$B%;%-%e%j%F%#%[!<%k(B memo - 2010.04

Last modified: Tue Aug 24 15:11:39 2010 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2010.04.30

$B"#(B $BDI5-(B

$B%1!<%?%$G>$,Bg

$B!!4XO"(B:

Authorization Bypass When Executing An Embedded Executable.

$B!!(B/Launch /Action $B$r;H$C$?967b(B PDF $B%U%!%$%k$,9-$/=P2s$C$F$$$k$h$&$G$9!#(B


$B"#(B 2010.04.29


$B"#(B 2010.04.28

$B"#(B $B$$$m$$$m(B (2010.04.28)
(various)

2010.05.02 $BDI5-(B:

$B!!(BOpera 10.53 $B=P$^$7$?(B: 10.53 released (Opera Desktop Team, 2010.04.30)$B!#(B SA39590: Opera Content Writing Uninitialised Memory Vulnerability (secunia, 2010.04.27) $B$N7o$,=$@5$5$l$F$$$^$9!#(B

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B%1!<%?%$G>$,Bg

$B"#(B $B$$$o$f$k(B Gumblar $B%&%$%k%9$K$h$C$F%@%&%s%m!<%I$5$l$k(B DDoS $B967b$r9T$&%^%k%&%(%"$K4X$9$kCm0U4-5/(B
(JPCERT/CC, 2010.04.28)

$B!!$@$=$&$G$9!#(B

$B"#(B Google Chrome Stable Update: Bug and Security Fixes
(Google Chrome Release, 2010.04.27)

$B!!(BGoogle Chrome 4.1.249.1064 $BEP>l!#(B3 $B7o$N%;%-%e%j%F%#=$@5$,4^$^$l$F$$$^$9!#(B $B$$$:$l$b(B High $B$G!"(B $1000 x 1$B!"(B$500 x 1 $B$,4^$^$l$^$9!#(B


$B"#(B 2010.04.27

$B"#(B Opera 10.52 for Mac and Windows is released
(Opera, 2010.04.27)

$B!!(BOpera 10.52 $BEP>l!#(BWindows $BHG(B $B$O0BDj@-$N6/2=$N$_$@$,!"(BMac $BHG(B$B$O(B 10.10 $B0JMh$N@5<0HG$J$N$G!"$=$l$^$G$N%;%-%e%j%F%#=$@5$r4^$s$G$$$k!#(B

$B!!(BUNIX / Linux $BHG$O$^$@$_$?$$!#(Bsnapshot 6325 $B$,:G?7$+$J!#(B

$B"#(B $BDI5-(B

$B%^%+%U%#!<(B DAT5958 $B$G(B C:\WINDOWS\system32\svchost.exe $B$r(B w32/wecorl.a $B$H$7$F8m8!=P(B

Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B


$B"#(B 2010.04.26


$B"#(B 2010.04.25

$B"#(B $BDI5-(B

$B%^%+%U%#!<(B DAT5958 $B$G(B C:\WINDOWS\system32\svchost.exe $B$r(B w32/wecorl.a $B$H$7$F8m8!=P(B

$B!!4XO"(B:

  • DAT5958$B$G$N8m8!CN$K4X$9$k(BCEO$B$+$i$N%a%C%;!<%8(B ($B%^%+%U%#!<(B, 2010.04.24)

    $B$=$7$FI|5l$,40N;$7$?8e$K$O!"$b$&0l$D=EMW$J$3$H$H$7$F$7!"$3$N$h$&$J$3$H$,FsEY$H5/$-$J$$$h$&$K$9$k$3$H$G$9!#=EMW$J%7%9%F%`%U%!%$%k$K1F6A$rM?$($k$h$&$J%j%j!<%9$K4X$7$F$O!"(BQA$B%W%m%;%9$rDI2C$9$k$h$&!"2~A1$7$F$^$$$j$^$9!#!!$5$i$K(BArtemis$B$K4X$7$F!"=EMW$J%7%9%F%`%U%!%$%k$H$=$l$K4XO"$9$k0E9f2=$5$l$?%O%C%7%e$K4X$9$k3HD%$5$l$?%[%o%$%H%j%9%H$r;HMQ$9$k$3$H$K$h$C$F!"8m8!CN$rKI$05!G=$rDI2C$9$k=`Hw$r$7$F$$$^$9!#(B

    $B8m8!=P$N860x$O(B Artemis $B$@$C$?$C$F$3$H(B?! $B$G$b(B Artemis $B$K4X$9$k5-=R$O!"1QJ8$K$O$J$$$h(B?!

    $B!D!D$H;W$C$?$i!"(BOpen Letter to McAfee Customers (McAfee Security Insights Blog, 2010.04.23) $B$K$O$"$C$?!#(B

    As that effort comes to a conclusion, our next and equally important priority is to review our processes to make sure this never happens again. We are implementing additional QA protocols for any releases that directly impact critical system files. We are also rolling out additional capabilities in Artemis that will provide another level of protection against false positives by leveraging an expansive whitelist of critical system files and their associated cryptographic hashes.

