$B%;%-%e%j%F%#%[!<%k(B memo - 2009.05

Last modified: Wed Jul 15 11:00:34 2009 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2009.05.30

$B"#(B $B$$$m$$$m(B (2009.05.30)
(various)

$B"#(B $BDI5-(B

IIS 6.0 + WebDAV: Unicode $B%P%0$N5U=1(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (971778) Microsoft DirectShow $B$N@H

$B!!(BMicrosoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released (MSRC blog, 2009.05.28) $B$N$3$NItJ,"-$,=EMW$J$N$G0zMQ$7$F$*$-$^$9$M!#(B

Also, we$B!G(Bve verified that it is possible to direct calls to DirectShow specifically, even if Apple$B!G(Bs QuickTime (which is not vulnerable) is installed.

$B!!(BQuickTime $B$r%$%s%9%H!<%k$7$F$"$k>l9g$G$b!"$3$N7g4Y$N1F6A$r

$B!!$"$H!"(BNew vulnerability in quartz.dll Quicktime parsing (Microsoft Security Research & Defense, 2009.05.28) $B$bFI$s$G$*$-$^$7$g$&!#$V$C$A$c$1!"$3$l$,$$$A$P$s$o$+$j$d$9$$$h$&$J5$$,!#(B

There are several workarounds that you may consider here.

#1: Disable Quick Time Parsing in Quartz.dll by deleting the following registry key:

HKEY_CLASSES_ROOT\CLSID\{D51BD5A0-7548-11CF-A520-0080C77EF58A}

This is the best workaround because it's the most surgical. It only disables QuickTime Parsing in DirectShow. DirectShow's other functionality is not affected. This workaround covers all known attack vectors. Therefore, if you are not concerned about QuickTime content playback via DirectShow, this is the workaround we recommend you apply.

$B"#(B 2009.05.29

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (971778) Microsoft DirectShow $B$N@H
(Microsoft, 2009.05.29)

$B!!(BWindows 2000 + DirectX 7.0 $B!A(B 9.0$B!"(BWindows XP / Server 2003 + DirectX 9 $B$G7g4Y!#$3$l$i$K$*$1$k(B QuickTime $B7A<0$N%U%!%$%k$N07$$$K7g4Y$,$"$j!"96N,(B QuickTime $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2009-1537

$B!!4XO"(B: KB 971778$B!"(B Microsoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released (MSRC blog, 2009.05.28)

2009.05.30 $BDI5-(B:

$B!!(BMicrosoft Security Advisory 971778 Vulnerability in Microsoft DirectShow Released (MSRC blog, 2009.05.28) $B$N$3$NItJ,"-$,=EMW$J$N$G0zMQ$7$F$*$-$^$9$M!#(B

Also, we$B!G(Bve verified that it is possible to direct calls to DirectShow specifically, even if Apple$B!G(Bs QuickTime (which is not vulnerable) is installed.

$B!!(BQuickTime $B$r%$%s%9%H!<%k$7$F$"$k>l9g$G$b!"$3$N7g4Y$N1F6A$r

$B!!$"$H!"(BNew vulnerability in quartz.dll Quicktime parsing (Microsoft Security Research & Defense, 2009.05.28) $B$bFI$s$G$*$-$^$7$g$&!#$V$C$A$c$1!"$3$l$,$$$A$P$s$o$+$j$d$9$$$h$&$J5$$,!#(B

There are several workarounds that you may consider here.

#1: Disable Quick Time Parsing in Quartz.dll by deleting the following registry key:

HKEY_CLASSES_ROOT\CLSID\{D51BD5A0-7548-11CF-A520-0080C77EF58A}

This is the best workaround because it's the most surgical. It only disables QuickTime Parsing in DirectShow. DirectShow's other functionality is not affected. This workaround covers all known attack vectors. Therefore, if you are not concerned about QuickTime content playback via DirectShow, this is the workaround we recommend you apply.

