$B%;%-%e%j%F%#%[!<%k(B memo - 2008.12

Last modified: Wed Nov 25 17:18:20 2009 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2008.12.31

$B"#(B $BDI5-(B

Windows Media Player Integer Overflow

$B!!(BMicrosoft $B$O!"$3$l$K$h$kG$0U$N%3!<%I$NQuestions about Vulnerability Claim in Windows Media Player (MSRC blog, 2008.12.29)

$B"#(B www.mozilla.com$B$N%5!<%P>ZL@=q$,Bh;0
($B?eL57n$P$1$i$N$($SF|5-(B, 2008.12.28)

$B!!$7$+$7

$B"#(B MD5 considered harmful today: Creating a rogue CA certificate
(win.tue.nl, 2008.12.30)

$B!!6aG/!"(BMD5 $B%O%C%7%e%"%k%4%j%:%`$N>WFMBQ@-$,!"$=$l$^$G9M$($i$l$F$$$?$[$I$K$O9b$/$J$$$3$H$,CN$i$l$k$h$&$K$J$C$?$,!"$3$l$rMxMQ$7$?8=25th Chaos Communication Congress (25C3) $B$GH/I=$5$l$?!#(B $B%G%b$5$l$?$N$O$3$s$JFbMF$_$?$$!#(B

$B!!6qBNE*$K$O!"(BMD5 $B$G=pL>$5$l$?>ZL@=q$r;HMQ$7$F$$$k%5%$%H$O%d%P$$LOMM!#(B

$B!!$7$+$7$3$l!"(BMD5 $B$N@H$OA4ItL5;k!W$H$$$C$?@_Dj$r$G$-$k$h$&$K$J$i$J$$$HBLL\$J5$$,!#(B

$B!!4XO"(B:

2009.01.07 $BDI5-(B:

$B!!4XO"(B:

2009.02.24 $BDI5-(B:

$B!!4XO"(B:


$B"#(B 2008.12.30


$B"#(B 2008.12.29

$B"#(B phpPgAdmin 4.2.2 Security Release
(postgresql.org, 2008.12.20)

$B!!$h$/$o$+$i$J$$$1$I(B security fix $B$,4^$^$l$F$$$kLOMM$G$9!#(B

$B"#(B Windows Media Player Integer Overflow
(SANS ISC, 2008.12.27)

$B!!$3$l$N$3$H$G$9$+$M(B: MS Windows Media Player * (.WAV) Remote Integrer Overflow (bugtraq, 2008.12.25)$B!#(B Windows Media Player 9 $B!A(B 11 $B$K$*$$$F!"(B $B96N,(B WAV / SND / MID $B%U%!%$%k$K$h$C$F(B integer overflow $B$9$k7g4Y$,$"$j!"(B $BG$0U$N%3!<%I$N

2008.12.31 $BDI5-(B:

$B!!(BMicrosoft $B$O!"$3$l$K$h$kG$0U$N%3!<%I$NQuestions about Vulnerability Claim in Windows Media Player (MSRC blog, 2008.12.29)


$B"#(B 2008.12.28


$B"#(B 2008.12.26

$B"#(B USB $B%a%b%j$J$I$N%j%`!<%P%V%k%a%G%#%"$K(B Microsoft Word $BJ8=q$rJ]B8$G$-$J$$(B
($B%7%^%s%F%C%/(B, 2008.12.18)

$B!!(BSymantec Endpoint Protection $B$NIT6q9g!#(BUSB $B%a%b%j>e$N(B Word $B%U%!%$%k$rJT=8$7!"J]B8$7$h$&$H$9$k$H!V%U%!%$%k(B $B%"%/%;%98"$N%(%i!<$N$?$aJ]B8$G$-$^$;$s!#!W$H8@$o$l$F<:GT$9$k!#?y1:$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(Bpatch $B$O$^$@$J$$!#2sHr:v$H$7$F$O!"0lC6%m!<%+%k%G%#%9%/>e$KJ]B8$7!"J]B8$7$?%U%!%$%k$r(B USB $B$K%3%T!<$9$k!#(B USB $B%a%b%j$K8B$i$:!"%j%`!<%P%V%k%a%G%#%"$K$D$$$F$OA4$F$3$&$J$kLOMM!#(B


$B"#(B 2008.12.25

$B"#(B $B$$$m$$$m(B (2008.12.25)
(various)

$B"#(B $BDI5-(B

Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability

$B"#(B SSL$B$rMW$9$k%b%P%$%k4D6-$G$N%Q%9%o!<%I%^%M!<%8%c$N;H$$J}$KCm0U(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2008.12.21)

$B!!MF0W$KEpD0$5$l$?$jCf4V2pF~967b$r


$B"#(B 2008.12.24


$B"#(B 2008.12.23

$B"#(B $BDI5-(B

$B!Z6[5^Cm0U4-5/![2~$6$s$5$l$?(BWeb$B%5%$%H1\Mw$K$h$kAH?%Fb$X$N%\%C%H@xF~Ho32$K$D$$$F(B

Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability

$B!!(BSA $B=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (961040) SQL Server $B$N@H (Microsoft)$B!#(B SQL Server 2000 / 2005$B!"(BSQL Server 2005 Express$B!"(BMSDE 2000$B!"(BWMSDE$B!"(BWindows Internal Database $B$K$3$N7g4Y$,$"$j!"(B SQL Server 7$B!"(BSQL Server 2005 SP3$B!"(BSQL Server 2008 $B$K$O$3$N7g4Y$O$J$$$=$&$G!#(B CVE-2008-4270

$B!!$3$N7g4Y$rMxMQ$7$?967b$rZ$,I,MW$@$,!"(BWeb $B%"%W%j$N(B SQL $B%$%s%8%'%/%7%g%s7g4Y$r7PM3$9$k>l9g$K$O!"!VG'>Z$,I,MW!W$H$$$&%O!<%I%k$,$J$/$J$C$F$7$^$&!#(B

$B!!(BMicrosoft $B$N?d>)2sHr:v$O!V(Bsp_replwritetovarbin $B3HD%%9%H%"%I%W%m%7!<%8%c$N%"%/%;%9$r5qH]$9$k!WJ}K!!#>\:Y$O(B SA $B$r;2>H!#(B

$B!!4XO"(B: More information about the SQL stored procedure vulnerability (Microsoft SVRD blog, 2008.12.22)

$B"#(B $B$$$m$$$m(B (2008.12.23)
(various)

$B"#(B Bug 473958 - (CVE-2008-5078) CVE-2008-5078 enscript: "epsf" special escape buffer overflows
(redhat.com, 2008.12.01)

$B!!(BGNU enscript 1.6.1 $B0JA0$N(B recognize_eps_file() $B$H(B tilde_subst() $B$K(B buffer overflow $B$9$k7g4Y!#3+H/HG$N(B GNU enscript 1.6.4 $B$K$O$3$N7g4Y$O$J$$!#(B CVE-2008-5078

$B"#(B [MediaWiki-announce] MediaWiki 1.13.3, 1.12.2, 1.6.11 security update
(wikimedia.org, 2008.12.15)

$B!!(BMediaWiki $B$K(B 4 $B$D$N7g4Y(B (XSS$B!"(BIE $B$GH/@8$9$k(B script injection$B!"(B Firefox $B$J$I(B SVG $B$KBP1~$7$?%/%i%$%"%s%H$GH/@8$9$k(B script injection$B!"(BCSRF) $B$,$"$j!"(BMediaWiki 1.13.3, 1.12.2, 1.6.11 $B$G=$@5$5$l$?!#(B CVE-2008-5249 CVE-2008-5250 CVE-2008-5252