    5400 $B%(%s%8%s<+?H$K$O%[%o%$%H%j%9%H5!G=$,$"$k(B$B$o$1$G$9$,!"(B Artemis $B$K$b%[%o%$%H%j%9%H5!G=$rDI2C$9$k!D!D$H$J$k$H!"(B Artemis $B$O(B 5400 $B%(%s%8%s$N5!G=$h$j$bA0$GF0$$$A$c$&$C$F$3$H$G$9$+$M!#(B

  • Malware Authors Taking Advantage of McAfee False Positive (Symantec, 2010.04.22)


$B"#(B 2010.04.23

$B"#(B $BDI5-(B

Operation $B!H(BAurora$B!I(B Hit Google, Others

$B!!(BNY Times $B$N5-;v$,OCBj$H$J$C$F$$$k$h$&$G!#(B

$B!!Cf9q$N(B Google $B=>6H0w$N(B PC $B$r!"(BMS Messenger $B7PM3$Gf+%5%$%H$KM6F3$7$F96N,$7!"$=$3$+$i(B Google $BK\Z%7%9%F%`(B Gaia $B$N%3!<%I$b4^$^$l$F$$$?!"$H$$$&OC$_$?$$!#(B

$B%^%+%U%#!<(B DAT5958 $B$G(B C:\WINDOWS\system32\svchost.exe $B$r(B w32/wecorl.a $B$H$7$F8m8!=P(B

$B!!(B $B%"%s%A%&%$%k%9$N8m8!CN$,56%"%s%A%&%$%k%9$rG[I[$9$k$?$a$K;H$o$l$k$H$$$&HiFy(B (Panda Security Japan $B%*%U%#%7%c%k%V%m%0(B, 2010.04.23)


$B"#(B 2010.04.22

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B"#(B $B%^%+%U%#!<(B DAT5958 $B$G(B C:\WINDOWS\system32\svchost.exe $B$r(B w32/wecorl.a $B$H$7$F8m8!=P(B
(McAfee, 2010.04.22)

$B!!%^%+%U%#!<(B DAT5958 $B$G(B C:\WINDOWS\system32\svchost.exe $B$r(B w32/wecorl.a $B$H$7$F8m8!=P$7$?LOMM!#(B

$B!!F|K\8lHG=P$F$?(B:

2010.04.23 $BDI5-(B:

$B!!(B $B%"%s%A%&%$%k%9$N8m8!CN$,56%"%s%A%&%$%k%9$rG[I[$9$k$?$a$K;H$o$l$k$H$$$&HiFy(B (Panda Security Japan $B%*%U%#%7%c%k%V%m%0(B, 2010.04.23)

2010.04.25 $BDI5-(B:

$B!!4XO"(B:

2010.04.27 $BDI5-(B:

$B!!(BMcAfee$B!"(BWindows XP$BGK2uLdBj$G2HDm!?%[!<%`%*%U%#%9%f!<%6!<$NI|5lHqMQ$rJd=~(B ($BF|7P(B IT Pro, 2010.04.27)

2010.04.28 $BDI5-(B:

$B!!(BMoving to Help Customers (McAfee Security Insights Blog, 2010.04.27)


$B"#(B 2010.04.21

$B"#(B Google Chrome Stable Update: Security Fixes
(Google, 2010.04.20)

$B!!(BGoogle Chrome 4.1.249.1059 $BEP>l!#(B2 $B$D$N(B $500 $B5i7g4Y$r4^$`!"J#?t$N7g4Y(B (High x 4$B!"(BMedium x 3) $B$,=$@5$5$l$F$$$k!#(B

$B"#(B $B<+F05/F0$rL58z$K$7$F$bKI$2$J$$(BUSB$B967b!"$[$H$s$I$N(BOS$B$,3:Ev(B
($B%^%$%3%_%8%c!<%J%k(B, 2010.04.20)

$B!!!V(BUSB $B@\B3$N%-!<%\!<%I!W$H$7$FF0:n$9$k$3$H$G!"?t!9$NKIJI$rFMGK$9$k!#(B $B$&$^$$$3$H9M$($k$J$"!#(B


$B"#(B 2010.04.20

$B"#(B $BDI5-(B

$B!V4JC1%m%0%$%s!W5!G=$N@H

$B"#(B $B$$$m$$$m(B (2010.04.20)
(various)


$B"#(B 2010.04.19

$B"#(B $B$$$m$$$m(B (2010.04.19)
(various)

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

MS10-019 - $B6[5^(B: Windows $B$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B Windows Authenticode $B$K(B 2 $B7o$N7g4Y!#(B

  • $B!V(BWinVerifyTrust Signature Verification $B$N@HCVE-2010-0486

    $B4{B8$N(B Authenticode $B=pL>:Q$_%U%!%$%k$r2~JQ$7!"%(%i!<$,H/@8$7$J$$$^$^!"96N,%3!<%I$rKd$a9~$`$3$H$,$G$-$k!#(B

    $B$3$N@H$*$h$S8!>Z$r9T$&>l9g$K!"%U%!%$%k(B $B%@%$%8%'%9%H$N%U%#!<%k%I$r>JN,$9$k:]$K5/$3$j$^$9!#(B

    Exploitability Index: 2

  • $B!V(BCabview $B$NGKB;$N8!>Z$N@HCVE-2010-0487

    $B4{B8$N(B Authenticode $B=pL>:Q$_(B .cab $B%U%!%$%k$r2~JQ$7!"(B $B=pL>$NHs8!>ZItJ,$,96N,%3!<%I$K%j%s%/$5$l$k$h$&$K$9$k$H!"(B $B96N,(B .cab $B%U%!%$%k$r3+$$$?;~E@$G%I%+%s!#(B

    Exploitability Index: 2

MS10-020 - $B6[5^(B: SMB $B%/%i%$%"%s%H$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B SMB $B%/%i%$%"%s%H

$B!!4XO"(B: MS10-020: SMB Client Update (Microsoft Security Research & Defense, 2010.04.12)

MS10-021 - $B=EMW(B: Windows $B%+!<%M%k$N@H:3J$5$l$k(B (979683)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B Windows $B%+!<%M%k$K(B 8 $B7o$N7g4Y!#(B

  • Windows $B%+!<%M%k$N(B Null $B%]%$%s%?!<$N@HCVE-2010-0234

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$N%7%s%\%j%C%/(B $B%j%s%/CM$N@HCVE-2010-0235