$B!!(BKB971778 $B$N(B Microsoft FixIt $B$,e5-$NFbMF$G$9$M!#(B

2009.06.03 $BDI5-(B:

$B!!(BExploit Shield $BBP(B DirectShow ($B%(%U%;%-%e%"%V%m%0(B, 2009.06.02)$B!#(BF-Secure $B@=IJ$N@kEA!#(B

2009.06.23 $BDI5-(B:

$B!!(BWindows XP/Server 2003$B$N@H (ComputerWorld.jp, 2009.06.23)

2009.06.27 $BDI5-(B:

$B!!(BOnline Game Password Stealers Riding with 0-day DirectShow Exploits (Microsoft Malware Protection Center, 2009.06.25)

2009.07.15 $BDI5-(B:

$B!!(BMS09-028 - $B6[5^(B: Microsoft DirectShow $B$N@H (Microsoft, 2009.07.15) $B$G=$@5$5$l$^$7$?!#(B


$B"#(B 2009.05.28


$B"#(B 2009.05.27


$B"#(B 2009.05.26

$B"#(B $BDI5-(B

Inside the Massive Gumblar Attack

$B"#(B Wireshark 1.0.8 Released
(wireshark.org, 2009.05.21)

$B!!(BWireshark 1.0.8 $BEP>l!#(BPCNFSD $B2r@O4o$K(B DoS $B967b$r?)$i$&7g4Y(B (Wireshark 0.8.20 $B!A(B 1.0.7) $B$,=$@5$5$l$F$$$k!#(B

$B"#(B QuickTime$B$KL$%Q%C%A$N@H
(ITmedia, 2009.05.26)

$B!!(B$B%;%-%e%j%F%#%"%C%W%G!<%H(B 2009-002 / Mac OS X v10.5.7 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B (Apple) $B$G=$@5$5$l$?!"(BQuickDraw Manager $B$N7g4Y(B (CVE-2009-0010) $B$K4XO"$7$?7g4Y$,(B QuickTime 7.6 $B$K$bB8:_$9$k$H$$$&OC!#(B

$B!!(Bpatch $B$O$b$A$m$s$^$@$J$$!#(B


$B"#(B 2009.05.25

$B"#(B $BDI5-(B

IIS 6.0 + WebDAV: Unicode $B%P%0$N5U=1(B

$B!!(BIIS admins, help finding WebDAV remotely using nmap (SANS ISC, 2009.05.24)$B!#(B nmap SVN $BHG(B + NSE script $B$r;H$C$?@H


$B"#(B 2009.05.24

$B"#(B $B$$$m$$$m(B (2009.05.24)
(various)

$B"#(B $B%;%-%e%j%F%#4k6H!":G?7HG!V(BMac OS X$B!W$N(BJava$B@HZ%3!<%I$r8x3+(B
(CNET, 2009.05.21)

$B!!$3$N7o(B: Write once, own everyone, Java deserialization issues (cr0 blog, 2009.05.19)$B!#(BSun $B$,H>G/A0$KD>$7$?7g4Y(B CVE-2008-5353 $B$,$$$^$@$KD>$C$F$J$$!"$H$$$&OC!#(B exploit (milw0rm)

$B!!(BApple Slow To Fix Java Flaws (Security Fix, 2009.05.22) $B$,!"(BMac $B$K$*$1$k(B Java $B$N=$@5CY$l>u67$r(B$B$^$H$a$F$$$k(B$B!#(B 6 $B$+7nCY$l$k$H$$$&$N$O!"(BApple $BE*$K$O$=$l$[$I0[>o$G$O$J$$$i$7$$!#(B

$B!!(Bpatch $B$O$^$@$J$$!#(BWeb $B%V%i%&%6$G(B Java $B$rL58z$K$9$l$P2sHr$G$-$k!#(B

2009.06.16 $BDI5-(B:

$B!!=P$^$7$?$h!#(B

$B"#(B $BDI5-(B

IIS 6.0 + WebDAV: Unicode $B%P%0$N5U=1(B


$B"#(B 2009.05.23


$B"#(B 2009.05.22

$B"#(B Inside the Massive Gumblar Attack
(Andrew Martin, 2009.05.20)


$B"#(B 2009.05.21


$B"#(B 2009.05.20

$B"#(B $B$$$m$$$m(B (2009.05.20)
(various)