$B!!>e5-$NB>$K$b!"(B CVE-2008-5687 CVE-2008-5688 $B$,=$@5$5$l$?LOMM!#(B

$B"#(B Memcached Injection
(NTT$B%3%_%e%K%1!<%7%g%s%:(B, 2008.12.19)

$B!!(BCRLF $B$r4^$`%-!$r;H$&$3$H$G!"(BCRLF $B%$%s%8%'%/%7%g%s967b$r9T$&$3$H$,2DG=$J(B memcached $B%/%i%$%"%s%HMQ%i%$%V%i%j$,B8:_$9$k!"$H$$$&OC!#J8=q$G$O(B

$B$K$D$$$F8!>Z$5$l$F$$$k$,!"(Bmemcached $B%/%i%$%"%s%HMQ%i%$%V%i%j$O>e5-$NB>$K$bB??tB8:_$9$k!#(B

$B:#8e!"(Bmemcached $B$rMxMQ$7$?%7%9%F%`3+H/$KFIl9g!"$+$D%-!$K1x@w%G!<%?$rM?$($k>l9g$K$O!"MxMQ$9$k%i%$%V%i%j$,$I$N$h$&$J%5%K%?%$%:=hM}$7$F$$$k$+$I$&$+$r3NG'$9$k$3$H$r?d>)$9$k!#(B
$B%i%$%V%i%jB&$G%5%K%?%$%:=hM}$r9T$C$F$$$J$$>l9g$O!"%"%W%j%1!<%7%g%sB&$G%5%K%?%$%:=hM}$r$*$3$J$&I,MW$,$"$k(B($B!V(B6 Memcahced Injection $B$NBP:v!W(B)$B!#(B

$B"#(B 2008.12.22

$B"#(B $B!Z6[5^Cm0U4-5/![2~$6$s$5$l$?(BWeb$B%5%$%H1\Mw$K$h$kAH?%Fb$X$N%\%C%H@xF~Ho32$K$D$$$F(B
(LAC, 2008.12.22)

$B!!N.9T$C$F$$$k$=$&$G$9!#(B

$B2~$6$s$K$h$jM6F3$5$l$k%5%$%H(B
s.cawjb.com
s1.cawjb.com
jpdog.3322.org
jpsb.meibu.com
$B"((B $B7h$7$F%"%/%;%9$7$J$$$G$/$@$5$$!#(B

$B!!>e5-%I%a%$%sL>$r$0$0$k$H!"$$$C$Q$$=P$F$-$^$9$M!#

$B0-MQ$5$l$F$$$k@H MS06-014$B!"(BMS08-078$B!"(BAdobe Flash Player$B$,3NG'$G$-$F$$$^$9!#(B

$B!!(BWindows Update $B$7$^$7$g$&(B / $B:G?7$N(B Flash Player $B$K%"%C%W%G!<%H$7$^$7$g$&!#(B

2008.12.24 $BDI5-(B:

$B!!(BSQL$B%$%s%8%'%/%7%g%s967b5^A}!$!V(B1$BF|Ev$?$j$K=>Mh$N(B1$B%+7nJ,$N967b$r4QB,!W(B ($BF|7P(B IT Pro, 2008.12.22)

2008.12.29 $BDI5-(B:

$B!!Ho32;vNc(B: $B5l2,C+;T%[!<%`%Z!<%8$X$NIT@5%"%/%;%9$K$D$$$F(B ($B2,C+;T(B, 2008.12.26)

$B!!(Bhttp://www.city.okaya.nagano.jp/mmcb/Contents/Contents.asp $B$d(B http://www.city.okaya.nagano.jp/mmcb/Contents/View.asp $B$,%@%a$@$C$?$h$&$G!#(B

2009.01.04 $BDI5-(B:

$B!!Ho32;vNc(B: $B%(%-%5%$%H%V%m%0%H%C%W%Z!<%8$K$F(B

2009.01.16 $BDI5-(B:

$B!!$D$E$-(B:

$B"#(B [SA33210] ESET Smart Security "epfw.sys" IOCTL Handler Privilege Escalation
(secunia, 2008.12.20)

$B!!(BESET Smart Security < 3.0.684 $B$K7g4Y!#(B epfw.sys $B%I%i%$%P$N(B IOCTL $B%O%s%I%i$K7g4Y$,$"$j!"96N,(B IOCTL $B$K$h$C$FG$0U$N%3!<%I$r(B kernel $B6u4V$G

$B!!(BESET Smart Security 3.0.684 $B$G=$@5$5$l$F$$$k!#(B

2008.12.23 $BDI5-(B:

$B!!(BESET Smart Security <= 3.0.672 (epfw.sys) Privilege Escalation Exploit (milw0rm)

$B"#(B $BJ#?t$N(B Linux $BMQ%"%s%A%&%$%k%9@=IJ$K7g4Y(B
(iViZ Techno Solutions, 2008.12.10)


$B"#(B 2008.12.21

$B"#(B $BDI5-(B

Firefox 3.0.5 and 2.0.0.19 security updates now available for download

$B!!$J$s$H!"(B2.0.0.19 $B$GD>$C$?$O$:$N(B MFSA 2008-65 $B$,(B Windows $BHG$G$@$1D>$C$F$$$J$+$C$?$=$&$G!"(B Firefox 2.0.0.20 $B$,6[5^%j%j!<%9$5$l$F$$$^$9!#(B

$B!!$H$$$&$o$1$G!"(BFirefox 2 $B7ONs$N:G=*HG$O(B 2.0.0.20 $B$K$J$j$^$7$?!#(B

$B"#(B Malware Hash Registry
(Team Cymru)

$B!!(BWhois $B$^$?$O(B DNS $B$r;H$C$F$"$d$7$$%U%!%$%k$N%O%C%7%eCM(B (MD5 or SHA1) $B$r8!:w$9$k$H!"Ez$($,JV$C$F$/$k%5%$%H!#$?$H$($P!"

% clamdscan Foto1.doc.exe
Foto1.doc.exe Trojan.Downloader-56253 FOUND
% md5 Foto1.doc.exe
MD5 (Foto1.doc.exe) = 7bbf2ce8d8695d16ad3a2fb79d37d8fe

$B$G;n$7$F$_$k$H$3$s$J46$8!#(B

% whois -h hash.cymru.com 7bbf2ce8d8695d16ad3a2fb79d37d8fe
7bbf2ce8d8695d16ad3a2fb79d37d8fe 1222237907 11
% dig +short 7bbf2ce8d8695d16ad3a2fb79d37d8fe.malware.hash.cymru.com TXT
"1222237907 11"

$B!!(BGNU netcat $B$r;H$&$H!"J#?t$N%O%C%7%e$r0l3g$7$FLd$$$"$o$;$G$-$k$=$&$G!#(B


$B"#(B 2008.12.19

$B"#(B APSB08-24: Security update available for Linux Flash Player 10.0.12.36 and Linux Flash Player 9.0.151.0
(Adobe, 2008.12.17)

$B!!(BLinux $BHG$N(B Flash Player 10.0.12.36 $B0JA0(B / 9.0.151.0 $B0JA0$K7g4Y!#96N,(B SWF $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2008-5499

$B!!(BLinux $BHG(B Flash Player 10.0.15.3 / 9.0.152.0 $B$G=$@5$5$l$F$$$k!#(BAdobe $B<+?H$O(B 10.0.15.3 $B$NMxMQ$r?d>)$7$F$$$k!#(B