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$N%a%b%j3d$jEv$F$N@HCVE-2010-0236

    Exploitability Index: 1

  • Windows $B%+!<%M%k(B $B$N%7%s%\%j%C%/(B $B%j%s%/:n@.$N@HCVE-2010-0237

    Exploitability Index: 1

  • Windows $B%+!<%M%k(B $B$N%l%8%9%H%j(B $B%-!<$N@HCVE-2010-0238

    Exploitability Index: N/A

  • Windows $B$N2>A[%Q%92r@O$N@HCVE-2010-0481

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$NIT@5$J7A<0$N2hA|$N@HCVE-2010-0482

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$NNc30%O%s%I%i!<$N@HCVE-2010-0810

    Exploitability Index: N/A

$B!!4XO"(B: Registry vulnerabilities addressed by MS10-021 (Microsoft Security Research & Defense, 2010.04.12)

MS10-022 - $B=EMW(B: VBScript $B%9%/%j%W%H(B $B%(%s%8%s$N@H

MS10-023 - $B=EMW(B: Microsoft Office Publisher $B$N@H

MS10-024 - $B=EMW(B: Microsoft Exchange $B$*$h$S(B Windows SMTP $B%5!<%S%9$N@H

MS10-025 - $B6[5^(B: Microsoft Windows Media Services $B$N@H

MS10-026 - $B6[5^(B: MPEG Layer-3 $B%3!<%G%C%/$N@H

MS10-027 - $B6[5^(B: Windows Media Player $B$N@H

MS10-028 - $B=EMW(B: Microsoft Visio $B$N@H

$B!!(BVisio 2002 / 2003 / 2007 $B$K(B 2 $B$D$N7g4Y!#(B

MS10-029 - $B7Y9p(B: Windows ISATAP $B%3%s%]!<%M%s%H$N@H

$B!!4XO"(B: 2010$BG/(B4$B7n(B14$BF|$N%;%-%e%j%F%#>pJs(B ($B7nNc(B) ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.04.14)


$B"#(B 2010.04.18

$B"#(B $B$$$m$$$m(B (2010.04.18)
(various)

$B"#(B $B%1!<%?%$G>$,Bg
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2010.04.17)

$B!!$3$NHa;4$J

2010.04.28 $BDI5-(B:

$B!!4XO"(B:

2010.04.30 $BDI5-(B:

$B!!4XO"(B:

$B"#(B $BDI5-(B

JAVA Web Start $B$K(B 0-day $B7g4Y!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$r

Authorization Bypass When Executing An Embedded Executable.

$B!!$+$$$H$5$s$K$h$k(B Windows / Linux $BMQ$N(B PDF $B%S%e!<%"$G$N(B /Launch /Action $B$N%5%]!<%H>u67$N$^$H$a$,8x3+$5$l$F$$$^$9(B ($B$+$$$H$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)$B!#(B


$B"#(B 2010.04.17


$B"#(B 2010.04.16

$B"#(B $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-003 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B
(Apple, 2010.04.15)

$B!!(BMac OS X 10.5.x / 10.6.x $B$K7g4Y!#(BApple Type Services $B$K$*$1$kKd$a9~$_%U%)%s%H$N=hM}$K7g4Y$,$"$j!"96N,J8=q%U%!%$%k$K$h$C$FG$0U$N%3!<%I$,CanSecWest Pwn2Own $B%O%C%-%s%0%3%s%F%9%H(B $B$G(B Safari $B$,%d%i$l$?7o$N=$@5!#(B CVE-2010-1120

$B"#(B $B!V4JC1%m%0%$%s!W5!G=$N@H
($B%5%$%\%&%:(B, 2010.04.15)

$B!!(B$B%5%$%\%&%:(BOffice$B$b:|$rEj$2$?!V4JC1%m%0%$%s!W(B ($B9bLZ9@8w!w<+Bp$NF|5-(B, 2010.04.15) $B$N7o!#(B

2010.04.20 $BDI5-(B:

$B!!(BJVN#87730223 - $BJ#?t$N%5%$%\%&%:@=IJ$K$*$1$k%"%/%;%9@)8B$K4X$9$k@H (JVN, 2010.04.20)

$B"#(B $BDI5-(B

CanSecWest Pwn2Own $B%O%C%-%s%0%3%s%F%9%H(B

$B!!(BSafari $B$,%d%i$l$?7o!"(B $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-003 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B (Apple, 2010.04.15) $B$G=$@5$5$l$^$7$?!#(B

JAVA Web Start $B$K(B 0-day $B7g4Y!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$r


$B"#(B 2010.04.15

$B"#(B $BDI5-(B

[JS10001] $B0lB@O:$N@H


$B"#(B 2010.04.14

$B"#(B Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2010.04.14)

$B!!M=Dj$I$*$j=P$^$7$?!#(B

2010.04.19 $BDI5-(B:

MS10-019 - $B6[5^(B: Windows $B$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B Windows Authenticode $B$K(B 2 $B7o$N7g4Y!#(B

  • $B!V(BWinVerifyTrust Signature Verification $B$N@HCVE-2010-0486

    $B4{B8$N(B Authenticode $B=pL>:Q$_%U%!%$%k$r2~JQ$7!"%(%i!<$,H/@8$7$J$$$^$^!"96N,%3!<%I$rKd$a9~$`$3$H$,$G$-$k!#(B

    $B$3$N@H$*$h$S8!>Z$r9T$&>l9g$K!"%U%!%$%k(B $B%@%$%8%'%9%H$N%U%#!<%k%I$r>JN,$9$k:]$K5/$3$j$^$9!#(B

