP WATCH, 1/30)

  • $B!U(B $B!V$D$J$.K!0F!W$N9KEO$j!"M?LnE^96KI$NCf$GG/6b ($BJ]:dE8?M$N$I$3$I$3F|5-(B, 1/29)

  • $B!U(B Flash Player 9.0.115.0 for Solaris now availalbe (Emmy Huang$B!"(B 1/29)

  • $B!U(B $B%&%$%k%9%P%9%?!<$N99?7$,$G$-$J$$!*(B (Moto's Page - Diary, 1/29)$B!#(B1/18 $B0J9_!"99?7$K<:GT$7$F$$$?OC!#(B $B%&%$%k%9%P%9%?!<(B 2008 $B$G$O4{CN$NLdBj$@$C$?LOMM(B: $B%"%C%W%G!<%HuBV$r3NG'$7!":FEY ($B%H%l%s%I%^%$%/%m(B)$B!#(B patch $B$"$j!#$3$N(B patch $B$O:G?7$N(B 16.05 $BHG(B$B$K$b4^$^$l$F$$$k$=$&$G!#(B

  • $B!U(B $B85FCA\8!;v$NEDCf?90l$5$s$,8l$k!A!VD4=q$O$$$+$K$7$F:n@.$5$l$k$+!W(B(JANJAN, 1/30) (JANJAN, 1/30)

  • $B!U(B $B?7$7$$8x6&$H;TL1<+<#!]!V8B3&=8Mn!W$H;}B3IT2DG=$J (JANJAN, 1/30)

  • $B!U(B $B=w@-<+1R41$N$o$$$;$DHo32!!I9;3$N0l3Q$+(B (JANJAN, 1/30)

  • $B!U(B $BCSED?.IW;a$K$h$kL>M@TLB;$K$J$k$+$b$7$l$J$$Z5rJ]A4(B ($B0-FA>&K!!)%^%K%"%C%/%9(B $B%3%3%m%0;YE9(B, 1/29)

  • $B!U(B $B9k(BCSIRO$B$H8E2OEECS$N!X%&%k%H%i%P%C%F%j! (WIRED VISION, 1/30)

  • $B!U(B $B2$=#:[H==j!"L1;vAJ>Y$N>l9g!!3Z6J$N0cK!8r49$r3+<($9$k5AL3$O$J$$(B (technobahn, 1/30)

  • $B!U(B $B!N(BWSJ$B!O(B $B%V%C%7%e@/8"!"%5%$%P!<967bBP:v$K(B60$B2/%I%k!)(B $BMh7nDs=PM=Dj$NM=;;0F$G!"JF9q$NDL?.LV$r (ITmedia, 1/29)

  • $B!U(B $B:GBg$N(BP2P$B%M%C%H%o!<%/$O(BThePrivateBay (yohgaki's blog, 1/27)

  • $B!U(B Latest findings about the Random JavaScript Rootkit (servertune.com, 1/26)

    The cPanel Security Team has recognized that the vast majority of affected systems are initially accessed vai shell (SSH) with no indications of brute force or exploitation of the underlying service. Despite non-trivial passwords, intermediary users and nonstandard ports, the attacker is able to gain access to the affected servers with no password failures. The cPanel security team also recognized that the vast majority of affected servers come from a single undisclosed data-center. All affected systems have password based authentication enabled. Based upon these findings, the cPanel security team believes that the attacker has gained access to a database of root login credentials for a large group of Linux servers. Once the hacker, manually, gains access to a system they can then perform various tasks. The hacker can download, compile, and execute a log cleaning script in order to hide their tracks. They also can download a customized Rootkit based off of Boxer version 0.99 beta 3. Finally, the hacker searches for files containing credit card related phrases such as CVC, CVV, and/or Authorize.

    $B!!%G!<%?%;%s%?!<$N4IM}MQ$N%"%+%&%s%H%G!<%?%Y!<%9$r%O%/$i$l$?$N$G$O$J$$$+!"$H$$$&$3$H$G$9$+!#$=$3$+$i@55,$N4IM}%"%+%&%s%H$rF~Boxer 0.99 beta 3 ($B%Q%9%o!<%I(B) $B%Y!<%9$N(B rootkit $B$r;E3]$1$?$j$7$?$H!#(B

  • $B!U(B 11S + TOMOYO(R) Linux$B%5%]!<%H$G0B?4!&2wE,$J%5!<%P!<1?MQ4D6-$r (Turbolinux, 1/29)

  • $B!U(B $B7HBS%U%#%k%?%j%s%0!"AmL3>J$,!H2a>j5,@)!I$K!VBT$C$?!W(B ($B;:7P(B / ITmedia, 1/29)

    $B7HBS%-%c%j%"$,?J$a$F$$$k%U%#%k%?%j%s%0$O7rA4$J%5%$%H$b%7%c%C%H%"%&%H$7$F$7$^$&!H2a>j5,@)!I$G$"$j!"LdBj$@(!(!$H!"%U%#%k%?%j%s%0$rMW@A$7$?Ev$NAmL3>J$,BT$C$?$r$+$1$h$&$H$7$F$$$k!#(B

    $B!!4XO"(B: $B!V%*%s!&%*%U$@$1$N%U%#%k%?%j%s%0$OL51W!W;\:v$N:F8!F$$r5a$a$k@<$b!!(B $BAmL3>J$N8!F$2q$G%d%U! (Internet Watch, 1/30)

  • $B!U(B $B4IM}?&$N$_$J$5$s!"K\Ev$K!V4IM}?&!W$G$9$+!)(B (slashdot.jp, 1/29)$B!#(B $B:#F|$+$i7/$O4IM}?&$@(B $B$K$O>P$C$?!#(B($B%k!<%D(B$B$r8+$F$$$J$$$H$o$+$i$J$$%.%c%0$@$1$I!D!D(B) ($B$b$7$+$7$?$i%.%c%0$8$c$J$$$N$+$b(B)

  • $B!U(B $BFf$N3$MNL1B2%b!<%1%s(B($B2>!K(B (NHK $B%9%Z%7%c%k(B, 2/17 $BJ|AwM=Dj(B)$B!#(B$B%&%)!<%?!<%o!<%k%I(B $B$rCO$G9T$/$h$&$J?MC#$J$N$+(B? $B!V%b!<%1%s!W$G$0$0$k(B$B!#(B

  • $B!U(B $BMxMQN((B7$B3d$N(BWEP$B$O!V(B1$BJ,!W$GGK$i$l$k(B ($BF|7P(B IT Pro, 1/26)$B!#(B$B%P%K%7%s%0(B IN 60" $B$H$$$&$3$H$G!#(B

  • $B!U(B $BD;%$%s%U%k%(%s%6J}LL(B

    $B!!$A$J$_$K!"!V30It$+$iN.F~$7$h$&$H$9$kGZ$OA40wLdEzL5MQ$G(B 5 $BF|4VJD$8$3$a!"2?$iH/>I$7$J$$>l9g$K$N$_

  • $B!U(B Linux/Apache$B$rA@$C$?967b(B - $B3NG'J}K!$O(Bmkdir 1 (yohgaki's blog, 1/28)

  • $B!U(B $B!c662 (ESPIO, 1/28)

  • $B!U(B Wikipedia $B"A(B Winny $B$G2?$,H=$k$+(B ($B9bLZ9@8w!w<+Bp$NF|5-(B, 1/27)$B!#6=L#?<$$!#(B

  • $B!U(B Vista SP1 RC$B$N!H%j%U%l%C%7%e!IBh(B2$BHG$,%j%j!<%9!!(B $B0[Nc$N2~D{HGG[I[$O(BMicrosoft$B$N?5=E$5$NI=$l!)(B (computerworld, 1/28)