$B"#(B SYM08-022: Symantec SPBBCDRV.SYS $B%G%P%$%9%I%i%$%P$K!"%m!<%+%k$G%5!<%S%95qH]$N@H
(Symantec, 2008.12.12)

$B"#(B DNS$B%5!<%P$N@H
(IPA, 2008.12.19)

$B!!$&$o!D!D!#$<$s$<$sD>$C$F$^$;$s$M!#(B

$B"#(B $BDI5-(B


$B"#(B 2008.12.18

$B"#(B $BDI5-(B

EEYEZD-20081209: Microsoft Internet Explorer 7 XML Zero-Day

$B!!(Bpatch $B=P$^$7$?!#(B

Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B


$B"#(B 2008.12.17

$B"#(B Firefox 3.0.5 and 2.0.0.19 security updates now available for download
(mozilla.org, 2008.12.16)

$B!!(BFirefox 3.0.5 / 2.0.0.19 $B=P$^$7$?!#J#?t$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$^$9!#(B $B$3$l$G(B Firefox 2 $B7ONs$OBG$A$I$a$G$9$M!#(B $B$"$o$;$F(B SeaMonkey 1.1.14 $B$b%j%j!<%9$5$l$F$$$^$9(B$B!#(B Thunderbird 2.0.0.19 $B$O$^$@$_$?$$!#(B

2008.12.21 $BDI5-(B:

$B!!$J$s$H!"(B2.0.0.19 $B$GD>$C$?$O$:$N(B MFSA 2008-65 $B$,(B Windows $BHG$G$@$1D>$C$F$$$J$+$C$?$=$&$G!"(B Firefox 2.0.0.20 $B$,6[5^%j%j!<%9$5$l$F$$$^$9!#(B

$B!!$H$$$&$o$1$G!"(BFirefox 2 $B7ONs$N:G=*HG$O(B 2.0.0.20 $B$K$J$j$^$7$?!#(B

$B"#(B $BDI5-(B


$B"#(B 2008.12.16

$B"#(B Opera 9.63 for Windows $B99?7MzNr(B
(Opera.com, 2008.12.16)

$B!!(B7 $B$B%@%&%s%m!<%I(B$B!#(B

$B"#(B ad4U ($B3t<02q
(various)

$B"#(B $B$$$m$$$m(B (2008.12.16)
(various)

$B"#(B $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2008-008 / Mac OS X v10.5.6 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B
(Apple, 2008.12.15)

$B!!(BMac OS X 10.5.6$B!"$*$h$S!"(BMac OS X 10.4.11 $BMQ%;%-%e%j%F%#%"%C%W%G!<%H(B 2008-008 $BEP>l!#(B $BNc$K$h$C$FBgNL$N=$@5$,4^$^$l$F$$$k!#(B

$B%b%8%e!<%kL>(B CVE $BHV9f(B $BBP>](B $B35@b(B
Apple Type Services (ATS) CVE-2008-4236 10.5.x ATS $B%5!<%P$,96N,(B PDF $B%U%!%$%k$K$h$k(B DoS $B967b(B ($BL58B(B loop) $B$r
BOM CVE-2008-4217 10.4.x / 10.5.x $B96N,(B CPIO $B%"!<%+%$%V$K$h$C$FG$0U$N%3!<%I$r
CoreGraphics CVE-2008-3623 10.4.x / 10.5.x $B96N,2hA|%U%!%$%k$K$h$C$FG$0U$N%3!<%I$r
CVE-2008-3170 10.4.x / 10.5.x Safari $B$,(B ccTLD $B$KBP$9$k%/%C%-!<$N@_Dj$r5v$9$?$a!"(B $B96N,(B Web $B%5%$%H$r1\Mw$9$k$H%f!<%6$N>ZL@=q$,O31L$9$k2DG=@-$,$"$k!#(B
CoreTypes CVE-2008-4234 10.5.x $B%@%&%s%m!<%I$7$?0BA4$G$J$$%3%s%F%s%D$r5/F0$9$k$H$-$K!"7Y9p$,I=<($5$l$J$$!#(B
Flash Player Plug-in CVE-2008-4818 CVE-2008-4819
CVE-2008-4820 CVE-2008-4821
CVE-2008-4822 CVE-2008-4823
CVE-2008-4824
10.4.x / 10.5.x $B%"%I%S(B $B%7%9%F%`%:!"(B Adobe Flash Player 10$B$NDs6!$r3+;O(B$B$N7o!#(B
Kernel CVE-2008-4218 10.5.x local user $B$,%7%9%F%`8"8B$r
CVE-2008-4219 10.5.x $B%@%$%J%_%C%/%i%$%V%i%j$K%j%s%/$7$F$$$k!"(BNFS $B%5!<%P>e$N
Libsystem CVE-2008-4220 10.4.x / 10.5.x inet_net_pton() $B<+BN$K(B integer overflow $B$9$k7g4Y$,$"$j!"(B inet_net_pton() $B$rMxMQ$9$k%"%W%j%1!<%7%g%s$K$*$$$F!"G$0U$N%3!<%I$r
CVE-2008-4221 10.4.x / 10.5.x strptime() $B<+BN$K%a%b%jGK2u$9$k7g4Y$,$"$j!"(B strptime() $B$rMxMQ$9$k%"%W%j%1!<%7%g%s$K$*$$$F!"G$0U$N%3!<%I$r
CVE-2008-1391 10.4.x / 10.5.x strfmon() $B<+BN$K(B integer overflow $B$9$k7g4Y$,J#?t$"$j!"(B strfmon() $B$rMxMQ$9$k%"%W%j%1!<%7%g%s$K$*$$$F!"G$0U$N%3!<%I$r
Managed Client CVE-2008-4237 10.5.x managed screen saver $B@_Dj$,E,MQ$5$l$J$$!#(B
network_cmds CVE-2008-4222 10.4.x / 10.5.x $B%$%s%?!<%M%C%H6&M-$,M-8z$J>l9g$K!"96N,(B TCP $B%Q%1%C%H$K$h$C$F(B remote $B$+$i(B DoS $B967b$r
Podcast Producer CVE-2008-4223 10.5.x remote $B$N967b
UDF CVE-2008-4224 10.4.x / 10.5.x ISO $B%U%!%$%k$r3+$/$HM=4|$;$:(B shutdown $B$9$k$3$H$,$"$k!#(B

$B"#(B Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability
(sec-consult.com, 2008.12.09)

$B!!(BMicrosoft SQL Server 2000 / 2005 $B$K7g4Y!#3HD%%9%H%"%I%W%m%7!<%8%c(B sp_replwritetovarbin ($B$I$N%f!<%6$G$bMxMQ$G$-$k(B) $B$r;H$C$F%a%b%j$X$N=q$-9~$_$r

$B!!3HD%%9%H%"%I%W%m%7!<%8%c(B sp_replwritetovarbin $B$r:o=|$9$k$3$H$G2sHr$G$-$k!#(B $B4IM}execute dbo.sp_dropextendedproc 'sp_replwritetovarbin' $B$rRemoving an Extended Stored Procedure from SQL Server $B$r;2>H!#(B

$B!!$0$0$C$F$_$?$H$3$m!"3HD%%9%H%"%I%W%m%7!<%8%c(B sp_replwritetovarbin $B$K$D$$$F$O(B Microsoft SQL Server 2005 Database Engine Common Criteria Evaluation $B$G$b?($l$i$l$F$$$^$9$M!#(B sp_replsendtoqueue $B$H$$$&$N$b$"$k$=$&$G!#(B

2008.12.23 $BDI5-(B:

$B!!(BSA $B=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (961040) SQL Server $B$N@H (Microsoft)$B!#(B SQL Server 2000 / 2005$B!"(BSQL Server 2005 Express$B!"(BMSDE 2000$B!"(BWMSDE$B!"(BWindows Internal Database $B$K$3$N7g4Y$,$"$j!"(B SQL Server 7$B!"(BSQL Server 2005 SP3$B!"(BSQL Server 2008 $B$K$O$3$N7g4Y$O$J$$$=$&$G!#(B CVE-2008-4270

$B!!$3$N7g4Y$rMxMQ$7$?967b$rZ$,I,MW$@$,!"(BWeb $B%"%W%j$N(B SQL $B%$%s%8%'%/%7%g%s7g4Y$r7PM3$9$k>l9g$K$O!"!VG'>Z$,I,MW!W$H$$$&%O!<%I%k$,$J$/$J$C$F$7$^$&!#(B

$B!!(BMicrosoft $B$N?d>)2sHr:v$O!V(Bsp_replwritetovarbin $B3HD%%9%H%"%I%W%m%7!<%8%c$N%"%/%;%9$r5qH]$9$k!WJ}K!!#>\:Y$O(B SA $B$r;2>H!#(B

$B!!4XO"(B: More information about the SQL stored procedure vulnerability (Microsoft SVRD blog, 2008.12.22)

2008.12.25 $BDI5-(B:

$B!!(BMicrosoft Security Advisory: Vulnerability in SQL Server could allow remote code execution (Microsoft KB961040)$B!#2sHr:v<+F0

2009.02.12 $BDI5-(B:

$B!!(BMS09-004 - $B=EMW(B: SQL Server $B$N@H $B$G=$@5$5$l$^$7$?!#(B


$B"#(B 2008.12.15

$B"#(B Wireshark 1.0.5 Released
(Wireshark.org, 2008.12.10)

$B!!(BWireshark 1.0.5 $BEP>l!#(BSMTP dissector $B$,(B CPU / $B%a%b%j$r?)$$$A$i$+$97g4Y(B (1.0.4) $B$H!"(BWLCCP dissector $B$,L58B%k!<%W$KFMF~$9$k7g4Y(B (0.99.7 $B!A(B 1.0.4) $B$,=$@5$5$l$F$$$k$=$&$G$9!#(B

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (960906) Microsoft $B%o!<%I%Q%C%I$N%F%-%9%H(B $B%3%s%P!<%?!<$N@H

EEYEZD-20081209: Microsoft Internet Explorer 7 XML Zero-Day

$B!!(B$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (961051) Internet Explorer $B$N@H (Microsoft) $B$,(B 2008.12.13 $BIU$G2~D{$5$l$F$$$^$9!#(Bcadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

  • $B2sHr:v!V(BACL $B$r;HMQ$7$F(B OLEDB32.DLL $B$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B$3$N2sHr:v$O!"(BWindows Vista$B$*$h$S!"$=$l0J9_$N%*%Z%l!<%F%#%s%0%7%9%F%`$KE,MQ2DG=$N$b$N$G!"4{Dj$GM-8z$H$J$C$F$$$k(BUAC$B$K$h$kDLCN5!G=$H!"J]8n%b!<%I$,M-8z$K$J$C$F$$$kI,MW$,$"$j$^$9!#(B($BCfN,(B)
    $B2sHr:v$N1F6A(B: $B0lHLE*$G$O$"$j$^$;$s$,!"(BADO/OLE DB$B%"%W%j%1!<%7%g%s$,(BInternet Explorer$B>e$GF0:n$7$F$$$k>l9g$K!"5!G=$7$J$/$J$j$^$9!#@09g@-%l%Y%k$,!"!VCf!W0J>e$NB>$N%W%m%;%9$G$O!"2sHr:v$N.8B$NHO0O$K<}$^$j$^$9!#(B
  • $B2sHr:v!V(BOLEDB32.dll$B$N(BRow Position$B5!G=$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B:$B$9$Y$F$N(BRowPosition$B%W%m%Q%F%#$H$=$l$KIU?o$9$k>pJs$r;HMQ$9$k(BADO$B%"%W%j%1!<%7%g%s$,5!G=$7$J$/$J$j$^$9!#(B $B$9$Y$F$N(BOLE DB Row Position $B%i%$%V%i%j$r;HMQ$9$k(BOLE DB$B%"%W%j%1!<%7%g%s$,5!G=$7$J$/$J$j$^$9!#(B
  • $B2sHr:v!V(BOLEDB32.DLL $B$NEPO?$r2r=|$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B:$B$9$Y$F$N(BOLE DB$B$*$h$S(BADO$B%"%W%j%1!<%7%g%s$O5!G=$7$J$/$J$j$^$9!#$3$l$O!"$9$Y$F$N(BASP/ADO$B$NA06u4V$r;HMQ$9$k(B .NET $B%"%W%j%1!<%7%g%s!"$*$h$S!"30It%G!<%?$r;2>H$9$k%*%U%#%9%"%W%j%1!<%7%g%s$,4^$^$l$^$9!#(B


$B!!!D!D$H$+=q$$$F$$$k4V$K$^$?99?7$5$l$F$^$9$h!#(B

  • $B2sHr:v!V(BXML $B%"%$%i%s%I5!G=$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B: HTML $B$KKd$a9~$^$l$?(B XML $B$,@5$7$/%l%s%@%j%s%0$5$l$J$/$J$k2DG=@-$,$"$j$^$9!#(B
  • $B2sHr:v!V(BInternet Explorer 8 Beta 2 $B$N%G!<%?(B $B%P%$%s%G%#%s%0(B $B%5%]!<%H$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B: $B$3$N2sHr:v$K$h$j!"$9$Y$F$N%;%-%e%j%F%#(B $B%>!<%s$K$D$$$F%G!<%?(B $B%P%$%s%G%#%s%0$,L58z$K$J$j$^$9!#(B $B%G!<%?(B $B%P%$%s%G%#%s%0$r;HMQ$7$F$$$k$9$Y$F$N%"%/%;%9$5$l$?(B Web $B%5%$%H$,E,@Z$K%l%s%@%j%s%0$7$J$/$J$j$^$9!#(B

$B!!4XO"(B:


$B"#(B 2008.12.12

$B"#(B $BDI5-(B

EEYEZD-20081209: Microsoft Internet Explorer 7 XML Zero-Day

$B!!$I$&$d$i(B IE7 $B$@$1$G$J$/!"(BIE 5.01 / 6 / 8 Beta $B$K$b1F6A$9$k$h$&$G$9!#(B

  • Microsoft Security Advisory (961051) Vulnerability in Internet Explorer Could Allow Remote Code Execution (Microsoft)$B!#(B2008.12.11 $BIU$G99?7$5$l!"(BIE 5.01 / 6 / 8 Beta $B$K$b7g4Y$,$"$k$H$5$l$F$$$^$9!#(B$BF|K\8lHG(B$B$O$^$@99?7$5$l$F$$$^$;$s$,!"$=$N$&$AJQ$o$k$G$7$g$&!#(B $B!D!DJQ$o$j$^$7$?!#(B

  • Microsoft Security Advisory 961051 Updated (MSRC blog, 2008.12.11)

    We've also added additional workarounds to the advisory and updated our guidance to recommend that you evaluate implementing two of the workarounds together for the most effective protection. Specifically, we're recommending both setting the Internet zone security setting to High and using ACLs to disable Ole32db.dll.