    Exploitability Index: 2

  • $B!V(BCabview $B$NGKB;$N8!>Z$N@HCVE-2010-0487

    $B4{B8$N(B Authenticode $B=pL>:Q$_(B .cab $B%U%!%$%k$r2~JQ$7!"(B $B=pL>$NHs8!>ZItJ,$,96N,%3!<%I$K%j%s%/$5$l$k$h$&$K$9$k$H!"(B $B96N,(B .cab $B%U%!%$%k$r3+$$$?;~E@$G%I%+%s!#(B

    Exploitability Index: 2

MS10-020 - $B6[5^(B: SMB $B%/%i%$%"%s%H$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B SMB $B%/%i%$%"%s%H

$B!!4XO"(B: MS10-020: SMB Client Update (Microsoft Security Research & Defense, 2010.04.12)

MS10-021 - $B=EMW(B: Windows $B%+!<%M%k$N@H:3J$5$l$k(B (979683)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N(B Windows $B%+!<%M%k$K(B 8 $B7o$N7g4Y!#(B

  • Windows $B%+!<%M%k$N(B Null $B%]%$%s%?!<$N@HCVE-2010-0234

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$N%7%s%\%j%C%/(B $B%j%s%/CM$N@HCVE-2010-0235

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$N%a%b%j3d$jEv$F$N@HCVE-2010-0236

    Exploitability Index: 1

  • Windows $B%+!<%M%k(B $B$N%7%s%\%j%C%/(B $B%j%s%/:n@.$N@HCVE-2010-0237

    Exploitability Index: 1

  • Windows $B%+!<%M%k(B $B$N%l%8%9%H%j(B $B%-!<$N@HCVE-2010-0238

    Exploitability Index: N/A

  • Windows $B$N2>A[%Q%92r@O$N@HCVE-2010-0481

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$NIT@5$J7A<0$N2hA|$N@HCVE-2010-0482

    Exploitability Index: N/A

  • Windows $B%+!<%M%k$NNc30%O%s%I%i!<$N@HCVE-2010-0810

    Exploitability Index: N/A

$B!!4XO"(B: Registry vulnerabilities addressed by MS10-021 (Microsoft Security Research & Defense, 2010.04.12)

MS10-022 - $B=EMW(B: VBScript $B%9%/%j%W%H(B $B%(%s%8%s$N@H

MS10-023 - $B=EMW(B: Microsoft Office Publisher $B$N@H

MS10-024 - $B=EMW(B: Microsoft Exchange $B$*$h$S(B Windows SMTP $B%5!<%S%9$N@H

MS10-025 - $B6[5^(B: Microsoft Windows Media Services $B$N@H

MS10-026 - $B6[5^(B: MPEG Layer-3 $B%3!<%G%C%/$N@H

MS10-027 - $B6[5^(B: Windows Media Player $B$N@H

MS10-028 - $B=EMW(B: Microsoft Visio $B$N@H

$B!!(BVisio 2002 / 2003 / 2007 $B$K(B 2 $B$D$N7g4Y!#(B

MS10-029 - $B7Y9p(B: Windows ISATAP $B%3%s%]!<%M%s%H$N@H

$B!!4XO"(B: 2010$BG/(B4$B7n(B14$BF|$N%;%-%e%j%F%#>pJs(B ($B7nNc(B) ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.04.14)

2010.04.22 $BDI5-(B:

$B!!(BMS10-025 - $B6[5^(B: Microsoft Windows Media Services $B$N@H $B$N(B patch $B$,0z$C9~$a$i$l$^$7$?!#7g4Y$,$-$A$s$H=$@5$5$l$F$$$J$+$C$?LOMM$G$9!#2~D{HG$r=`HwCf!#(B

2010.04.27 $BDI5-(B:

$B!!(BMS10-025 - $B6[5^(B: Microsoft Windows Media Services $B$N@H $B$N(B patch$B!"L@F|:F%j%j!<%9M=Dj$@$=$&$G$9!#(B

2010.04.28 $BDI5-(B:

$B!!(BMS10-025 - $B6[5^(B: Microsoft Windows Media Services $B$N@H $B$N(B patch$B!":F%j%j!<%9$5$l$^$7$?!#(B

2010.05.29 $BDI5-(B:

$B!!(BMS10-020 patch $B$rE,MQ$9$k$H!"(BSMB 1.0 $B%Y!<%9$N%j%b!<%H%5!<%P(B ($BNc(B: Windows NT 4.0$B!"(BCisco WAAS$B!"(BNetApp DataOnTap) $B$H$N4V$G!"J8=q$NJ]B8$d%Q!<%_%C%7%g%s$NJQ99$,$G$-$J$/$J$k>l9g$,$"$k$=$&$G!#(B Cisco WAAS (Samba $B%Y!<%9$N

$B"#(B $B%f%K!<%/(BID$B$,$"$l$PG'>Z$,$G$-$k$H$$$&88A[(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2010.04.11)

$B!!$3$l$O$9$5$^$8$$$J$"!D!D!#4XO"(B:

$B"#(B Oracle Critical Patch Update Advisory - April 2010
(Oracle, 2010.04.13)

$B!!Nc$K$h$C$F$F$s$3$b$j$G$9!#(B

$B!!(BSun $B$NJ,(B: Sun security fixes included in the Oracle Critical Patch Update for April 2010 (Sun, 4/13)

$B"#(B $BDI5-(B

APSB10-09: Security Advisory for Adobe Reader and Acrobat

Opera$B%V%i%&%6$K?<9o$J@H

$B!!4XO"(B:

$B!!(BOpera 10.51 $B$G=$@5$5$l$?$=$&$G$9!#(BMac / Linux $BHG$O$^$@&B%F%9%HCf$N$h$&$G!#(B