  • $B!U(B $BCf9qH/$N%l%]!<%H$G8+$($?0G;T>l!!HH:a ($BF|7P(B IT Pro, 1/29)

  • $B!U(B $BJF9q@/I\$N$<$$ ($BF|7P(B IT Pro, 1/22)$B!"(B $BJF9q@/I\$N$<$$ ($BF|7P(B IT Pro, 1/29)

  • $B!U(B $BL@F|!"M=;;0Q0w2q$G!VG/6bAR8K!W$N:FD4::MW5a$X(B ($BJ]:dE8?M$N$I$3$I$3F|5-(B, 1/28)$B!#:rF|$NM=;;0Q0w2q$G$J$5$l$?$O$:$J$N$@$J!D!D!#(B

  • $B!U(B $B$=$b$=$bI=8=$H$O2A$r$a$0$k2?$+!!!JN.BP6(%;%_%J! (SLAPP WATCH, 1/29)

  • $B!U(B $B%"%C%W%k$K$h$k(BSLAPP (SLAPP WATCH, 1/28)

  • $B!U(B $B;d$O%&%$%k%9$r:n$C$?$3$H$,$"$k(B (hoshikuzu | star_dust dairy, 1/29)$B!#(B hoshikuzu $B$5$s$OA4$F$o$+$C$?>e$G9TF0$5$l$?$N$G$7$g$&$,!"(B $BA16L%&%$%k%9J}<0$O4m81@-$,6K$a$F9b$$J}K!$J$N$G!"0lHL$K$O$*$9$9$a$G$-$^$;$s!#(B

  • $B!U(B Linux$B%G%9%/%H%C%W$r%;%-%e%"$K$9$k$?$a$NJ}K!$r%;%l%V$KJ9$$$F$_$?(B (Open Tech Press, 1/29)$B!#%+!<%M%k%O%C%+!<$KJ9$/$N$O4V0c$C$F$k$h$&$J5$$,!#(B

  • $B!U(B Microsoft$B!"(BOffice 2003 SP3$B$N<+F099?7$r(B2$B7n(B27$BF|$h$j3+;O!!(B $B!V(B30$BF|A09pCN$O8xLs$I$*$j!W$HF1 (computerworld, 1/29)

  • $B"#(B $BDI5-(B

    APSA07-06: Vulnerabilities in some SWF files could allow cross-site scripting

    $B!!F|K\8lHG(B:

    $B$$$m$$$m(B (2008.01.16)

    $B!!(BFreeBSD-SA-08:02.libc - inet_network() buffer overflow $B$HF1$8OC$O(B bind $B$K$b$"$C$?$=$&$G!#(B


    $B"#(B 2008.01.29

    $B"#(B $BDI5-(B

    $B%^%$%/%m%=%U%H(B 2008 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B

    $B!!(BMS08-001 $B4XO"(B:


    $B"#(B 2008.01.28

    $B"#(B $B$$$m$$$m(B (2008.01.28)
    (various)

    $B"#(B $BDI5-(B

    $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H

    $B!!(BNetnote $B$NBP1~%b%8%e!<%k$,MQ0U$5$l$?!#(B

    $B"#(B Stop error message on a Windows Server 2003-based computer that has Symantec AntiVirus software installed: "Stop 0x0000007f"
    (Microsoft, 2008.01.21 $B99?7(B)

    $B!!(BSymantec AntiVirus Corporate Edition 8.0 / 9.0 / 10.0 $B$^$?$O(B Symantec Client Security 3.0 $B$r(B Windows NT / 2000 / XP / Server 2003 $B$K%$%s%9%H!<%k$7$F:F5/F0$9$k$H!"(Bkernel stack $B$r;H$$@Z$C$F%V%k!<2hLL$K$J$k$3$H$,$"$kLOMM!#(B $B>\:Y$H2sHrJ}K!(B: Blue screen with "STOP 0x0000007f" error on Windows 2003/XP/2000/NT (Symantec)$B!#(BWindows 2000 Server + $B%?!<%_%J%k%5!<%S%9$N4D6-$G$"$j$,$A$i$7$$!#(B


    $B"#(B 2008.01.27

    $B"#(B $B@HpJs$N8xI=$K4X$9$k5?Ld(B
    ($B$R$0$^$N$R$^%0(B, 2008.01.27)

    $B!!0l8@$G8@$&$H!"(B $B>pJs%;%-%e%j%F%#Aa4|7Y2|%Q!<%H%J!<%7%C%W(B $B$O5!G=$7$F$$$J$$$I$3$m$+32$K$9$i$J$C$F$$$k!"$H$$$&$3$H$G$9$J!#(B

    $B"#(B Firefox chrome: URL Handling Directory Traversal.
    (hiredhacker.com, 2008.01.19)

    $B!!$=$b$=$b!V?.Mj$G$-$J$$5!G=3HD%$O%$%s%9%H!<%k$7$F$O$$$1$^$;$s!W$H$$$&OC$O$"$k$o$1$G$9$,!"$@$+$i$H8@$C$F$&$l$7$$OC$G$b$J$$$o$1$G!#(B NoScript $B$r%$%s%9%H!<%k$7$F$"$l$PKI;_$G$-$k$h$&$G$9!#(B $B$^$?(B Firefox 2.0.0.12 $B$G=$@5$5$l$k$h$&$G$9!#(B

    2008.02.01 $BDI5-(B:

    $B!!$D$E$-!#(B

    $B!!(BFirefox 2.0.0.12 $B$G=$@5$5$l$kM=Dj$J$N$OF1$8!#(B


    $B"#(B 2008.01.26


    $B"#(B 2008.01.25

    $B"#(B Apache httpd$B@H2A$OIT==J,(B (Apache mod_negotiation Xss and Http Response Splitting)
    (yohgaki's blog, 2008.01.24)

    $B!!(BApache 1.3.x / 2.0.x / 2.2.x $B$N(B mod_negotiation $B$K$*$1$k(B 300 $B1~Ez$H(B 406 $B1~Ez$K$O(B XSS / Http Response Splitting $B7g4Y$,$"$k$H$$$&OC!#(B CVE-2008-0455 CVE-2008-0456

    $BNc$($P(BSecunia$B$N(BApache httpd 2.2$B$N@H2A$5$l$F$$$^$9!#(B
    http://secunia.com/advisories/28046/

    $B$3$3$K$O(Bmod_negotiation$B@H

    $B!!5-=R$,$J$$$N$O!"D>$C$F$$$J$$$+$i$J$N$G$O!#(B Minded Security Labs: Advisory #MSA01150108 - Apache mod_negotiation Xss and Http Response Splitting $B$K$O!V(BApache 1.3.41 / 2.0.63 / 2.2.8 $B$G=$@5$5$l$F$$$k!W$H$O0l8@$b=q$+$l$F$$$^$;$s$7!"$C$F$$$J$$$h$&$K8+$($^$9!#(B

    $B!!$H$j$"$($:!"(BOptions MultiViews $B$,@_Dj$5$l$F$$$k>l9g$O!"$=$l$r30$;$P2sHr$G$-$k$N$+$J$"!#(Bmod_negotiation $B$rL58z$K$G$-$l$P$=$NJ}$,3N

    $B!!(BCVE-2008-0455 CVE-2008-0456 $B$N(B Vendor Statements $B$G!"(BRed Hat $B$O$3$&8@$C$F$$$^$9(B:

    Official Statement from Red Hat (1/25/2008)
    We do not consider this issue to be security sensitive. Untrusted users should not be permitted to upload files to the directories from where they can be directly served by the web server without prior careful sanitation of both contents and filename.