    Ole32db.dll $B!D!D$G$O$J$/$F(B OLEDB32.DLL $B$NL58z2=Microsoft Security Advisory (961051) $B$r;2>H!#(B(cadz $B$5$s46

$B!!$V$C$A$c$1!"!VIaCJ$O(B IE $B$O;H$o$J$$!W$N$,5H$G$7$g$&!#%G%U%)%k%H$N(B web $B%V%i%&%6$b(B IE $B$G$O$J$$$b$N$KJQ99$7$F$*$-$^$7$g$&!#(BFirefox $B$N>l9g$O!"(BIE Tab $B$r;H$&$H!V(BIE $B$G$J$$$H%@%a$J%5%$%H!W$H$N$*$D$-$"$$$b3Z$K$J$j$^$9!#(B

$B!!$"$H!"(Bexploit $B$G$9$,(B

$B!!(BSQL $B%$%s%8%'%/%7%g%s$G967b%3!<%I$D$C$3$^$l$k;vNc$b$"$k$h$&$G(B: MSIE 0-day Spreading Via SQL Injection (SANS ISC, 2008.12.12)

$B!!4XO"(B: Microsoft Internet Explorer $B$G$N(B Span $B%?%0$K$h$k%3!<%I (ISSKK, 2008.12.11)$B!#8=:_!"(BAlertCon $B$O(B 2 $B$G$9$M!#(B


$B"#(B 2008.12.11

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (960906) Microsoft $B%o!<%I%Q%C%I$N%F%-%9%H(B $B%3%s%P!<%?!<$N@H
(Microsoft, 2008.12.10)

$B"#(B EEYEZD-20081209: Microsoft Internet Explorer 7 XML Zero-Day
(eEye, 2008.12.09)

$B!!$3$l$N$3$H$+$J$"(B: MS Internet Explorer XML Parsing Remote Buffer Overflow Exploit (milw0rm)

$B!!4XO"(B:

$B!!(BMicrosoft $B$+$i$b=P$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (961051) Internet Explorer $B$N@H (Microsoft, 2008.12.11)$B!#(B CVE-2008-4844$B!#(B $B?9ED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2008.12.12 $BDI5-(B:

$B!!$I$&$d$i(B IE7 $B$@$1$G$J$/!"(BIE 5.01 / 6 / 8 Beta $B$K$b1F6A$9$k$h$&$G$9!#(B

  • Microsoft Security Advisory (961051) Vulnerability in Internet Explorer Could Allow Remote Code Execution (Microsoft)$B!#(B2008.12.11 $BIU$G99?7$5$l!"(BIE 5.01 / 6 / 8 Beta $B$K$b7g4Y$,$"$k$H$5$l$F$$$^$9!#(B$BF|K\8lHG(B$B$O$^$@99?7$5$l$F$$$^$;$s$,!"$=$N$&$AJQ$o$k$G$7$g$&!#(B $B!D!DJQ$o$j$^$7$?!#(B

  • Microsoft Security Advisory 961051 Updated (MSRC blog, 2008.12.11)

    We've also added additional workarounds to the advisory and updated our guidance to recommend that you evaluate implementing two of the workarounds together for the most effective protection. Specifically, we're recommending both setting the Internet zone security setting to High and using ACLs to disable Ole32db.dll.

    Ole32db.dll $B!D!D$G$O$J$/$F(B OLEDB32.DLL $B$NL58z2=Microsoft Security Advisory (961051) $B$r;2>H!#(B(cadz $B$5$s46

$B!!$V$C$A$c$1!"!VIaCJ$O(B IE $B$O;H$o$J$$!W$N$,5H$G$7$g$&!#%G%U%)%k%H$N(B web $B%V%i%&%6$b(B IE $B$G$O$J$$$b$N$KJQ99$7$F$*$-$^$7$g$&!#(BFirefox $B$N>l9g$O!"(BIE Tab $B$r;H$&$H!V(BIE $B$G$J$$$H%@%a$J%5%$%H!W$H$N$*$D$-$"$$$b3Z$K$J$j$^$9!#(B

$B!!$"$H!"(Bexploit $B$G$9$,(B

$B!!(BSQL $B%$%s%8%'%/%7%g%s$G967b%3!<%I$D$C$3$^$l$k;vNc$b$"$k$h$&$G(B: MSIE 0-day Spreading Via SQL Injection (SANS ISC, 2008.12.12)

$B!!4XO"(B: Microsoft Internet Explorer $B$G$N(B Span $B%?%0$K$h$k%3!<%I (ISSKK, 2008.12.11)$B!#8=:_!"(BAlertCon $B$O(B 2 $B$G$9$M!#(B

2008.12.15 $BDI5-(B:

$B!!(B$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (961051) Internet Explorer $B$N@H (Microsoft) $B$,(B 2008.12.13 $BIU$G2~D{$5$l$F$$$^$9!#(Bcadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

  • $B2sHr:v!V(BACL $B$r;HMQ$7$F(B OLEDB32.DLL $B$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B$3$N2sHr:v$O!"(BWindows Vista$B$*$h$S!"$=$l0J9_$N%*%Z%l!<%F%#%s%0%7%9%F%`$KE,MQ2DG=$N$b$N$G!"4{Dj$GM-8z$H$J$C$F$$$k(BUAC$B$K$h$kDLCN5!G=$H!"J]8n%b!<%I$,M-8z$K$J$C$F$$$kI,MW$,$"$j$^$9!#(B($BCfN,(B)
    $B2sHr:v$N1F6A(B: $B0lHLE*$G$O$"$j$^$;$s$,!"(BADO/OLE DB$B%"%W%j%1!<%7%g%s$,(BInternet Explorer$B>e$GF0:n$7$F$$$k>l9g$K!"5!G=$7$J$/$J$j$^$9!#@09g@-%l%Y%k$,!"!VCf!W0J>e$NB>$N%W%m%;%9$G$O!"2sHr:v$N.8B$NHO0O$K<}$^$j$^$9!#(B
  • $B2sHr:v!V(BOLEDB32.dll$B$N(BRow Position$B5!G=$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B:$B$9$Y$F$N(BRowPosition$B%W%m%Q%F%#$H$=$l$KIU?o$9$k>pJs$r;HMQ$9$k(BADO$B%"%W%j%1!<%7%g%s$,5!G=$7$J$/$J$j$^$9!#(B $B$9$Y$F$N(BOLE DB Row Position $B%i%$%V%i%j$r;HMQ$9$k(BOLE DB$B%"%W%j%1!<%7%g%s$,5!G=$7$J$/$J$j$^$9!#(B
  • $B2sHr:v!V(BOLEDB32.DLL $B$NEPO?$r2r=|$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B:$B$9$Y$F$N(BOLE DB$B$*$h$S(BADO$B%"%W%j%1!<%7%g%s$O5!G=$7$J$/$J$j$^$9!#$3$l$O!"$9$Y$F$N(BASP/ADO$B$NA06u4V$r;HMQ$9$k(B .NET $B%"%W%j%1!<%7%g%s!"$*$h$S!"30It%G!<%?$r;2>H$9$k%*%U%#%9%"%W%j%1!<%7%g%s$,4^$^$l$^$9!#(B


$B!!!D!D$H$+=q$$$F$$$k4V$K$^$?99?7$5$l$F$^$9$h!#(B

  • $B2sHr:v!V(BXML $B%"%$%i%s%I5!G=$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B: HTML $B$KKd$a9~$^$l$?(B XML $B$,@5$7$/%l%s%@%j%s%0$5$l$J$/$J$k2DG=@-$,$"$j$^$9!#(B
  • $B2sHr:v!V(BInternet Explorer 8 Beta 2 $B$N%G!<%?(B $B%P%$%s%G%#%s%0(B $B%5%]!<%H$rL58z$K$9$k!W$,DI2C$5$l$F$$$^$9!#(B