$B"#(B 2010.04.13

$B"#(B $BDI5-(B

[JS10001] $B0lB@O:$N@H

$B"#(B CERT-FI Advisory on Antivirus Signature Evasion Using Archive Files
(CERT-FI, 2010.04.12)

$B!!J#?t$N%"%s%A%&%$%k%9@=IJ$K7g4Y!#%"!<%+%$%V%U%!%$%k$N

$B!!4XO"(B: JVNVU#545953 - $BJ#?t$N%"%s%A%&%#%k%9@=IJ$K@H (JVN, 2010.04.13)

$B"#(B Enterprise Administration of the Acrobat Family of Products
(Adobe, 2010.04.11 $B99?7(B)

$B!!(BAcrobat-Reader Updater: A configuration and user guide. For the Acrobat Product Family 9.2 and 8.1.7 and later $B$,2C$o$C$?B>!"B>$NJ8=q$b2~D{$5$l$F$$$kLOMM$G$9!#(B


$B"#(B 2010.04.12

$B"#(B [JS10001] $B0lB@O:$N@H
($B%8%c%9%H%7%9%F%`(B, 2010.04.12)

$B!!>/$J$/$H$b!"0lB@O:(B 2006$B!A(B2010 $B$K7g4Y!#%U%)%s%H>pJs$N=hM}$K7g4Y$,$"$j!"96N,J8=q%U%!%$%k$r3+$/$HG$0U$N%3!<%I$,

$B!!8=;~E@$G$O!"0lB@O:(B 2009 / 2010 $BMQ$N%"%C%W%G!<%H%b%8%e!<%k$,8x3+$5$l$F$$$k!#(B $B0lB@O:(B 2006$B!A(B2008 $BMQ$N%"%C%W%G!<%H%b%8%e!<%k$K$D$$$F$O=`HwCf!#B>$N%W%m%0%i%`$N0BA4@-$K$D$$$F$OD4::Cf!#(B

$B!!!V(B2010$BG/(B 4$B7n(B 7$BF|!"J@

2010.04.13 $BDI5-(B:

$B!!4XO"(B:

2010.04.15 $BDI5-(B:

$B!!0lB@O:(B 2006$B!A(B2008 $BMQ$N%"%C%W%G!<%H%b%8%e!<%k$,(B$B8x3+$5$l$^$7$?(B$B!#(B $B$^$?!"0lB@O:(B2010 $BBN83HG$K$D$$$F$b?7HG$,(B$B8x3+$5$l$F$$$^$9(B$B!#(B


$B"#(B 2010.04.11

$B"#(B JAVA Web Start $B$K(B 0-day $B7g4Y!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$r
(various, 2010.04.09)

$B!!(BJava 6 Update 10 $B0J9_$N(B Windows / Linux $BHG$,BP>]$NLOMM!#$3$N$X$s(B:

$B!!(Bjavaws / javaws.exe $B$rL58z2=$9$k$3$H$G2sHr$G$-$kLOMM!#(B

2010.04.16 $BDI5-(B:

$B!!pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!$3$N7g4Y$r=$@5$7$?(B JDK / JRE 6 Update 20 $B$,(B$B8x3+$5$l$^$7$?(B$B!#(B Oracle Security Alert CVE-2010-0886 (Oracle, 2010.04.15) $B$r;2>H!#(B

$B!!4XO"(B:

2010.04.18 $BDI5-(B:

$B!!4XO"(B:

$B"#(B [Security-announce] VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
(VMware, 2010.04.09)

$B!!(BVMware Workstation / Player / ACE / Server / Fusion / VIX API / ESX / ESXi $B$K1F6A$9$k7g4Y!#(B

  1. Windows-based VMware Tools Unsafe Library Loading vulnerability

  2. Windows-based VMware Tools Arbitrary Code Execution vulnerability

  3. Windows-based VMware Workstation and Player host privilege escalation

  4. Third party library update for libpng to version 1.2.37

  5. VMware VMnc Codec heap overflow vulnerabilities

  6. VMware Remote Console format string vulnerability

  7. Windows-based VMware authd remote denial of service

  8. Potential information leak via hosted networking stack

  9. Linux-based vmrun format string vulnerability

$B!!(BWindows-based $B$H=q$+$l$F$$$k$+$i$H8@$C$F!"(BWindows $BHG$@$1$K1F6A$9$k$H$O8B$i$J$$$N$GCm0U!#(B

$B!!(BWorkstation 7.0.1 / 6.5.4 $B$J$I!"3F@=IJ$N:G?7HG!"$"$k$$$O(B patch $B$GBP1~$5$l$k!#(B


$B"#(B 2010.04.10


$B"#(B 2010.04.09

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2010 $BG/(B 4 $B7n(B
(Microsoft, 2010.04.09)

$B!!:#2s$O(B 11 $B8D!#(BOffice $B$d(B Exchange $B$b4^$^$l$^$9!#(BExchange $B$C$F!"$R$5$7$V$j$K8+$?5$$,!#(B

$B!!4XO"(B: 2010$BG/(B4$B7n(B14$BF|$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($B7nNc(B) ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.04.09)

$B$^$?!"%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B 977544 (SMB) , $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B 981169 (VBScript) $B$N7o$K$D$$$F:#7nDs6!$9$k%;%-%e%j%F%#99?7%W%m%0%i%`$G$NBP=h$rM=Dj$7$F$$$^$9!#(B

$B"#(B APSB10-09: Security Advisory for Adobe Reader and Acrobat
(Adobe, 2010.04.08)

$B!!(BAdobe $B$+$iM=9p=P$^$7$?!#(B2010.04.13 (US $B;~4V(B) $B$K(B Adobe Reader / Acrobat 9.3.2 / 8.2.2 $B$,=P$k$=$&$G$9!#(B critical updates $B$HH=Dj$5$l$F$$$^$9!#(B

$B!!4XO"(B: Upcoming Adobe Reader and Acrobat 9.3.2 and 8.2.2 to be Delivered by New Updater (Adobe Reader Blog, 2010.04.08)

On Tuesday, April 13, 2010, as part of our quarterly update, we will activate the new updater for all users needing Adobe Reader and Acrobat 9.3.2 and 8.2.2 for Windows and Macintosh. As of yesterday, April 7, 2010, we have been activating our new updater for those users who are not yet up-to-date with our latest versions. During this phase of the process, we are utilizing users' current update setting found in the Adobe Reader and Acrobat Preferences, under the "Updater" panel, as shown in the screen captures below.