    $B"#(B $BDI5-(B

    1/9 $B0J9_!"(BWindows VISTA $BEk:\(B $B%l%C%D%N!<%H$N%O!<%I%G%#%9%/$,FMA3;`$9$k2DG=@-$,$"$k(B

    $B!!(BKB $B=P$^$7$?(B: Windows Vista $B$G%9%?%s%P%$!"5Y;_>uBV$+$iI|5"8e$K%3%s%T%e!<%?$NEE8;$r@Z$k$H!"FCDj$N5!G=$r%5%]!<%H$7$F$$$k%O!<%I(B $B%G%#%9%/$,G'<1$5$l$J$/$J$k(B (Microsoft KB948023)$B!#=$@5(B patch $B$O$^$@$"$j$^$;$s$,!"(B

    $BCm(B : $B$3$NLdBj$O!"(BPower-Up In Standby $B5!G=(B ($BEE8;EjF~;~$K%9%?%s%P%$(B $B%b!<%I$K0\9T$9$k5!G=(B) $B$r%5%]!<%H$7$F$$$k%O!<%I(B $B%G%#%9%/$r;HMQ$7$?>l9g$KH/@8$7$^$9!#(B

    $B!!>r7o$N(B 1 $B$D$,3NDj$5$l$^$7$?!#(B


    $B"#(B 2008.01.24

    $B"#(B $B$$$m$$$m(B (2008.01.24)
    (various)


    $B"#(B 2008.01.23

    $B"#(B $BDI5-(B

    $B@lLg2H$,Z!"(BJavaScript$B%3!<%I$G%k!<%?$r>h$C

    $B!!$$$h$$$h8=

    Hacking The Interwebs

    $B!!(B$B!Z(B3$B![J#?t$N%G%P%$%9$K(B UPnP $B$K5/0x$9$k@H (JPCERT/CC REPORT 2008-01-23)


    $B"#(B 2008.01.22

    $B"#(B X.Org security advisory: multiple vulnerabilities in the X server
    (X.Org, 2008.01.18)

    $B!!(BX.Org xserve $B$KJ#?t$N7g4Y!#(B

    $B!!(BXorg xserver 1.4.1 $B$G=$@5$5$l$F$$$k!#$^$?(B xserver 1.2 / 1.4 $BMQ$N(B patch $B$,MQ0U$5$l$F$$$k!#(B

    2008.06.10 $BDI5-(B:

    $B!!(BJVN#88935101 - X.Org Foundation $B@=(B X $B%5!<%P$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H (JVN, 2008.06.10)$B!#(BCVE-2008-0006 - PCF Font parser buffer overflow $B$N7o!#(B

    $B"#(B SKYPE-SB/2008-001: Skype Cross Zone Scripting Vulnerability
    (Skype, 2008.01.18)

    $B!!(BSkype for Windows 3.5 / 3.6 $B$K7g4Y!#(B CVE-2007-5989

    $B"#(B $BDI5-(B

    Apache $B$KJ#?t$N7g4Y(B

    $B!!(BApache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability (CVE-2008-0005) $B$bD>$C$F$^$7$?!#(BProxyFtpDirCharset $B%G%#%l%/%F%#%V$,DI2C$5$l$F$$$^$9!#(B

    Hacking The Interwebs

    $B!!(BFlashing Home Routers (Symantec blog, 2008.01.21)

    1/9 $B0J9_!"(BWindows VISTA $BEk:\(B $B%l%C%D%N!<%H$N%O!<%I%G%#%9%/$,FMA3;`$9$k2DG=@-$,$"$k(B

    $B!!(BPanasonic $B$+$i>pJs=P$^$7$?(B: CF-R6M/CF-R6A$B%7%j!<%:$4;HMQ$N$*5RMM$X$N$40FFb(B (Panasonic, 2008.01.21)

    • CF-R6[MA] $B$N(B BIOS V1.00L13 / V2.00L10 $B$GH/@8(B
    • $B860x$O(B 943899 patch
    • $BBP1~HG(B BIOS $B$r8x3+(B (V1.00L14 / V2.00L13)

    $B!!8=>]$,4{$KH/@8$7$F$7$^$C$F$$$k>l9g$O!"$^$:$O@g@P;a$K$h$k(B USB Linux $B$J$I$r;H$C$F%O!<%I%G%#%9%/$rI|5l$5$;!"$=$N8e$K(B BIOS $B$r99?7$9$k!#(B


    $B"#(B 2008.01.21

    $B"#(B $BDI5-(B

    1/9 $B0J9_!"(BWindows VISTA $BEk:\(B $B%l%C%D%N!<%H$N%O!<%I%G%#%9%/$,FMA3;`$9$k2DG=@-$,$"$k(B

    $B!!@g@P;a$,!"$3$NLdBj$,H/@8$7$?>l9g$KMxMQ$9$k$?$a$N(B USB $B%V!<%H(B Linux $B$r!">\:Y$J2r@b$D$-$G8x3+$7$F$$$k!#(B

    $B!!$^$?!"%3%a%s%HMw$K$O(B ThinkPad T60 $B$GF1MM$N8=>]$,H/@8$7$?$H$N>pJs$,$"$j!"(B

    $B$A$J$_$K5! Model=Hitachi HTS541612J9SA00
    $B$H!"F10l$N(BHDD$B$NMM$G$9!#(B

    $B!!$U$%$`!D!D(B

    Apache $B$KJ#?t$N7g4Y(B

    $B!!(BApache 1.3.41 / 2.0.63 / 2.2.8 $B$,%j%j!<%9$5$l$^$7$?!#(Biida $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


    $B"#(B 2008.01.19

    $B"#(B APSA07-06: Vulnerabilities in some SWF files could allow cross-site scripting
    (Adobe, 2008.01.16 $B99?7(B)

    $B!!(BAdobe Dreamweaver CS3 $B$*$h$S(B Adobe Acrobat Connect $B$,@8@.$9$k(B SWF $B%U%!%$%k$K(B XSS $B7g4Y$,$"$kOC!#(B CVE-2007-6244 CVE-2007-6637

    2008.01.30 $BDI5-(B:

    $B!!F|K\8lHG(B:

    $B"#(B CORE-2007-1119: CORE FORCE Kernel Buffer Overflow
    (Core Security Technologies, 2008.01.18)

    $B!!(BCORE FORCE 0.95.167 $B0JA0$K7g4Y!#(BCORE FORCE $B$N%U%!%$%"%&%)!<%k%b%8%e!<%k(B (OpenBSD $B$N(B pf $B$r(B Windows $B$K0\?"$7$?$b$N(B) $B$*$h$S%l%8%9%H%j%b%8%e!<%k$K(B kernel buffer overflow $B$9$k7g4Y$,$"$j!"(Blocal user $B$K$h$k(B DoS $B967b$d8"8B>e>:$,2DG=!#(B

    $B!!(BCORE FORCE 0.95.172 $B$G=$@5$5$l$F$$$k!#$J$*!"(BCORE FORCE $B$O(B Windows 2000 / XP $B$GMxMQ$G$-$k!"%U%j!<$N%(%s%I%]%$%s%H%;%-%e%j%F%#%=%j%e!<%7%g%s$@$=$&$@!#(B

    $B"#(B [FIXED] Remote Denial of Service for SSH service at Dell DRAC4 (maybe Mocana SSH)
    (ETES GmbH, 2008.01.18)

    $B!!(BDell Remote Access Card 4 (DRAC4) Firmware Version 1.50 (Build 02.16) $B$KEc:\$5$l$F$$$k(B SSH $B%5!<%P(B (Mocana Embedded SSH Server $B$r%Y!<%9$K$7$?$b$N$H?dB,(B) $B$r(B Debian unstable $B>e$N(B nmap-4.03-3 $B$G(B nmap -O $B$9$k$H(B DoS $B>uBV$K$J$kOC!#$J$<$+(B nmap 4.20 $B$@$H$=$&$O$J$i$J$$$H$$$&!#(B CVE-2007-4360