    $B2sHr:v$N1F6A(B: $B$3$N2sHr:v$K$h$j!"$9$Y$F$N%;%-%e%j%F%#(B $B%>!<%s$K$D$$$F%G!<%?(B $B%P%$%s%G%#%s%0$,L58z$K$J$j$^$9!#(B $B%G!<%?(B $B%P%$%s%G%#%s%0$r;HMQ$7$F$$$k$9$Y$F$N%"%/%;%9$5$l$?(B Web $B%5%$%H$,E,@Z$K%l%s%@%j%s%0$7$J$/$J$j$^$9!#(B

$B!!4XO"(B:

2008.12.17 $BDI5-(B:

$B!!Mh$?$h$&$G$9!#L@F|%j%j!<%9M=Dj!#(B

$B!!(BMS Internet Explorer XML Parsing Buffer Overflow Exploit (allinone) (milw0rm)

2008.12.18 $BDI5-(B:

$B!!(Bpatch $B=P$^$7$?!#(B

2008.12.25 $BDI5-(B:

$B!!4XO"(B:

$B"#(B [tomoyo-users 522] TOMOYO Linux 1.6.5 $B$NIT6q9g$K$D$$$F(B
(tomoyo-users, 2008.12.09)

$B!!(BTOMOYO Linux 1.6.5 $B$K$O%a%b%j$rO2Hq$7$F$7$^$&IT6q9g$,$"$k$=$&$G$9!#(B

  • $B2sHrJ}K!(B: /usr/sbin/ccs-auditd /dev/null /dev/null $B$r

  • $BBP1~J}K!(B: [tomoyo-users 522] $B$KE:IU$5$l$F$$$k(B patch $B$r;H$C$F(B TOMOYO Linux 1.6.5 $B$r:F9=C[$9$k$+!"(B $B4V$b$J$/8x3+$5$l$kM=Dj$N=$@5HG%P%$%J%j$r;HMQ$9$k!#(B

$B!!7'G-$5$/$i$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2008.12.10

$B"#(B $B$$$m$$$m(B (2008.12.10)
(various)

$B"#(B Microsoft 2008 $BG/(B 12 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2008.12.10)

MS08-070 - $B6[5^(B: Visual Basic 6.0 $B%i%s%?%$%`3HD%%U%!%$%k(B (ActiveX $B%3%s%H%m!<%k(B) $B$N@H

$B!!(BVisual Basic 6.0 $B%i%s%?%$%`3HD%%U%!%$%k$K4^$^$l$k(B ActiveX $B%3%s%H%m!<%k$KJ#?t$N7g4Y!#LdBj$H$J$k%U%!%$%k$N0lIt$O(B Visual Studio .NET 2002 / 2003$B!"(BVisual FoxPro 8.0 / 9.0$B!"(BOffice FrontPage 2002$B!"(BOffice Project 2003 / 2007 $B$K$b4^$^$l$k!#(B

  • $B%^%9%/JT=8%3%s%H%m!<%k$N%a%b%j$NGKB;$N@HCVE-2008-3704$B!"(B Microsoft Visual Studio (Msmask32.ocx) ActiveX Remote BOF PoC (milw0rm, 2008.08.14)
    Exploitability Index: 1

  • DataGrid $B%3%s%H%m!<%k$N%a%b%j$NGKB;$N@HCVE-2008-4252
    Exploitability Index: 1

  • FlexGrid $B%3%s%H%m!<%k$N%a%b%jGKB;$N@HCVE-2008-4253
    Exploitability Index: 2

  • $B3,AX(B FlexGrid $B%3%s%H%m!<%k$N%a%b%j$NGKB;$N@HCVE-2008-4254
    Exploitability Index: 2

  • Windows $B$N%3%b%s(B AVI $B2r@O$N%*!<%P!<%U%m!<$N@HCVE-2008-4255
    Exploitability Index: 2

  • $B%A%c!<%H(B $B%3%s%H%m!<%k$N%a%b%j$NGKB;$N@HCVE-2008-4256
    Exploitability Index: 1

MS08-071 - $B6[5^(B: GDI $B$N@H

MS08-072 - $B6[5^(B: Microsoft Office Word $B$N@H

$B!!(BWord 2000 / 2002 (XP) / 2003 / 2007$B!"(BOutlook 2007$B!"(BWorks 8$B!"(BWord Viewer 2003$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$KJ#?t$N7g4Y!#(B

  • Word $B$N%a%b%j$NGKB;$N@HCVE-2008-4024
    Exploitability Index: 1

  • Word $B$N(B RTF $B$N%*%V%8%'%/%H$N2r@O$N@HCVE-2008-4025
    Exploitability Index: 2

  • Word $B$N%a%b%j$NGKB;$N@HCVE-2008-4026
    Exploitability Index: 2

  • Word $B$N(B RTF $B$N%*%V%8%'%/%H$N2r@O$N@HCVE-2008-4027
    Exploitability Index: 2

  • Word $B$N(B RTF $B$N%*%V%8%'%/%H$N2r@O$N@HCVE-2008-4028
    Exploitability Index: 2

  • Word $B$N(B RTF $B$N%*%V%8%'%/%H$N2r@O$N@HCVE-2008-4030
    Exploitability Index: 2

  • Word $B$N(B RTF $B$N%*%V%8%'%/%H$N2r@O$N@HCVE-2008-4031
    Exploitability Index: 3

  • Word $B$N%a%b%j$NGKB;$N@HCVE-2008-4837
    Exploitability Index: 2

MS08-073 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (958215)

$B!!(BIE 5.01 / 6 / 7 $B$KJ#?t$N7g4Y!#(B

MS08-074 - $B6[5^(B: Microsoft Office Excel $B$N@H

MS08-075 - $B6[5^(B: Windows Search $B$N@H

MS08-076 - $B=EMW(B: Windows Media $B%3%s%]!<%M%s%H$N@H

$B!!(BWindows Media Player 6.4 / 7.1 / 9.0 / 9.5 / 11$B!"(BWindows Media $B%5!<%S%9(B 4.1 / 9 / 2008 $B$KJ#?t$N7g4Y!#(B

  • SPN $B$N@HCVE-2008-3009
    Exploitability Index: 1

  • ISATAP $B$N@HCVE-2008-3010$B!#(BNTLM $B;q3J>pJs$,O3$($$$9$k2DG=@-!#(B
    Exploitability Index: 1

$B!!4XO"(B:

MS08-077 - $B=EMW(B: Microsoft Office SharePoint Server $B$N@H:3J$5$l$k(B (957175)

$B!!(BSharePoint Server 2007 / Search Server 2008 $B$K7g4Y!#(B $B967bZ$J$7$G@\B3$9$k$3$H$K$h$j!"8"8B>e>:$r>7$/!#(B CVE-2008-4032

$B!!(BExploitability Index: 1

$B!!4XO"(B:

2009.11.25 $BDI5-(B:

$B!!(BMS08-076 - $B=EMW(B: Windows Media $B%3%s%]!<%M%s%H$N@H $B$,2~D{$5$l$F$$$k!#(B

2009/11/25: $B$3$N%;%-%e%j%F%#>pJs$r99?7$7!"!V$3$N%;%-%e%j%F%#99?7%W%m%0%i%`$K4X$9$k$h$/4s$;$i$l$k)$7$^$9!#$=$NB>$N%*%Z%l!<%F%#%s%0(B $B%7%9%F%`$r$4MxMQ$N$*5RMM$G!"$3$N99?7%W%m%0%i%`$r4{$K%$%s%9%H!<%k:Q$_$N>l9g$O!"$=$NB>$NA