$B"#(B NSD Vulnerability Announcemen
(NLnet Labs, 2009.05.19)

$B!!(BNSD 2.0.0$B!A(B3.2.1 $B$K7g4Y!#(Bbuffer overflow $B$9$k7g4Y$,$"$j!"96N,%Q%1%C%H$K$h$C$F(B NSD $B$r(B crash $B$G$-$k!#G$0U$N%3!<%I$N

$B!!(BNSD 3.2.2 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B JVNVU#853097 - ntpd autokey $B$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H
(JVN, 2009.05.19)

$B!!(BNTP $B%Q%C%1!<%8(B $B$N(B ntpd $B$K7g4Y!#8x3+80G'>Z$r;HMQ$9$k(B NTP $B%Q%1%C%H$NG'>Z5!G=!"(B NTP Protocol Version 4 Autokey (04 $B$O(B expire $B$5$l$F$^$9$,!"(B$B$3$N%Z!<%8(B$B$K(B 05 $B$,$"$j$^$9(B) $B$NCVE-2009-1252

$B!!7g4Y$,$"$k$N$O(B NTP 4.0.99m / 4.1.70 $B0J9_!#(B NTP 4.2.4p7 / 4.2.5p74 $B$G=$@5$5$l$F$$$k!#(B

$B!!(Bautokey $B5!G=$rL58z$H$9$k$3$H$G2sHr$G$-$k!#L58z$H$9$k$K$O!"(Bntp.conf $B$N(B crypto $B%-!<%o!<%I$G$O$8$^$k9T$rA4$F!"%3%a%s%H%"%&%H$9$k$+:o=|$9$k!#(B JVN $B$d(B VU#853097 $B$K$O(B crypto pw password $B$H$$$&9T$@$1$r:o=|$9$l$P$$$$$H$5$l$F$$$k$,!"(B Security Notice :: Resolved Vulnerabilities :: Remote exploit if autokey is enabled (ntp.org) $B$K$O$=$&$O=q$+$l$F$$$J$$!#(B


$B"#(B 2009.05.19

$B"#(B $BDI5-(B

IIS 6.0 + WebDAV: Unicode $B%P%0$N5U=1(B

$B!!%*%U%#%7%c%k>pJsMh$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (971492) $B%$%s%?!<%M%C%H(B $B%$%s%U%)%a!<%7%g%s(B $B%5!<%S%9$N@H:3J$5$l$k(B (Microsoft, 2009.05.19)$B!#(BCVE-2009-1535

  • $BBP>](B: IIS 5.0 / 5.1 / 6.0$B!#(BIIS 7.0 $B$K$O$3$N7g4Y$O$J$$!#(B

  • $BG'>Z$O2sHr$G$-$k$,!"%"%/%;%98"8B$O!VF?L>%f!<%6!<(B $B%"%+%&%s%H!W$N$^$^!#=>$C$F!"!VF?L>%f!<%6!<(B $B%"%+%&%s%H!W$,%"%/%;%9$G$-$J$$NN0h$O!"$3$N7g4Y$+$i$OJ]8n$5$l$k!#(B

  • WebDAV $B$rL58z$K$9$l$P!"$3$N7g4Y$r2sHr$G$-$k!#(B

  • URLScan $B$r;H$C$F(B WebDAV $B$r%U%#%k%?$9$l$P!"$3$N7g4Y$r2sHr$G$-$k!#(B


$B"#(B 2009.05.18

$B"#(B $B$$$m$$$m(B (2009.05.18)
(various)


$B"#(B 2009.05.17


$B"#(B 2009.05.16

$B"#(B IIS 6.0 + WebDAV: Unicode $B%P%0$N5U=1(B
(various, 2009.05.16)

$B!!(BIIS 6.0 + WebDAV $B$N4D6-$K(B Unicode $B%P%0(B$B$,$"$j!"G'>Z$r2sHr$7$F%3%s%F%s%D$rFI$_=q$-$G$-$F$7$^$&LOMM$G$9!#(B

$B!!(Bpatch $B$O$^$@$"$j$^$;$s!#(B

2009.05.19 $BDI5-(B:

$B!!%*%U%#%7%c%k>pJsMh$^$7$?(B: $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (971492) $B%$%s%?!<%M%C%H(B $B%$%s%U%)%a!<%7%g%s(B $B%5!<%S%9$N@H:3J$5$l$k(B (Microsoft, 2009.05.19)$B!#(BCVE-2009-1535

  • $BBP>](B: IIS 5.0 / 5.1 / 6.0$B!#(BIIS 7.0 $B$K$O$3$N7g4Y$O$J$$!#(B

  • $BG'>Z$O2sHr$G$-$k$,!"%"%/%;%98"8B$O!VF?L>%f!<%6!<(B $B%"%+%&%s%H!W$N$^$^!#=>$C$F!"!VF?L>%f!<%6!<(B $B%"%+%&%s%H!W$,%"%/%;%9$G$-$J$$NN0h$O!"$3$N7g4Y$+$i$OJ]8n$5$l$k!#(B

  • WebDAV $B$rL58z$K$9$l$P!"$3$N7g4Y$r2sHr$G$-$k!#(B

  • URLScan $B$r;H$C$F(B WebDAV $B$r%U%#%k%?$9$l$P!"$3$N7g4Y$r2sHr$G$-$k!#(B

2009.05.24 $BDI5-(B:

$B!!(Bexloit:

2009.05.25 $BDI5-(B:

$B!!(BIIS admins, help finding WebDAV remotely using nmap (SANS ISC, 2009.05.24)$B!#(B nmap SVN $BHG(B + NSE script $B$r;H$C$?@H

2009.05.30 $BDI5-(B:

$B!!(BUnixwiz.net Tech Tip: Understanding Microsoft's KB971492 IIS5/IIS6 WebDAV Vulnerability (Unixwiz.net)$B!#2r@b5-;v!#(B

2009.06.10 $BDI5-(B:

$B!!(BMS09-020 - $B=EMW(B: $B%$%s%?!<%M%C%H(B $B%$%s%U%)%a!<%7%g%s(B $B%5!<%S%9(B (IIS) $B$N@H:3J$5$l$k(B (970483) (Microsoft, 2009.06.10) $B$G=$@5$5$l$^$7$?!#(B


$B"#(B 2009.05.15

$B"#(B $BDI5-(B

$B"#(B $B=EMW$J$*CN$i$;(B - HP Notebook PC$B%P%C%F%j%Q%C%/<+
(HP, 2009.05.14)

$B!!(BHP $B@=$N

  • HP Compaq 6720s Notebook PC
  • HP Pavilion Notebook PC dv2000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv2405$B!J(BP/N: RX692AV$B!K(B
  • HP Pavilion Notebook PC dv2605$B!J(BP/N: RW026AV$B!K(B
  • HP Pavilion Notebook PC dv6000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv6200$B!J(BP/N: RD869AV$B$^$?$O(BRD870AV)
  • HP Pavilion Notebook PC dv6205$B!J(BP/N: RD861AV$B$^$?$O(BRD862AV0$B!K(B
  • HP Pavilion Notebook PC dv6500$B!J(BP/N: RL675AV$B$^$?$O(BRL676AV$B!K(B
  • HP Pavilion Notebook PC dv9000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv9500$B!J(BP/N: RL596AV)
  • HP G7000 Notebook PC
    • HP Pavilion Notebook PC dv6700/ dv9700$B!JF|K\%b%G%k$OBP>]30!K(B
    • HP Pavilion Notebook PC dv2000/ dv2500/ dv2700/ dv6000/ dv9000$B!JF|K\L$H/Gd!K(B
    • HP G6000 Notebook PC$B!JF|K\L$H/Gd!K(B
    • Compaq Presario A900/ C700/ F700 Notebook PC$B!JF|K\L$H/Gd!K(B
    • Compaq Presario V3000/ V3500/ V3700/ V6000/ V6500/ V6700 Notebook PC$B!JF|K\L$H/Gd!K(B

    $B!!(BHP $B@=(B note PC $BMxMQ


    $B"#(B 2009.05.14

    $B"#(B Microsoft 2009 $BG/(B 5 $B7n$N%;%-%e%j%F%#>pJs(B
    (Microsoft, 2009.05.13)