    $B!!(BDRAC4 Firmware Version 1.60 (Build 10.04) $B$G=$@5$5$l$F$$$k!#(B


    $B"#(B 2008.01.18

    $B"#(B Vista TCP Window Scaling Auto Tuning May Slow Down Network Performance
    (My Digital Life, 2007.12.15)

    $B!!(BWindows Vista $B$K$O(B TCP $B$B$H$$$&5!G=$,?7$?$KEc:\$5$l$F$$$k$N$@$,!"$3$l$K$h$C$F5U$K!"%M%C%H%o!<%/%Q%U%)!<%^%s%9$,Dc2<$7$F$7$^$&;vNc$,$"$kLOMM!#(B

    $B!!F|K\9qFb$G$O%H%l%s%I%^%$%/%m$N%&%$%k%9%P%9%?!<(B 2007 / 2008 $B$H(B Vista $B$H$NJ;MQ;~$K8=>]$,3NG'$5$l$k;vNc$,B?$$$h$&$@$,!"$=$&$H$O8B$i$J$$;vNc$bB8:_$9$k!#(B

    $B!!LdBj$r2sHr$9$k$K$O!"DL>o$O!V(BTCP $B

    $B!!$J$*!"$3$N5!G=$O(B Windows Server 2008 $B$K$bB8:_$9$kLOMM!#(B

    $B"#(B Apollon$B%7%9%F%`!!@H
    ($BF|K\N99T(B, 2008.01)

    $B!!F|K\N99T$N(B Apollon $B%7%9%F%`(B $B$K7g4Y$,$"$j!"=$@5$5$l$?LOMM!#$I$N$h$&$J7g4Y$,$"$C$?$N$+!"$$$D=$@5$5$l$?$N$+$O$$$^(B 3 $B$D$[$IITL@!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    $B:#8e$O$40B?4$7$F$4MxMQ$$$?$@$/$3$H$,$G$-$^$9!#(B

    $B!!$3$l$^$G$O$I$NDxEY0B?4$G$-$J$+$C$?$s$G$7$g$&!D!D!#(B


    $B"#(B 2008.01.17

    $B"#(B $BDI5-(B

    $B%^%$%/%m%=%U%H(B 2007 $BG/(B 12 $B7n$N%;%-%e%j%F%#>pJs(B

    $B!!(BMS07-065 - $B=EMW!!(B $B%a%C%;!<%8(B $B%-%e!<$N@H $B$@$,!"

    2007 $BG/(B 11 $B7n$N%;%-%e%j%F%#>pJs(B

    $B!!(BMS07-061 $B$N4{CN$NLdBj(B: MS07-061: Vulnerability in Windows URI Handling could allow remote code execution (Microsoft KB943460)

    $B"#(B 1/9 $B0J9_!"(BWindows VISTA $BEk:\(B $B%l%C%D%N!<%H$N%O!<%I%G%#%9%/$,FMA3;`$9$k2DG=@-$,$"$k(B
    ($B@g@P9@L@$NF|5-(B, 2008.01.17)

    $B!!(BWindows Vista $B$r%$%s%9%H!<%k$7$?(B Panasonic Let's Note $B$K(B 943899 patch $B$r%$%s%9%H!<%k$9$k$H!"$=$N8e!"%O!<%I%G%#%9%/$,%9%T%s%"%C%W$7$J$$>l9g$,$"$kLOMM!#$3$N>l9g!"$J$<$+%O!<%I%G%#%9%/$N(B power-on in standby $B$,M-8z$K$J$C$F$7$^$C$F$$$k$h$&$G!"(B Linux $B$N(B hdparm $B%3%^%s%I$J$I$r;H$C$FL58z$K@_Dj$9$l$P!"$H$j$"$($:$O2r7h$9$kLOMM!#(B

    $B!!;vNc(B:

    $B!!:{It$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    2008.01.21 $BDI5-(B:

    $B!!@g@P;a$,!"$3$NLdBj$,H/@8$7$?>l9g$KMxMQ$9$k$?$a$N(B USB $B%V!<%H(B Linux $B$r!">\:Y$J2r@b$D$-$G8x3+$7$F$$$k!#(B

    $B!!$^$?!"%3%a%s%HMw$K$O(B ThinkPad T60 $B$GF1MM$N8=>]$,H/@8$7$?$H$N>pJs$,$"$j!"(B

    $B$A$J$_$K5! Model=Hitachi HTS541612J9SA00
    $B$H!"F10l$N(BHDD$B$NMM$G$9!#(B

    $B!!$U$%$`!D!D(B

    2008.01.22 $BDI5-(B:

    $B!!(BPanasonic $B$+$i>pJs=P$^$7$?(B: CF-R6M/CF-R6A$B%7%j!<%:$4;HMQ$N$*5RMM$X$N$40FFb(B (Panasonic, 2008.01.21)

    $B!!8=>]$,4{$KH/@8$7$F$7$^$C$F$$$k>l9g$O!"$^$:$O@g@P;a$K$h$k(B USB Linux $B$J$I$r;H$C$F%O!<%I%G%#%9%/$rI|5l$5$;!"$=$N8e$K(B BIOS $B$r99?7$9$k!#(B

    2008.01.25 $BDI5-(B:

    $B!!(BKB $B=P$^$7$?(B: Windows Vista $B$G%9%?%s%P%$!"5Y;_>uBV$+$iI|5"8e$K%3%s%T%e!<%?$NEE8;$r@Z$k$H!"FCDj$N5!G=$r%5%]!<%H$7$F$$$k%O!<%I(B $B%G%#%9%/$,G'<1$5$l$J$/$J$k(B (Microsoft KB948023)$B!#=$@5(B patch $B$O$^$@$"$j$^$;$s$,!"(B

    $BCm(B : $B$3$NLdBj$O!"(BPower-Up In Standby $B5!G=(B ($BEE8;EjF~;~$K%9%?%s%P%$(B $B%b!<%I$K0\9T$9$k5!G=(B) $B$r%5%]!<%H$7$F$$$k%O!<%I(B $B%G%#%9%/$r;HMQ$7$?>l9g$KH/@8$7$^$9!#(B

    $B!!>r7o$N(B 1 $B$D$,3NDj$5$l$^$7$?!#(B

    2008.02.02 $BDI5-(B:

    $B!!(BThinkPad $BMQ$N=$@5HG%U%!!<%`%&%'%"$,8x3+$5$l$F$$$^$9(B: $B%U%!!<%`%&%'%"!&%"%C%W%G!<%H!&%f!<%F%#%j%F%#(B 2.5$B%$%s%A(B SATA $B%O!<%I!&%G%#%9%/!&%I%i%$%VMQ(B (lenovo)

    $BBP1~5! ThinkPad G50
    ThinkPad R60, R60e
    ThinkPad R61, R61e
    ThinkPad T60, T60p
    ThinkPad T61, T61p
    ThinkPad X60, X60s, X60 Tablet
    ThinkPad X61, X61s, X61 Tablet
    ThinkPad Z60m, Z60t
    ThinkPad Z61e, Z61m, Z61p, Z61t

    $B!!4XO"(B: Vista$B$N(BKB943899$BE,MQ$G%N!<%H(BPC$B$N(BHDD$B$,FMA3;`(B (slashdot.jp, 2008.02.01)

    $B"#(B Hacking The Interwebs
    (gnucitizen, 2008.01.12)

    $B!!(BUPnP $B5!G=$D$-$N(B SOHO $B%k!<%?$r2p$7$F%$%s%?!<%M%C%H$K@\B3$7$F$$$k%/%i%$%"%s%H$K!"(B $B96N,(B Flash $B%"%W%j$rFI$_9~$^$;$k$3$H$G!"%k!<%?$N(B UPnP $B5!G=$rA`:n$7$F(B port forwarding $B$r$B$7$?$j!"(BDNS $B@_Dj$rJQ99$7$?$j$J$I$rFlash UPnP Attack FAQ $B$b;2>H!#(B

    $B!!2sHr$9$k$K$O!"%k!<%?$N(B UPnP $B5!G=$rI,MW$H$7$F$$$J$$$N$G$"$l$P!"$=$l$rL58z$K$9$k(B ($B$?$$$F$$$O%G%U%)%k%H$GM-8z$K$J$C$F$$$k(B)$B!#$5$C$=$/!"