$B!!$&$*$C!"$3$l$O!D!D!#C1$K!V$3$N99?7%W%m%0%i%`$r4{$K%$%s%9%H!<%k:Q$_$N>l9g$O!"$=$NB>$NA

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2008.08.18)

SecurityReason.com : PHP 5.2.6 SAPI php_getuid() overload

$B!!(BPHP 5.2.7 $B$K$O%P%0$,$"$C$?$=$&$G!":G?7$N(B PHP $B$O(B PHP 5.2.8 $B$G$9!#>._7$5$s!"?@8M$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B PHP 5.2.7 Release Announcement $B$r8+$k$H!"B>$K$b$$$m$$$mD>$C$F$$$k$h$&$G!#(B

Security Enhancements and Fixes in PHP 5.2.7:
  • Upgraded PCRE to version 7.8 (Fixes CVE-2008-2371)
  • Fixed missing initialization of BG(page_uid) and BG(page_gid), reported by Maksymilian Arciemowicz.
  • Fixed incorrect php_value order for Apache configuration, reported by Maksymilian Arciemowicz.
  • Fixed a crash inside gd with invalid fonts (Fixes CVE-2008-3658).
  • Fixed a possible overflow inside memnstr (Fixes CVE-2008-3659).
  • Fixed security issues detailed in CVE-2008-2665 and CVE-2008-2666.
  • Fixed bug #45151 (Crash with URI/file..php (filename contains 2 dots)).(Fixes CVE-2008-3660)
  • Fixed bug #42862 (IMAP toolkit crash: rfc822.c legacy routine buffer overflow). (Fixes CVE-2008-2829)

$B"#(B 2008.12.09

$B"#(B SecurityReason.com : PHP 5.2.6 SAPI php_getuid() overload
(SecurityReason, 2008.12.05)

$B!!(BPHP 5.2.6 $B0JA0$K7g4Y!#(BPHP $B$r(B apache $B%b%8%e!<%k$H$7$FF0:n$5$;$F$$$k>l9g!"(B .htaccess $B$r;H$C$F(B PHP $B$N@_Dj$rJQ99$G$-$k(B$B$N$@$,!"$3$N@_Dj$,@5$7$/=hM}$5$l$J$$>l9g$,$"$k!#(B $B;vNc$H$7$F>R2p$5$l$F$$$k$N$O(B error_log $B$N@_Dj$,H?1G$5$l$J$$$3$H$,$"$k!"$H$$$&$b$N!#(B CVE-2008-5624 CVE-2008-5625

$B!!(BPHP 5.2.7 $B$G=$@5$5$l$F$$$k!#(B

2008.12.10 $BDI5-(B:

$B!!(BPHP 5.2.7 $B$K$O%P%0$,$"$C$?$=$&$G!":G?7$N(B PHP $B$O(B PHP 5.2.8 $B$G$9!#>._7$5$s!"?@8M$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B PHP 5.2.7 Release Announcement $B$r8+$k$H!"B>$K$b$$$m$$$mD>$C$F$$$k$h$&$G!#(B

Security Enhancements and Fixes in PHP 5.2.7:
  • Upgraded PCRE to version 7.8 (Fixes CVE-2008-2371)
  • Fixed missing initialization of BG(page_uid) and BG(page_gid), reported by Maksymilian Arciemowicz.
  • Fixed incorrect php_value order for Apache configuration, reported by Maksymilian Arciemowicz.
  • Fixed a crash inside gd with invalid fonts (Fixes CVE-2008-3658).
  • Fixed a possible overflow inside memnstr (Fixes CVE-2008-3659).
  • Fixed security issues detailed in CVE-2008-2665 and CVE-2008-2666.
  • Fixed bug #45151 (Crash with URI/file..php (filename contains 2 dots)).(Fixes CVE-2008-3660)
  • Fixed bug #42862 (IMAP toolkit crash: rfc822.c legacy routine buffer overflow). (Fixes CVE-2008-2829)

$B"#(B $BDI5-(B

VideoLAN Security Advisory 0811: Buffer overflow in Real demuxer

$B!!(BVLC media player 0.9.8a $B$N(B Windows / Mac $BMQ%P%$%J%j=P$^$7$?!#(B


$B"#(B 2008.12.08

$B"#(B $BDI5-(B


$B"#(B 2008.12.06

$B"#(B $BDI5-(B


$B"#(B 2008.12.05

$B"#(B $BDI5-(B

VideoLAN Security Advisory 0811: Buffer overflow in Real demuxer

$B!!%"%I%P%$%6%j$,2~D{$5$l!"(BVLC Media Player 0.9.0 $B!A(B 0.9.8 $B$K7g4Y$,$"$j!"(B 0.9.8a $B$G=$@5$5$l$F$$$k!"$H$5$l$F$$$^$9!#(BWindows / Mac OS X $BMQ%P%$%J%j$O$$$^$@$K(B 0.9.6 $B$N$^$^$_$?$$!#(B

$B!!!D!D(BWindows $BHG$N%P%$%J%j$K$D$$$F$O!"(Bhttp://download.videolan.org/pub/vlc/0.9.8a/win32/ $B$+$iF~pJs$"$j$,$H$&$4$6$$$^$9!#(B

Advance notification of Security Updates for Java SE

$B!!(BSun Alerts $B=P$?$h$&$G$9!#CfED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS08-066 patch $B$K$O!"(BCheckpoint ZoneAlarm Pro 6.5.645.000$B!A(B7.0.482.000 $B$J$I$HIT@09g$r5/$3$9LdBj$,$"$C$?$=$&$J$N$G$9$,!"(B KB958752 patch $B$rE,MQ$9$k$3$H$G$3$NLdBj$KBP1~$G$-$k$=$&$G$9!#(B $B$b$C$H$b!"(BZoneAlarm Pro 7.0.483.00 $B0J9_$rMxMQ$9$k$3$H$G$bBP1~$G$-$k$=$&$G$9$,!#(B

$B"#(B $B$$$m$$$m(B (2008.12.05)
(various)

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2008 $BG/(B 12 $B7n(B
(Microsoft, 2008.12.05)

$B!!$b$&$=$s$J5(@a$G$9!#(BWindows x 2$B!"(BIE$B!"(BVisual Basic$B!"(BWord$B!"(BExcel$B!"(BSharePoint$B!"(BWindows Media $B%3%s%]!<%M%s%H$G$9$+!#(B $B$"$H!"%;%-%e%j%F%#$G$J$$99?7$K$D$$$F$O(B Description of Software Update Services and Windows Server Update Services changes in content for 2008 (Microsoft KB894199) $B$r;2>H!#(B

$B!!4XO"(B: 2008$BG/(B12$B7n$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2008.12.05)


$B"#(B 2008.12.04

$B"#(B $B$$$m$$$m(B (2008.12.04)
(various)

$B"#(B [Security-announce] VMSA-2008-0019 VMware Hosted products and patches for ESX and ESXi resolve a critical security issue and update bzip2
(VMware, 2008.12.02)

$B!!(BVMware $B@=IJ$K(B 2 $B$D$N7g4Y!#(B

$BCWL?E*$J%a%b%jGK2u$,H/@8$9$k(B

$B!!(BVMWare Workstation 5.x / 6.0.x$B!"(BPlayer 1.x / 2.0.x$B!"(BACE 1.x / 2.0.x$B!"(BServer 1.x$B!"(BFusion 1.x$B!"(BESX 3.x$B!"(BESXi 3.5 $B$K7g4Y!#(B $B%2%9%H(B OS $B$+$i2>A[%O!<%I%&%'%"$K96N,%j%/%(%9%H$rAw$k$H!"2>A[%O!<%I%&%'%"$,J*M}%a%b%j$K=q$-9~$`2DG=@-$,$"$k(B ($B0LCV$O;XDj$G$-$J$$(B)$B!#(B CVE-2008-4917