$B!!$U$`$s!#(B

$B!!!V<+F0E*$K%"%C%W%G!<%H$r%$%s%9%H!<%k$9$k!W$K$7$F$*$/$H!"$&$l$7$$$3$H$,$"$k$N$+$J!#@_Dj$9$k$H(B HKLM\SOFTWARE\Adobe\Adobe ARM\1.0\ARM\iCheck $B$,(B 3 $B$K$J$k$_$?$$!#(B

$B!!4XO"(B: $B%"%I%S!"?7$?$J<+F0%"%C%W%G!<%H%7%9%F%`$r%m!<%s%A$X(B--13$BF|$N%;%-%e%j%F%#%"%C%W%G!<%H$G(B (CNET, 2010.04.09)

2010.04.14 $BDI5-(B:

$B!!(BAdobe Reader / Acrobat 9.3.2 / 8.2.2 $B=P$^$7$?(B:

2010.04.23 $BDI5-(B:

$B!!F|K\8lHG(B: APSB10-09: Adobe Reader$B$*$h$S(BAcrobat$BMQ%;%-%e%j%F%#%"%C%W%G!<%H8x3+(B (Adobe)

$B"#(B 4/22 $B$"$N:c;R@h@8$,5"$C$F$/$k(B?!
(Microsoft, 2010.04.09)

$B!!$J!"$J$s$@$C$F!

2010.04.12 $BDI5-(B:

$B!!(B$B%5%$%H$,99?7$5$l$^$7$?(B$B!D!D$,!"(B

$B!!8+$l$J$$!#$7$/$7$/!#$I$&$d$i!"@b(B3$B$N%j%"%k:c;R@h@8$N$h$&$J$N$@$,!#(B

$B!!!D!D(BCell_$B?}(B $B$J$s$F$b$N$,$"$k$N$G$9$M!#!V:c;R@h@8$H%H%-%a%-!y%b!<%I!W$C$F!D!D!#$H$$$&$+!"$3$NJ}!"(BMicrosoft MVP $B$@!D!D!#(B $B4XO"(B: Excel$B$N%^%/%m$GF0$/0[?'Kc?}%2!<%`(B---$B!V(BCell_$B?}!W(B Excel$B$N%^%/%m$GF0$/0[?'Kc?}%2!<%`(B ($BF|7P(B PC Online, 2009.03.27)$B!#(B

2010.04.16 $BDI5-(B:

$B!!(B$B%S%G%*99?7$5$l$^$7$?!#$=$7$F:c;R@h@8$,(B 4/22 $B$h$j$D$V$d$-$O$8$a$^$9(B @saeko2010 4/22 $B$"$N:c;R@h@8$,5"$C$F$/$k(B!? http://bit.ly/bUQZho #saeko2010 (Office2010J, 2010.04.16)$B!#(B $B

2010.04.19 $BDI5-(B:

$B!!4XO"(B:

2010.04.22 $BDI5-(B:

$B!!4XO"(B:

2010.04.27 $BDI5-(B:

$B!!(B$B!V(B2,010$B?M$N$$$$$M(B!$B!W$rL\;X$7!":c;R@h@8$,%;%_%J!<%G%S%e!<(B $B!A(B70$B?MD6$N;22C (PC Watch, 2010.04.26)

2010.05.25 $BDI5-(B:

$B!!(B$B:c;R(B 2010 $BB46H%$%Y%s%H (saeko2010.tv)$B!#(B2010.06.30$B!"El5~=BC+6hK?=j!"L5NA!#El5~ET=BC+6h$H8@$o$l$?$i!"(B$B%^%$%/%m%=%U%H3t<02q$B$7$+;W$$$D$+$J$$$N$G$9$,!"$I$&$J$s$G$7$g$&!D!D!#(B


$B"#(B 2010.04.08

$B"#(B $BDI5-(B

Microsoft 2009 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

Authorization Bypass When Executing An Embedded Executable.

$B!!(BImmunity $B$N?M$O(B 2 $BG/A0$+$iCN$C$F$$$?$=$&$G(B: Exploiting PDF files without vulnerability (immunityinc.com, 2010.03.24)$B!"(B CVE-2009-4764

$B!!$"$H!"(BKeeping Adobe Reader and Acrobat Safe (ESET Threat Blog, 2010.04.07) $B$G$O!"(B[$B%^%k%A%a%G%#%"$N?.Mj@-(B($B=>Mh7A<0(B)] $B$N(B [$B%^%k%A%a%G%#%"A`:n$r5v2D(B] $B$N9`$r!"(B $B!V>o$K5v2D!W(B($B%G%U%)%k%H(B) $B$+$i!V3NG'$9$k!W$KJQ99$9$kOC$,=P$F$$$^$9!#(B

$B"#(B $B$$$m$$$m(B (2010.04.08)
(various)


$B"#(B 2010.04.07

$B"#(B $BDI5-(B

Authorization Bypass When Executing An Embedded Executable.