    MS09-017 - $B6[5^(B: Microsoft Office PowerPoint $B$N@H

    $B!!(BPowerPoint 2000 / 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BPowerPoint Viewer 2003 / 2007$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BMicrosoft Works 8.5 / 9.0 $B$K(B 14 $B

    $B!!(BPowerPoint 2000 / 2002 (XP) / 2003 / 2007$B!"(BPowerPoint Viewer 2003 / 2007$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/MQ$N=$@5%W%m%0%i%`$OMQ0U$5$l$F$$$k!#0lJ}!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BMicrosoft Works 8.5 / 9.0 $BMQ$N=$@5%W%m%0%i%`$O:#$@3+H/Cf!#4XO"(B:

    Changelog:

    2009.05.15

    $B!!(B14 $B

    $B!!(BMS09-017: An out-of-the-ordinary PowerPoint security update (Microsoft Security Research & Defense, 2009.05.12) $B$rDI2C!#(B

    $B"#(B Apple $BJ}LL(B
    (Apple, 2009.05.12)

    2009.05.15 $BDI5-(B:

    $B!!(BMac OS X 10.5.7 $BI{:nMQ>pJs(B: Advisory: Sophos Anti-Virus for Mac OS X - email alerts do not work on Mac OS X version 10.5.7 (Sophos, 2009.05.14)


    $B"#(B 2009.05.13

    $B"#(B $BDI5-(B


    $B"#(B 2009.05.12

    $B"#(B $BDI5-(B


    $B"#(B 2009.05.11

    $B"#(B $B$$$m$$$m(B (2009.05.11)
    (various)


    $B"#(B 2009.05.10

    $B"#(B $BDI5-(B

    Microsoft 2009 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

    $B!!(BIE6 + MS09-014 patch + Microsoft Foundation Classes (MFC) $B%Y!<%9$N(B ActiveX $B%3%s%H%m!<%k$GI{:nMQ$,H/@8$9$kLOMM(B: Internet Explorer 6 may crash if you visit a Web site that contains an MFC ActiveX control after you install MS09-014 (Microsoft KB 971131)$B!#$3$l$^$G$OLdBj$J$+$C$?%9%/%j%W%H$,(B crash $B$N860x$K$J$C$F$7$^$&LOMM!#2sHrMQ$N%3!<%INc$,>R2p$5$l$F$$$k!#(B

    $B"#(B $B$$$m$$$m(B (2009.05.10)
    (various)

    APSB09-05: Updates available to address Flash Media Server privilege escalation issue (Adobe, 2009.04.30)

    $B!!(BAdobe Flash Media Streaming Server / Adobe Flash Media Interactive Server 3.0.x / 3.5.x $B$K7g4Y!#(B RPC $B$r;H$C$F!"(Bremote $B$+$i(B server side ActionScript $B%U%!%$%kCf$NG$0U$N%W%m%7!<%8%c$rCVE-2009-1365

    $B!!(BFlash Media Server 3.0.4 / 3.5.2 $B$G=$@5$5$l$F$$$k!#(B

    2009.05.20 $BDI5-(B: $BF|K\8lHG%"%I%P%$%6%j(B: APSB09-05: Flash Media Server$B$N8"8B>:3JLdBj$KBP=h$9$k$?$a$N%"%C%W%G!<%H8x3+(B (Adobe, 2009.05.13)

    SYM09-006: Security Advisories Relating to Symantec Products - Symantec Log Viewer JavaScript Injection Vulnerabilities (Symantec, 2009.04.28)

    $B!!8D?M8~$1(B / $B4k6H8~$1%7%^%s%F%C%/@=IJ$K4^$^$l$k(B Symantec Log Viewer (ccLgView.exe) $B$K(B 2 $B$D$N7g4Y$,$"$j!"(B $B96N,EE;R%a!<%k$r;H$C$F(B Log Viewer $B$KG$0U$N%9%/%j%W%H$rCmF~$G$-$k!#(B $B$3$N7g4Y$O!"(BLog Viewer $B$N(B View Logs - Email Filtering $B%*%W%7%g%s$,M-8z$G$"$k>l9g$KH/8=$9$k!#(B CVE-2009-1428$B!#(B