    $B!!4XO"(B: UPnP$B%k!<%?(B+Flash=$B?<9o$J%;%-%e%j%F%#LdBj(B (yohgaki's blog, 2008.01.17)$B!#(B

    2008.01.22 $BDI5-(B:

    $B!!(BFlashing Home Routers (Symantec blog, 2008.01.21)

    2008.01.23 $BDI5-(B:

    $B!!(B$B!Z(B3$B![J#?t$N%G%P%$%9$K(B UPnP $B$K5/0x$9$k@H (JPCERT/CC REPORT 2008-01-23)

    2008.02.05 $BDI5-(B:

    $B!!(BJVNVU#347812: $B%M%C%H%o!<%/5!4o$K$*$$$F(B UPnP $B$,M-8z$K$J$C$F$$$k>l9g$NLdBj(B

    2008.04.03 $BDI5-(B:

    $B!!(BCVE-2008-1654

    2008.06.23 $BDI5-(B:

    $B!!4XO"(B: $B%M%C%H%o!<%/5!4o$K$*$1$k(BUPnP$B5!G=$N@H (NEC, 2008.06.23)


    $B"#(B 2008.01.16

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B(947563) Microsoft Excel $B$N@H
    (Microsoft, 2008.01.16)

    $B!!(BExcel 2003 SP2 $B0JA0(B / 2002 / 2000 / 2004 for Mac, Excel Viewer 2003 $B$K7g4Y!#(B Excel $B%U%!%$%k$N=hM}$N7g4Y$N$?$a$K%a%b%jGK2u$,H/@8!"96N,(B Excel $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2008-0081

    $B!!=$@5%W%m%0%i%`$O$^$@$J$$!#(BExcel 2003 SP3 / 2007 / 2008 for Mac $B$K%"%C%W%0%l!<%I$9$k$3$H$GBP1~$G$-$k!#$^$?!"(BExcel 2003 $B$G$O(B MOICE (Microsoft Office Isolated Conversion Environment) $B$r;H$&$3$H$G$b2sHr$G$-$k$=$&$@(B (info from: Excel$B$N@H ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog))

    2008.03.11 $BDI5-(B:

    $B!!$3$N7g4Y$r96N,$9$k!VKL5~%*%j%s%T%C%/!W%&%$%k%9$,3NG'$5$l$?$=$&$G$9!#(B

    $B!!(BExcel 2003 SP3 / Excel 2007 $B$N?M$O!"$3$N7g4Y$N1F6A$r$BL@F|$N(B Windows Update $B$GBP1~$5$l$k$O$:$G$9!#(B

    2008.03.12 $BDI5-(B:

    $B!!(BMS08-014 $B$GBP1~$5$l$^$7$?!#(B

    $B"#(B $B$$$m$$$m(B (2008.01.16)
    (various)

    2008.01.30 $BDI5-(B:

    $B!!(BFreeBSD-SA-08:02.libc - inet_network() buffer overflow $B$HF1$8OC$O(B bind $B$K$b$"$C$?$=$&$G!#(B

    2008.11.24 $BDI5-(B:

    $B!!(BFreeBSD-SA-08:02.libc - inet_network() buffer overflow / CVE-2008-0122 $BOC!"(Bbind 9.5.0 / 9.4.3 / 9.3.5 $B$G=$@5$5$l$F$$$k!#(B

    $B"#(B Drupal $B$KJ#?t$N7g4Y(B
    (Drupal.org, 2008.01.10)

    $B!!(BDrupal $B$KJ#?t$N7g4Y!#(B

    $B!!?@8M$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    $B"#(B $BDI5-(B

    JVN#80057925$B!!(B Apache HTTP Server $B$N(B mod_imap $B$*$h$S(B mod_imagemap $B$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H

    $B!!(BApache 1.3.40 / 2.0.62 / 2.2.7 $B$O%j%j!<%9$5$l$:!"(B Apache 1.3.41 / 2.0.63 / 2.2.8 $B$G=$@5$5$l$kLOMM!#(B

    $B"#(B Apache $B$KJ#?t$N7g4Y(B
    (various)

    $B!!(BApache $B$KJ#?t$N7g4Y$,H/8+$5$l$F$$$^$9!#(B

    $B!!(BApache 1.3.41 / 2.0.63 / 2.2.8 $B$G=$@5$5$l$k!#4{$K3F%P!<%8%g%s$N3+H/HG$G$O=$@5$5$l$F$$$k!#(Btakezou $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    2008.01.21 $BDI5-(B:

    $B!!(BApache 1.3.41 / 2.0.63 / 2.2.8 $B$,%j%j!<%9$5$l$^$7$?!#(Biida $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    2008.01.22 $BDI5-(B:

    $B!!(BApache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability (CVE-2008-0005) $B$bD>$C$F$^$7$?!#(BProxyFtpDirCharset $B%G%#%l%/%F%#%V$,DI2C$5$l$F$$$^$9!#(B

    $B"#(B About the security content of iPhone v1.1.3 and iPod touch v1.1.3
    (Apple, 2008.01.16)

    $B!!(BiPhone / iPod touch v1.1.3 $BEP>l!#(B3 $B$D$N7g4Y$,=$@5$5$l$F$$$k(B:

    $B"#(B About the security content of QuickTime 7.4
    (Apple, 2008.01.16)

    $B!!(BQuickTime 7.4 $BEP>l!#(B4 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B

    $B!!!D!D$"$l!"(BJVNVU#112179$B!!(B Apple QuickTime RTSP $B$N(B Response message $B$K4^$^$l$k(B Reason-Phrase $B=hM}$K%P%C%U%!%*!<%P!<%U%m!<$N@H $B$OD>$C$F$J$$$h$&$G$9!D!D!#(B


    $B"#(B 2008.01.15

    $B"#(B $BDI5-(B

    $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H

    $B!!(B2008.01.08, 2008.01.15 $B$K2~D{$5$l$F$$$k!#(B

    $B"#(B InterScan Messaging Security Suite 7.0 / InterScan Messaging Security Appliance 7.0 $B$N(B $B!H(BKeep Alive$B!I@_Dj$K4X$9$k=EBg$JLdBj$K$D$$$F(B
    ($B%H%l%s%I%^%$%/%m(B, 2008.01.15)

    $B!!(BIMSS 7.0 / IMSA 5000 7.0 $B$K7g4Y!#(BKeep Alive $B$rM-8z$K$7$?>l9g$K(B ($B%G%U%)%k%H(B: $BL58z(B) $B!"!VFCDj$N%a!<%k!W$r

    $B!!(BIMSS 7.0 Linux $BHG(B Service Pack 1 $B$G=$@5$5$l$F$$$kB>!"(B IMSS 7.0 Windows $BHG(B / Solaris $BHG!"(BIMSA 5000 7.0 $BMQ$K$O(B Critical Patch $B$,8x3+$5$l$F$$$k!#(B