$B!!(BAdobe $B$+$i8x<0%"%J%&%s%9=P$^$7$?(B: PDF "/Launch" Social Engineering Attack (Adobe Reader Blog, 2010.04.06)$B!#(B [$B4D6-@_Dj(B] $B"*(B [$B?.Mj@-4IM}%^%M!<%8%c(B] $B$N!V30It%"%W%j%1!<%7%g%s$G(B PDF $B0J30$NE:IU%U%!%$%k$r3+$/$3$H$r5v2D!W$rL58z$K$9$k(B ($B%A%'%C%/$r30$9(B) $B$3$H$G2sHr$G$-$k$=$&$G$9!#(B

$B!!%l%8%9%H%j$@$H!"(BHKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\$B%P!<%8%g%sHV9f(B\Originals $B$G(B bAllowOpenFile $B$r(B 0 $B$K$9$k$N$@$=$&$G!#(B $B$"$H!"F1$8>l=j$G(B bSecureOpenFile $B$r(B 1 $B$K$9$k$H!"$3$N@_Dj9`L\$,%0%l%$%"%&%H$5$l$k$=$&$G!#(B

$B"#(B Recommend Removing RSA Security 1024 V3 root certificate authority
(mozilla.dev.security.policy, 2010.04.03)

$B!!(BMozilla $B@=IJ$KAH$_9~$^$l$F$$$k%k!<%H>ZL@=q(B RSA Security 1024 v3 $B$O!"(B RSA $B$+$i$N$b$N$G$b(B VeriSign $B$+$i$N$b$N$G$b$J$$$+$i:o=|$9$Y$-!"$H$$$&OC!#(B $B!D!D%"%J%&%s%9=P$^$7$?(B: Removing the RSA Security 1024 V3 Root (Mozilla Security Blog, 2010.04.06)

$B!!$d$jJ}(B:

  1. [$B%D!<%k(B] $B%a%K%e!<$N(B [$B%*%W%7%g%s(B] $B$rA*Br$7$^$9!#(B $B!V%*%W%7%g%s!W%&%#%s%I%&$,3+$-$^$9!#(B

  2. $B!V%*%W%7%g%s!W%&%#%s%I%&$K$*$$$F!"(B[$B>\:Y(B] $B$N(B [$B0E9f2=(B] $B%?%V$rA*Br$7!"(B[$B>ZL@=q$rI=<((B] $B$rA*Br$7$^$9!#(B

    $B!V>ZL@=q%^%M!<%8%c!W%&%#%s%I%&$,3+$-$^$9!#(B

  3. $B!V>ZL@=q%^%M!<%8%c!W%&%#%s%I%&$K$*$$$F!"(B[$BG'>Z6I>ZL@=q(B] $B%?%V$rA*Br$7!"(B RSA Security Inc $B$N(B RSA Security 1024 v3 $B$rA*Br$7$^$9!#(B $B$=$N8e$G(B [$B@_Dj(B] $B$rA*Br$7$^$9!#(B

    $B!VG'>Z6I>ZL@=q$KBP$9$k?.Mj@-$N@_Dj!W%&%#%s%I%&$,I=<($5$l$^$9!#(B

  4. $B!VG'>Z6I>ZL@=q$KBP$9$k?.Mj@-$N@_Dj!W%&%#%s%I%&$K$*$$$F!"(B

    • $B$3$N>ZL@=q$r(B Web $B%5%$%H$N<1JL$K;HMQ$9$k(B
    • $B$3$N>ZL@=q$r%a!<%k%f!<%6$N<1JL$K;HMQ$9$k(B
    • $B$3$N>ZL@=q$r%=%U%H%&%'%"@=:n

      $BA4$F$K$D$$$F%A%'%C%/$r30$7$^$9!#(B

      $B30$7=*$($?$i!"(B[OK] $B$rA*Br$7$^$9!#!VG'>Z6I>ZL@=q$KBP$9$k?.Mj@-$N@_Dj!W%&%#%s%I%&$,>C$($^$9!#(B

$B!!!V>ZL@=q%^%M!<%8%c!W%&%#%s%I%&$K$*$$$F!"(B[$B@_Dj(B] $B$G$O$J$/(B [$B:o=|(B] $B$rA*Br$9$k$H!"0l8+:o=|$G$-$k$h$&$K8+$($^$9$,!"(B $B%"%W%j$r:F5/F0$9$k$H$^$?I|3h$7$F$7$^$&$h$&$G$9!#$?$@$7$3$N$H$-!"?.Mj@-@_Dj$OA4$FL58z(B ($B%A%'%C%/$,30$5$l$?>uBV(B) $B$K$J$C$F$$$^$9!#$=$N$?$a!"(B[$B:o=|(B] $B$r7$-$d$9$$$N$G(B [$B@_Dj(B] $B$r;H$&J}K!$K=q$-D>$7$^$7$?!#$?$+$@$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!%"%W%j%1!<%7%g%s8DJL$Kl9g$O!"(BFirefox $B$H(B Thunderbird $B$=$l$>$l$K$*$$$F:o=|$r


$B"#(B 2010.04.06

$B"#(B $BDI5-(B

Authorization Bypass When Executing An Embedded Executable.

$B!!(BCVE-2010-1240 (Adobe Reader 9.3.1)$B!"(B CVE-2010-1239 (Foxit Reader < 3.2.1.0401)$B!#(B CVE-2010-1240 $B$O!"7Y9p2hLL$NI=5-$r:>>N$G$-$k$3$H$KBP$9$k$b$N!#(B Escape From PDF (Didier Stevens, 2010.03.29) $B$K:>>NNc$"$j!#(B


$B"#(B 2010.04.05

$B"#(B $BDI5-(B

Authorization Bypass When Executing An Embedded Executable.