$B!!(BVMWare Workstation 5.5.9 / 6.5.x$B!"(BPlayer 1.0.9 / 2.5.x$B!"(BACE 1.0.8 / 2.5.x$B!"(BServer 1.0.8 / 2.x$B!"(BFusion 2.x $B$G=$@5$"$k$$$OBP1~$5$l$F$$$k!#(B ESX / ESXi $B$K$D$$$F$OBP1~(B patch $B$rE,MQ$9$k!#(B

bzip2 $B%Q%C%1!<%8$N99?7(B

$B!!(BVMware ESX 2.x / 3.x $B$K7g4Y!#Ec:\$5$l$F$$$k(B bzip2 $B%Q%C%1!<%8$K7g4Y$,$"$j!"96N,%"!<%+%$%V$K$h$C$F(B crash $B$9$k!#(BCVE-2008-1372

$B!!BP1~(B patch $B$rE,MQ$9$l$P$h$$!#$?$@$7!"(BESX 2.x $BMQ$N(B patch $B$O$^$@$J$$!#(B

$B!!(BCVE-2008-1372 $B$J$N$@$,!"(BFreeBSD 6.3 / 7.0 $B$N(B bzip2 $B$b3:Ev$9$k$h$&$J5$$,!#(B

$B"#(B JVN#02216739 - Movable Type Enterprise $B$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H
(JVN, 2008.12.03)

$B!!(BMovable Type Enterprise 1.56 / 4.23 $B$G=$@5$5$l$F$$$k$=$&$G$9!#4XO"(B: MT4.23 ($B?eL57n$P$1$i$N$($SF|5-(B, 2008.12.03)

$B$A$J$_$K!"(BMTE $B$N$[$&$K$O!V(BJVN#02216739 Movable Type Enterprise $B$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H\:YITL@$G$9$,!"!VFCDj$N%&%'%V%V%i%&%6>e$G!W!VJs9p

$B!!$=$&$$$&7O$G$9$+$M!D!D!#(B

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2008.10.17)

APSB08-19: Security Update available for Adobe Reader 8 and Acrobat 8

$B!!4XO"(B: $B%$%s%?!<%M%C%H$G9-$^$k(BPDF$B%^%k%&%(%"(B ($BF|7P(B IT Pro, 2008.12.04)

[Clamav-announce] announcing ClamAV 0.94.2

$B!!(BJPEG $B%U%!%$%k$N=hM}$K$*$$$F7g4Y$,$"$j!"96N,(B JPEG $B%U%!%$%k$K$h$C$F(B DoS $B967b$,2DG=$@$C$?LOMM!#(B

Advance notification of Security Updates for Java SE

$B!!8x3+$5$l$F$$$^$9!#(B

$B!!(BJava $B%3%s%H%m!<%k%Q%M%k$N%"%C%W%G!<%H5!G=$r;H$C$F$b99?7$G$-$k$3$H$r3NG'$7$^$7$?!#(B

$B!!(BSun Alerts 244986, 244987, 244988, 245246, 246386, 246387 $B$,=EMW$J$N$+$J!D!D!#$$$:$l$b$^$@8x3+$5$l$F$$$J$$$h$&$G$9!#(B


$B"#(B 2008.12.03


$B"#(B 2008.12.02

$B"#(B $BDI5-(B

$B"#(B Advance notification of Security Updates for Java SE
(Sun, 2008.12.01)

$B!!l$9$kM=Dj$@$=$&$G$9!#(B

  • JDK and JRE 6 Update 11
  • JDK and JRE 5.0 Update 17
  • SDK and JRE 1.4.2_19
  • SDK and JRE 1.3.1_24

$B!!(B14 $B

2008.12.04 $BDI5-(B:

$B!!8x3+$5$l$F$$$^$9!#(B

$B!!(BJava $B%3%s%H%m!<%k%Q%M%k$N%"%C%W%G!<%H5!G=$r;H$C$F$b99?7$G$-$k$3$H$r3NG'$7$^$7$?!#(B

$B!!(BSun Alerts 244986, 244987, 244988, 245246, 246386, 246387 $B$,=EMW$J$N$+$J!D!D!#$$$:$l$b$^$@8x3+$5$l$F$$$J$$$h$&$G$9!#(B

2008.12.05 $BDI5-(B:

$B!!(BSun Alerts $B=P$?$h$&$G$9!#CfED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2008.12.08 $BDI5-(B:

$B!!$^$@$"$j$^$7$?!#(B

$B"#(B VideoLAN Security Advisory 0811: Buffer overflow in Real demuxer
(VideoLAN.org, 2008.12.01)

$B!!(BVLC Media Player 0.9.0 $B!A(B 0.9.6 $B$K7g4Y!#(BReal Media $B%U%!%$%k$N%X%C%@=hM}$K$*$$$F(B integer overflow $B$,H/@8!"96N,(B Real Media $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2008-5276$B!"(BTKADV2008-013: VLC media player RealMedia Processing Integer Overflow Vulnerability (trapkit.de)$B!#(B

$B!!(BVLC Media Player 0.9.7 $B$G=$@5$5$l$F$$$k!#(B0.9.7 $B$N(B Windows / Mac OS X $BMQ%P%$%J%jHG$O$^$@MQ0U$5$l$F$$$J$$$_$?$$!#(B

$B!!!D!D0.9.8 $B$,EP>l$7$F$$$kLOMM!#J?;3$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2008.12.05 $BDI5-(B:

$B!!%"%I%P%$%6%j$,2~D{$5$l!"(BVLC Media Player 0.9.0 $B!A(B 0.9.8 $B$K7g4Y$,$"$j!"(B 0.9.8a $B$G=$@5$5$l$F$$$k!"$H$5$l$F$$$^$9!#(BWindows / Mac OS X $BMQ%P%$%J%j$O$$$^$@$K(B 0.9.6 $B$N$^$^$_$?$$!#(B

$B!!!D!D(BWindows $BHG$N%P%$%J%j$K$D$$$F$O!"(Bhttp://download.videolan.org/pub/vlc/0.9.8a/win32/ $B$+$iF~pJs$"$j$,$H$&$4$6$$$^$9!#(B

2008.12.06 $BDI5-(B:

$B!!(Bhttp://download.videolan.org/pub/vlc/0.9.8a/win32/ $B$NCf?H$,>C$($F$$$^$9!#$3$l$b@5<0HG$G$O$J$+$C$?$h$&$G!#(B VLC 0.9.8a - GUI Problems maximization and splitting (videolan.org) $B$K$h$k$H!"%F%9%HHG$O(B http://people.videolan.org/~jb/0.9.8a/ $B$K$"$k$=$&$G$9!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2008.12.09 $BDI5-(B:

$B!!(BVLC media player 0.9.8a $B$N(B Windows / Mac $BMQ%P%$%J%j=P$^$7$?!#(B


$B"#(B 2008.12.01

$B"#(B Google$B%"%+%&%s%H$r:o=|$9$k$H%^%$%^%C%W$d%+%l%s%@!<$r:o=|$G$-$J$/$J$k(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2008.11.29)

$B!!$3$3$^$GMh$k$H!">pJsNQM}$,$I$&$3$&0JA0$NLdBj$@$h$J$"!D!D!#$[$s$H!"$I$&$$$&@_7W$J$N$@$m$&!#(B


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B