    $B"#(B 2008.01.14


    $B"#(B 2008.01.12


    $B"#(B 2008.01.11

    $B"#(B UTF-7$B$G(BXSS$B$rH/@8$5$;$k(B10$B$NJ}K!(B
    ($BMU$C$QF|5-(B, 2008.01.10)

    $B!!$?$@$$$^A}?#Cf!#(BJavaScript $B$rM-8z$K$7$J$$$HFI$a$J$$$h$&$G$9!#(B

    $B"#(B Web$B7PM3$G%W%j%s%?$rA`:n$9$k967b
    (computerworld, 2008.01.10)

    $B!!85$M$?(B: Cross Site Printing (Aaron Weaver)$B!#%$%s%H%i%M%C%HFb$N%M%C%H%o!<%/%W%j%s%?$N(B HP JetDirect $B%]!<%H(B (9100/tcp) $B$r(B Form $B$NAw$j@h$K@_Dj$7$F$*$/$H!"!D!D(B

    $B"#(B JVNVU#112179$B!!(B Apple QuickTime RTSP $B$N(B Response message $B$K4^$^$l$k(B Reason-Phrase $B=hM}$K%P%C%U%!%*!<%P!<%U%m!<$N@H
    (JVN, 2008.01.11)

    $B!!(BQuickTime 7.3.1 $B0JA0$K$*$1$k(B RTSP $B%l%9%]%s%9%a%C%;!<%8$N=hM}$K7g4Y!#(B $BFCDj$N(B RTSP $B%9%F!<%?%9%3!<%I$r$B4{$K(B exploit $B$,8x3+$5$l$F$$$k(B$B!#(B

    $B!!=$@5HG$O$^$@$J$$!#8=;~E@$K$*$1$k3NVulnerability Note VU#112179: Apple QuickTime RTSP Response message Reason-Phrase buffer overflow vulnerability (US-CERT) $B$K$O$3$NB>$K$bJ#?t$NJ}K!$,5-:\$5$l$F$$$k$,!"$$$:$l$b3N

    2008.01.16 $BDI5-(B:

    2008.02.07 $BDI5-(B:

    $B!!(BQuickTime 7.4.1 $BEP>l!"$h$&$d$/=$@5$5$l$^$7$?(B: About the security content of QuickTime 7.4.1 (Apple)$B!#(BCVE-2008-0234


    $B"#(B 2008.01.10

    $B"#(B [SA28247] SSH Tectia Client/Server ssh-signer Unspecified Privilege Escalation
    (Secunia, 2008.01.10)

    $B!!(BSSH Tectia 5.x $B$K7g4Y!#(Bssh-signer $B$K8"8B>e>:$r5v$97g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rC%

    $B!!(BSSH Tectia 5.2.4 / 5.3.6 $B$G=$@5$5$l$F$$$k!#$^$?!"(Bssh-signer $B%3%^%s%I$r:o=|$9$k$3$H$G2sHr$G$-$k!#$?$@$7!"$3$l$rZ$,$G$-$J$/$J$k!#(B


    $B"#(B 2008.01.09

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (943411) Windows $B%5%$%I%P!<$NJ]8n$r6/2=$9$k99?7%W%m%0%i%`(B
    (Microsoft, 2008.01.09)

    $B!!(BWindows Sidebar Protection update for Windows Vista (Microsoft KB941411) $B$K$h$k$H!"$3$l$rE,MQ$9$k$3$H$G!"(BWindows $B%5%$%I%P!<$K$O

    • Windows $B%5%$%I%P!<$G5/F0$7$F$$$kA4$F$N%,%8%'%C%H$KBP$7$F!"0l0U$J<1JL;R$,@8@.$5$l$k(B
    • Windows Update $B$r;H$C$F!"4{CN$N7g4Y$r;}$D%,%8%'%C%H$N0lMw$r$B7g4Y$r;}$D%,%8%'%C%H$ODd;_$5$l$k(B
    • $B7g4Y$r;}$D%,%8%'%C%H$O%$%s%9%H!<%k$G$-$J$$(B

    $B"#(B $BDI5-(B

    $B%^%$%/%m%=%U%H(B 2008 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B

    $B!!:#7n$O(B 2 $B7o$G$9!#(B

    $B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

    $B!!4XO"(B: 2008$BG/(B1$B7n$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog, 2008.01.04)


    $B"#(B 2008.01.08

    $B"#(B $B$$$m$$$m(B (2008.01.08)
    (various)

    • Exploiting WDM Audio Drivers.(updated) (reversemode.com, 2007.12.20)$B!#(B$B35MW(B

    • CVE-2007-6351$B!#(Blibexif 0.6.16 ($B:G?7(B) $B0JA0$K!"L58B%k!<%W$K4Y$k7g4Y$,$"$k$H$$$&OC!#(B RHSA-2007:1165-4$B!"(B RHSA-2007:1166-3 $B$G$OD>$C$F$k!#(B

    • CVE-2007-6352$B!#(Blibexif 0.6.16 ($B:G?7(B) $B0JA0$K(B integer overflow $B$9$k7g4Y$,$"$k$H$$$&OC!#(B RHSA-2007:1166-3 $B$G$OD>$C$F$k!#(B

    • CVE-2007-6514$B!#(B Linux $B>e$GF0:n$9$k(B Apache $B$K$*$$$F!"(B Windows $B>e$N6&M-%U%)%k%@$r(B smbfs $B$r;H$C$F%^%&%s%H$7$?>l=j$r(B Apache $B$G8x3+$7$F$$$k>l9g$K!"(B http://linuxbox/winshare/info.php\ $B$N$h$&$K%"%/%;%9$9$k$H!"(B PHP $B%U%!%$%k$,=hM}$5$l$:$KI=<($5$l$F$7$^$&$H$$$&OC!#(B $B>/$J$/$H$b(B Apache 2.2.6 $B$G$3$&$J$k$=$&$@!#(B $B$^$?(B PHP $B$@$1$G$J$/!"(Bhoge.cgi\ $B$H$+(B page.rb\ $B$H$+$G$b$=$&$J$kLOMM!#(B

    • CVE-2007-6285$B!#(B RHEL 4 / 5 $BMQ$N(B autofs 5 $B%Q%C%1!<%8$K$*$$$F!"(B-hosts $B%^%C%W$N%G%U%)%k%H@_Dj$G(B nodev $B%*%W%7%g%s$,;XDj$5$l$F$$$J$+$C$?$H$$$&OC!#(B RHSA-2007:1177-4 RHSA-2007:1176-7 $B$G=$@5$5$l$F$$$k!#(B

      $B;w$?OC(B: CVE-2007-5964$B!#(B-host $B%^%C%W$N%G%U%)%k%H@_Dj$G(B nosuid $B%*%W%7%g%s$,;XDj$5$l$F$$$J$+$C$?$H$$$&OC!#(B

    $B"#(B 2008-01-07 Cumulative Security Update Release
    (PostgreSQL.org, 2007.01.07)

    $B!!(BPostgreSQL $BA4%P!<%8%g%s$KJ#?t$N7g4Y!#(B

    • $B<0%$%s%G%C%/%9(B (expression index) $B$K$^$D$o$k8"8B>e>:$N7g4Y(B CVE-2007-6600

    • $B@55,I=8=%i%$%V%i%j$K$^$D$o$k(B DoS $B967b$rCVE-2007-4772 CVE-2007-6067 CVE-2007-4769

    • DBLink $B4X?t$K$^$D$o$k8"8B>e>:$N7g4Y(B CVE-2007-660$B!#(B $B$3$l$O(B CVE-2007-3278 $B$HF1$8LdBj$J$N$@$1$l$I!"(BCVE-2007-3278 $B$N=$@5$,40A4$G$O$J$+$C$?LOMM!#(B