    $B!!8D?M8~$1@=IJ(B (Norton 360 1.0, NIS 2005$B!A(B2008) $B$N=$@5$O(B LiveUpdate $B$rDL$8$FDs6!:Q!#(B Norton 360 2.0$B!"(BNIS 2009 $B$K$O$3$N7g4Y$O$J$$!#(B

    $B!!4k6H8~$1@=IJ$O!"(BSymantec AntiVirus Corporate Edition 9.0 MR7 / 10.1 MR8 / 10.2 MR2$B!"(BSymantec Endpoint Protection 11.0 MR1$B!"(BSymantec Client Security 2.0 MR7 / 3.1 MR8 $B$G=$@5$5$l$F$$$k!#(B

    SYM09-007: Security Advisories Relating to Symantec Products - Symantec Alert Management System 2 multiple vulnerabilities (Symantec, 2009.04.28)

    $B!!4k6H8~$1%7%^%s%F%C%/@=IJ$K4^$^$l$k(B Alert Management System 2 (AMS2) $B$K(B 4 $B$D$N7g4Y!#(BIntel LANDesk Common Base Agent (CBA)$B!"(BIntel Alert Originator Service (IAO.EXE)$B!"(BIntel File Transfer service (XFR.EXE) $B$K7g4Y$,$"$j!"(Bremote $B$+$i(B local SYSTEM $B8"8B$rC%CVE-2009-1429 CVE-2009-1430 CVE-2009-1431

    $B!!(BSymantec AntiVirus Corporate Edition 9.0 MR7 / 10.1 MR8 / 10.2 MR2$B!"(BSymantec Endpoint Protection 11.0 MR3$B!"(BSymantec Client Security 2.0 MR7 / 3.1 MR8 $B$G=$@5$5$l$F$$$k!#(B

    $B!!4XO"(B: Symantec System Center Alert Management System Console Arbitrary Program Execution Design Error Vulnerability (iDefense, 2009.04.29)

    SYM09-008: Security Advisories Relating to Symantec Products - Symantec Reporting Server Improper URL Handling Exposure (Symantec, 2009.04.28)

    $B!!4k6H8~$1%7%^%s%F%C%/@=IJ$K4^$^$l$k(B Symantec Reporting Server $B$K7g4Y!#(B URL $B$N=hM}$K7g4Y$,$"$j!"(Bphishing $B967b$rCVE-2009-1432

    $B!!(BSymantec AntiVirus Corporate Edition 10.1 MR8 / 10.2 MR2$B!"(B Symantec Endpoint Protection 11.0 MR2$B!"(B Symantec Client Security 3.1 MR8 $B$G=$@5$5$l$F$$$k!#(B


    $B"#(B 2009.05.09


    $B"#(B 2009.05.08

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2009 $BG/(B 5 $B7n(B
    (Microsoft, 2009.05.08)


    $B"#(B 2009.05.07

    $B"#(B $B$$$m$$$m(B (2009.05.07)
    (various)

    $B"#(B $BDI5-(B

    $B!V9qN)46@w>I8&5f=j!W$r:>>N$7$?%V%?%$%s%U%k%(%s%64XO"%a!<%k$K$4Cm0U$/$@$5$$(B

    $B!!(BSwine Flu Spam Attempt to Infect Japanese Users (trendmicro blog, 2009.05.03) $B$K$h$k$H!"%H%l%s%I%^%$%/%m$G$O(B TROJ_PIDIEF.UA $B$*$h$S(B TROJ_PIDIEF.TY $B$H$7$F8!=P$9$k$=$&$G!#(B

    $B!!$C$F!D!D!#(B$B%5%$%P!<6u4V$K$*$1$kFZ%$%s%U%k%(%s%6A{F0$N1F6A(B ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2009.04.30) $B$@$H%K%e%"%s%9$,0[$J$k$>!#(BSwine Flu Spam Attempt to Infect Japanese Users (trendmicro blog, 2009.05.03) $B$G$O(B

    Spammed messages with the subject Warning of Swine Flu claiming to be from the National Institute of Infectious Diseases, encourages users to open an attached .ZIP file, to $B!H(Blearn$B!I(B more about the pandemic (detection available as TROJ_PIDIEF.UA and TROJ_PIDIEF.TY). Our engineers have verified that TROJ_PIDIEF.TY drops and executes BKDR_KUPS.G.

    $B$H$"$k$N$G!"(Bzip $B$NCf?H$,(B TROJ_PIDIEF.UA $B$*$h$S(B TROJ_PIDIEF.TY $B$G$"$k$h$&$KFI$a$k$N$@$,!"(B$B%5%$%P!<6u4V$K$*$1$kFZ%$%s%U%k%(%s%6A{F0$N1F6A(B ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2009.04.30) $B$G$O(B

    $B!!$3$&$7$?;vNc$OB>$+$i$b4s$;$i$l$F$$$^$9!#B>$N;vNc$G$O!V(B.ZIP$B!W%U%!%$%k$N$_$J$i$:!"!V(B.PDF$B!W!J!V(BTROJ_PIDIEF.TY$B!W!"!V(BTROJ_PIDIEF.UA$B!WEy!K(B/$B!V(B.DOC$B!W$J$I$NJ8=q%U%!%$%k$rAu$C$?%&%$%k%9$b$7$/$O!"J8=q:n@.%=%U%H%&%'%"$N@HW$-967b$r9T$&%&%$%k%9$NB8:_$r3NG'$7$F$$$^$9!#(B

    TROJ_PIDIEF.UA $B$d(B TROJ_PIDIEF.TY $B$O$"$/$^$G!VB>$N;vNc!W$G$"$j!"Ev3:(B zip $B$NCf?H$,2?$J$N$+$OA4$/ITL@$@!#(B

    bid 34736: Adobe Reader 'getAnnots()' Javascript Function Remote Code Execution Vulnerability

    $B!!(BAdobe Reader Issue Update (Adobe Product Security Incident Response Team (PSIRT), 2009.05.01)$B!#=$@5HG$O(B 2009.05.12 ($BB?J,JF9q;~4V(B) $B$K8x3+$5$l$k$=$&$G!#(BWindows $BHG$N(B Adobe Reader / Acrobat 7.x / 8.x / 9.x$B!"(B Mac OS X $BHG$N(B Adobe Reader / Acrobat 8.x / 9.x$B!"(B Unix $BHG$N(B Adobe Reader 8.x / 9.x $B$,MQ0U$5$l$k!#(B

    $B"#(B PDF most common file type in targeted attacks
    (F-Secure blog, 2009.05.06)

    $B!!$b$O$d(B Microsoft Office $BJ8=q$r;H$C$?;vNc$H(B PDF $B$r;H$C$?;vNc$OYI93$7$F$$$k$=$&$G!#(B


    $B"#(B 2009.05.06

    $B"#(B $BDI5-(B

    $BJ#?t$N%"%s%A%&%$%k%9%=%U%H$K$*$1$k%"!<%+%$%V%U%!%$%k$N07$$$K4X$9$k7g4Y(B

    $B!!B?J,4XO"(B:

    • $B%;%-%e%j%F%#4+9p(B FSC-2009-1 (F-Secure, 2009.05.06)$B!#(BF-Secure $B%"%s%A%&%#%k%9(B Linux$B%2!<%H%&%'%$$K4X$7$F!"=$@5HG(B 3.02 $B$,MQ0U$5$l$F$$$k!#(B2.x $B$K$D$$$F$O!"(B3.02 $B$X$N%"%C%W%0%l!<%I$r9T$&$+!"$"$k$$$O%[%C%H%U%#%C%/%9(B libfm.3.10.15160.tar.gz $B$rE,MQ$9$k!#(B


    $B"#(B 2009.05.05


    $B"#(B 2009.05.03


    $B"#(B 2009.05.02


    $B"#(B 2009.05.01


    [$B%;%-%e%j%F%#%[!<%k(B memo]
    $B;d$K$D$$$F(B