    $B!!(BPostgreSQL 8.2.6, 8.1.11, 8.0.15, 7.4.19, 7.3.21 $B$G=$@5$5$l$F$$$k!#(B 7.3 $B7ONs$O(B 7.3.21 $B$G=*N;$@$=$&$@!#(B $B$^$?(B 8.0 / 8.1 $B7ONs$N(B Windows $BHG%P%$%J%j%Q%C%1!<%8$NDs6!$b(B 8.0.15 / 8.1.11 $B$G=*N;$@$=$&$@!#B>$N%W%i%C%H%[!<%`$d%=!<%9$G$N(B 8.0 / 8.1 $B7ONs$NDs6!$O0];}$5$l$k$=$&$G!#(B

    $B!!(BFreeBSD ports $B$b99?7$5$l$F$^$9(B: Adobe Acroread 8$BEP>l!$(BPostgreSQL$B%;%-%e%j%F%#99?7!$(BPostgreSQL$B8~$1A4J88!:w5!G=(Bludia$BDI2C!$(Blibgpod$B$G?7(BiPod Classic/Nano Video$BBP1~!$(BLinux Flash 7/9$B99?7(B (FreeBSD Daily Topics, 2008.01.08)

    $B!!4XO"(B: PostgreSQL$B$K4m81$J%;%-%e%j%F%#!&%[!<%k!$4IM} ($BF|7P(B IT Pro, 2008.01.08)

    $B"#(B $BDI5-(B


    $B"#(B 2008.01.07

    $B"#(B $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H
    ($B%8%c%9%H%7%9%F%`(B, 2008.01.07)

    $B!!%8%c%9%H%7%9%F%`@=IJ6&DL%i%$%V%i%j(B jsfc.dll $B$K7g4Y!#(Bjtd $B%U%!%$%k(B jtd $B%U%!%$%k$J$I$NJ8=q%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k$?$a!"96N,(B jtd $B%U%!%$%k(B$BJ8=q%U%!%$%k$r;H$C$FG$0U$N%3!<%I$r

    $B!!1F6A$rHo$k%=%U%H%&%'%"$O!"(BJSGCI.DLL $B$N$H$-(B$B$HF1MM!"B?4t$K$o$?$k!#(B

    • $B0lB@O:(B 2007 / 2006 / 2005 / 2004 / 13 / 12 / 11 / 10 / 9
    • $B0lB@O:(B Lite2
    • XML $B%F%s%W%l!<%H%/%j%(!<%?!<(B 1 / 2 / 3
    • FormLiner for XML/SGML
    • $B0lB@O:(B 9 SGML $B%(%/%9%F%s%7%g%s(B
    • $B%8%c%9%H%[!<%`(B/i/2/3/4/EX/EX2
    • $B2V;R(B 2007 / 2006 / 2005 / 2004 / 13 / 12 / 11 / 10 / 9
    • $B;0;MO:(B 2007 / 2005 / 9 / SE / Home
    • $B%i%Y%k%^%$%F%#(B 1 / 2 / 3 / 4 / 5 / 6 / 7 / 8
    • $B%i%Y%k%^%$%F%#(B POP in Shop 1 / 2 / 3 / 4 / 5
    • $B3Z!9$O$,$-(B 2008 / 2007 / 2006 / 2005 / 2004 / 2003 / 2002 / 2001 / 2000
    • $B%^%$%Z%s%7%k(B
    • $B%(%W%m%s(B/2
    • $B%U%)%H%Z%?!*(B
    • $B%8%c%9%H%/%l%h%s(B
    • $B%[!<%`%Z!<%8%_%C%/%9(B
    • $B%I%/%?!<%^%&%9(B [$B1QOB!?OB1Q!?9q8l<-E5(B]
    • $B%;!<%k%9%^%$%F%#(B
    • $B?^2r%^%9%?!<(B
    • $B%8%c%9%H%9%^%$%k(B 2 / 3 @$B%U%l%s%I(B
    • $B%8%c%9%H%9%^%$%k(B 1 / 2 / 3
    • $B0lB@O:%9%^%$%k(B 1 / 2 / 3
    • $B%8%c%9%H%8%c%s%W(B 2 / 3 @$B%U%l%s%I(B
    • $B%8%c%9%H%8%c%s%W(B 1 / 2 / 3
    • $B0lB@O:%8%c%s%W(B 1 / 2 / 3
    • $B$D$?$o$k$M$C$H(B 1 / 3 @$B%U%l%s%I(B
    • $B$O$C$T$g$&L>?M(B 1 / 2 / 3
    • $B$R$i$a$-%i%$%?!<(B 1 / 2 / 3
    • $B$+$$$1$DI=%0%i%U(B 1 / 2 / 3
    • $BCO?^%9%?%8%*(B
    • $BJ8;z%9%?%8%*(B 1 / 2
    • $B8&=$%G%6%$%J!<(B
    • ConceptSearch
    • ExpandFinder
    • $B0lB@O:(B for Linux
    • $B0lB@O:%S%e!<%"(B (5.0.7.0 $B0JA0(B)
    • $B2V;R%S%e!<%"(B (2.0.2.0 $B0JA0(B)
    • $B$O$C$T$g$&L>?M%S%e!<%"(B
    • ConceptBase
    • Netnote
    • Netnote / R.2

    $B!!=$@5%W%m%0%i%`$^$?$O99?7HG$,8x3+$5$l$F$$$k$N$G!"E,MQ$9$l$P$h$$!#(B

    $B!!(B$B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B$B$N1-;t$5$s$K$h$kH/8+$@$=$&$@!#(B $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H ($B%8%c%9%H%7%9%F%`(B) $B$K$O!V(B2007$BG/(B12$B7n(B19$BF|!"Ev[FFRUA-20071216] $BJ8=q:n@.%=%U%H%&%(%"$N@H ($B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B) $B$,$=$l$@$m$&$+!#(B

    $B!!4XO"(B:

    2008.01.08 $BDI5-(B:

    $B!!(B[FFRRA-20080107] $B%8%c%9%H%7%9%F%`4pK\%/%i%9%i%$%V%i%j$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<@H ($B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B) $B$,8x3+$5$l$F$$$k!#(B

    $B:Y9)$5$l$?J8=q%U%!%$%k(B(jtd$B%U%!%$%k$J$I(B)$B$r3+$/$3$H$G!"$"$k$$$O!":Y9)$5$l$?J8=q%U%!%$%k$,CV$+$l$?(Bweb$B%5%$%H$r(BInternet Explorer$B$d(BFirefox$BEy$N(Bweb$B%V%i%&%6$G1\Mw$9$k$3$H$G!"J8=q%U%!%$%kCf$K5-=R$5$l$?G$0U$N%3!<%I$r

    $B!!1F6AHO0O$O(B jtd $B%U%!%$%k$K$H$I$^$i$J$$LOMM!#:rF|=q$$$?!V(Bjtd $B%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k$?$a!W$H$$$&J8>O$O!"(B JVN#08237857$B!!(B $BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H (JVN) $B$N(B

    $BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$O!":Y9)$5$l$?(B jtd $B%U%!%$%k$r=hM}$9$k:]$K%P%C%U%!%*!<%P!<%U%m!<$N@H

    $B$r:,5r$K$7$?$N$@$,!"$I$&$d$i4V0c$C$F$$$k$h$&$J$N$G=$@5$7$?!#(B

    2008.01.15 $BDI5-(B:

    $B!!(B2008.01.08, 2008.01.15 $B$K2~D{$5$l$F$$$k!#(B

    2008.01.28 $BDI5-(B:

    $B!!(BNetnote $B$NBP1~%b%8%e!<%k$,MQ0U$5$l$?!#(B

    $B"#(B $BJFO"K.9R6u6I!"%\!<%$%s%0(B787$B$NFbIt%M%C%H%o!<%/$K$O?<9o$J@H
    (technobahn, 2008.01.07)

    $B!!%O%C%-%s%0$G%O%$%8%c%C%/;~BeE~Mh(B?


    $B"#(B 2008.01.06

    $B"#(B [SA28264] XOOPS "b_system_comments_show()" Security Bypass
    (secunia, 2008.01.05)

    $B!!(BXOOPS 2.0.18 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

    $B"#(B [SA28228] Qt QSslSocket Certificate Verification Vulnerability
    (secunia, 2008.01.04)

    $B!!(BQt 4.3.0$B!A(B4.3.2 $B$N(B QSslSocket $B$K(B SSL $B$N>ZL@=qG'>Z$K4X$9$k7g4Y$,$"$k$=$&$G!#(B Qt 4.3.3 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(Bpatch $B$b$"$j$^$9(B$B!#(B CVE-2007-5965

    $B"#(B [SA28318] PHP Multiple Vulnerabilities
    (secunia, 2008.01.04)

    $B!!(BPHP 4.4.8 $B$G=$@5$5$l$?(B 5 $B$D$N7g4Y$NOC!#(B

    $B"#(B securityvulns.com russian vulnerabilities digest
    (3APA3A, 2008.01.04)

    $B!!(Bhttp://securityvulns.com/ $B$GJs9p$5$l$?%;%-%e%j%F%#7g4Y$N$&$A!"1Q8l$G$NJs9p$,$J$5$l$F$$$J$$$b$N$K4X$9$k%@%$%8%'%9%H!#(BWordPress $B$N(B XSS $B$M$?$J$I!#(B

    $B"#(B multiple CAPTCHA automation test bypass digest
    (3APA3A, 2008.01.04)

    $B!!(BMonth of Bugs in Captchas $B$H$$$&%W%m%8%'%/%H$,(B 2007.11 $B$K3+:E$5$l$?$=$&$G!"$=$N7k2L$N%@%$%8%'%9%H!#(B $BJs9p$5$l$?(B 75 $B8D$N7g4Y$N$&$A!"=$@5$5$l$?$b$N$O(B 5 $B$D$@$1$@$=$&$G!#(B

    $B"#(B $BDI5-(B

    $B"#(B $B$$$m$$$m(B (2008.01.06)
    (various)


    $B"#(B 2008.01.05

    $B"#(B [SA28276] RealPlayer Unspecified Buffer Overflow Vulnerability
    (secunia, 2008.01.03)

    $B!!>/$J$/$H$b(B RealPlayer 11 $B$KL$=$@5$N7g4Y$,B8:_$9$kLOMM!#(B $BH/8+[Dailydave] 0day RealPlayer exploit demo

    $B!!(Bpatch $B$O$^$@$J$$!#(BSANS ISC $B$O(B uc8010.com $B$X$N%"%/%;%9$r5qH]$9$k$h$&?d>)$7$F$$$k!#(B $B;2>H(B: Realplayer Vulnerability (SANS ISC, 2008.01.04)

    $B"#(B $B%^%$%/%m%=%U%H(B 2008 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B
    (Microsoft, 2008.01.04)

    $B!!:#7n$O(B 2 $B7o$G$9!#(B

    $B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

    $B!!4XO"(B: 2008$BG/(B1$B7n$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog, 2008.01.04)

    2008.01.09 $BDI5-(B:

    $B!!(BBulletin $B8x3+$K$"$o$;$FA4LLE*$K=q$-$J$*$7!#(B

    2008.01.29 $BDI5-(B:

    $B!!(BMS08-001 $B4XO"(B:

    2008.02.01 $BDI5-(B:

    $B!!(BWindows$B$N(BTCP/IP$B@HZ(BFlash$B%`!<%S!<$,8x3+(B (ITmedia, 2008.01.31)$B!#(BMS08-001 $BOC!#(B

    2008.02.06 $BDI5-(B:

    $B!!4XO"(B: $BJF%^%$%/%m%=%U%H$N%;%-%e%j%F%#>pJs!V(BMS08-001$B!W$KBP=h$9$kFq$7$5(B ($BF|7P(B IT Pro, 2008.02.06) ($B855-;v(B)


    $B"#(B 2008.01.02


    $B"#(B 2008.01.01

    $B"#(B TK53 Advisory #2: Multiple vulnerabilities in ClamAV
    (Lolek of TK53, 2007.12.30)

    $B!!(BClamAV 0.92 ($B:G?7HG(B) $B$K(B 3 $B$D$N7g4Y$,$"$k!"$H$$$&;XE&!#(B

    • $B0l;~%U%!%$%k$N:n@.$K$*$$$F6%9g>uBV$,H/@8!#(B CVE-2007-6595

    • BASE64 $B7A<0$N(B UUENCODE $B%U%!%$%k(B (GNU sharutils $B$J$I$,BP1~!"(Buuencode -m ) $B$r$&$^$/07$($J$$$?$a!"4{CN$N%^%k%&%'%"$rDL2a$5$;$F$7$^$&!#(B CVE-2007-6596

    • sigtool $B$K$*$1$k(B utf16-decode $B;~$N%U%!%$%k$N07$$$,%;%-%e%"$G$J$$!#(B CVE-2007-6337

    $B"#(B HDD$B$r%U%)!<%^%C%H$9$k%V%i%/%i(B $B$^$H$a(Bwiki
    (@wiki, 2007.12.31)

    $B!!$J$s$@$+$=$&$$$&$b$N$,N.9T$C$F$$$k$h$&$G$9!#;38}$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

    1. IE $BA@$$$N%V%i%&%6%/%i%C%7%c!<%Z!<%8$K%"%/%;%9$5$;$k(B ($B3HD%;R$r56Au$7$F$$$k>l9g$"$j(B)
    2. $B%V%i%&%6%/%i%C%7%c!<$O!"967b(B .bat $B%U%!%$%k$r%9%?!<%H%"%C%W$KEPO?$5$;$?>e$G:F5/F0$rB%$7$?$j$9$kLOMM(B
    3. $B:F5/F0$7$F$7$^$&$H%I%+%s(B

    $B!!%"%/%;%9$7$F$7$^$C$?>l9g$NMM;R(B: http://www.geocities.jp/hdd_matome/

    $B!!(BIE 6 SP2 / IE 7 $B$N>l9g!"!V3HD%;R$G$O$J$/!"FbMF$K$h$C$F%U%!%$%k$r3+$/!W$rL58z$K@_Dj$9$k$H!"3HD%;R56Au$K$D$$$F$O2sHr$G$-$^$9!#(B $B$7$+$7(B IE $B%3%s%]!<%M%s%H$r;HMQ$9$k%V%i%&%6$N>l9g!"$3$N@_Dj$,8z$+$J$$>l9g$,$"$k$h$&$G$9!#(BSleipnir $B$N>l9g$O(B 2.5.14 $B$GBP1~$5$l$F$$$k$=$&$G$9!#(B$B%j%j!<%9%N!<%H(B

    $B!!%V%i%&%6%/%i%C%7%c!<<+BN$O(B JavaScript $B$rL58z$K$7$J$$$H2sHr$G$-$J$$LOMM!#(B $B$"$k$$$O(B Firefox $B$d(B Opera $B$J$I(B IE $B$G$O$J$$%V%i%&%6$r;HMQ$9$k!#(B

    $B!!4XO"(B: $B2hA|%U%!%$%k$K56Au$7$?!$(BHDD$B$r%U%)!<%^%C%H$7$h$&$H$9$k%H%m%$$NLZGO$,%M%C%H$GOCBj$K(B ($BF|7P(B IT Pro, 2007.12.31)


    [$B%;%-%e%j%F%#%[!<%k(B memo]
    $B;d$K$D$$$F(B