$B!!(BFoxit Reader 3.2.1.0401 $B$r;n$7$F$_$^$7$?!#(BAdobe Reader $B$HF1MM!"7Y9p2hLL$,=P$k$h$&$K$J$j$^$7$?!#$?$@$7!"(BFoxit Reader $B$O(B [$B3+$/(B] $B$,%G%U%)%k%H$J$s$@$h$M$(!#(B

$B!!(BAdobe Reader $B$O(B [$B3+$+$J$$(B] $B$,%G%U%)%k%H$J$N$G$9$,!#(B


$B"#(B 2010.04.04

$B"#(B Authorization Bypass When Executing An Embedded Executable.
(foxitsoftware.com, 2010.04.02)

$B!!(BEscape From PDF (Didier Stevens, 2010.03.29)$B!"(BPDF$B$H$O%W%m%V%l%^%F%#%C%/!&%I%-%e%a%s%H!&%U%)!<%^%C%H$NN,$J$N$+!)(B ($B%(%U%;%-%e%"%V%m%0(B, 2010.03.31) $B$N7o!"(BFoxit Reader 3.2.1.0401 $B$G=$@5$5$l$?$=$&$G!#(B $B%@%&%s%m!<%I(B$B!#(B

$B!!4XO"(B: $B;EMM$H@H ($B%(%U%;%-%e%"%V%m%0(B, 2010.04.02)$B!#N`;w;vNc$OB>$K$b$"$k$H$$$&;XE&!#(B

Windows$B%5%$%I%P!<$N%,%8%'%C%H$O(BHTML$B$d(BJavaScript$B$rMQ$$$F:n@.$9$k$3$H$,$G$-$^$9!#(BWindows$B$G$9$N$G$*$=$i$/(B Internet Explorer$B$N%;%-%e%j%F%#@_Dj$,0z$-7Q$,$l$k$H;W$o$l$,$A$G$9$,!"o$K4K$$%;%-%e%j%F%#@_Dj$G
Java$B$N(BSWT$B$G$O(BIE$B%3%s%]!<%M%s%H$r;H$C$F3+H/$9$k$3$H$,$G$-$^$9$,!"$3$N$H$-$N%;%-%e%j%F%#@_Dj$b(BIE$B$N$b$N$,;H$o$l$k$N$G$O$J$/!"Hs>o$K4K$$@_Dj$GF0:n$7$^$9$N$G!"$d$O$j(BCMD.EXE$B$r

2010.04.05 $BDI5-(B:

$B!!(BFoxit Reader 3.2.1.0401 $B$r;n$7$F$_$^$7$?!#(BAdobe Reader $B$HF1MM!"7Y9p2hLL$,=P$k$h$&$K$J$j$^$7$?!#$?$@$7!"(BFoxit Reader $B$O(B [$B3+$/(B] $B$,%G%U%)%k%H$J$s$@$h$M$(!#(B

$B!!(BAdobe Reader $B$O(B [$B3+$+$J$$(B] $B$,%G%U%)%k%H$J$N$G$9$,!#(B

2010.04.06 $BDI5-(B:

$B!!(BCVE-2010-1240 (Adobe Reader 9.3.1)$B!"(B CVE-2010-1239 (Foxit Reader < 3.2.1.0401)$B!#(B CVE-2010-1240 $B$O!"7Y9p2hLL$NI=5-$r:>>N$G$-$k$3$H$KBP$9$k$b$N!#(B Escape From PDF (Didier Stevens, 2010.03.29) $B$K:>>NNc$"$j!#(B

2010.04.07 $BDI5-(B:

$B!!(BAdobe $B$+$i8x<0%"%J%&%s%9=P$^$7$?(B: PDF "/Launch" Social Engineering Attack (Adobe Reader Blog, 2010.04.06)$B!#(B [$B4D6-@_Dj(B] $B"*(B [$B?.Mj@-4IM}%^%M!<%8%c(B] $B$N!V30It%"%W%j%1!<%7%g%s$G(B PDF $B0J30$NE:IU%U%!%$%k$r3+$/$3$H$r5v2D!W$rL58z$K$9$k(B ($B%A%'%C%/$r30$9(B) $B$3$H$G2sHr$G$-$k$=$&$G$9!#(B

$B!!%l%8%9%H%j$@$H!"(BHKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\$B%P!<%8%g%sHV9f(B\Originals $B$G(B bAllowOpenFile $B$r(B 0 $B$K$9$k$N$@$=$&$G!#(B Acrobat Reader $B$r(B Adobe Acrobat $B$KJQ$($k$H(B Acrobat $BMQ!#(B $B$"$H!"F1$8>l=j$G(B bSecureOpenFile $B$r(B 1 $B$K$9$k$H!"$3$N@_Dj9`L\$,%0%l%$%"%&%H$5$l$k$=$&$G!#(B

2010.04.08 $BDI5-(B:

$B!!(BImmunity $B$N?M$O(B 2 $BG/A0$+$iCN$C$F$$$?$=$&$G(B: Exploiting PDF files without vulnerability (immunityinc.com, 2010.03.24)$B!"(B CVE-2009-4764

$B!!$"$H!"(BKeeping Adobe Reader and Acrobat Safe (ESET Threat Blog, 2010.04.07) $B$G$O!"(B[$B%^%k%A%a%G%#%"$N?.Mj@-(B($B=>Mh7A<0(B)] $B$N(B [$B%^%k%A%a%G%#%"A`:n$r5v2D(B] $B$N9`$r!"(B $B!V>o$K5v2D!W(B($B%G%U%)%k%H(B) $B$+$i!V3NG'$9$k!W$KJQ99$9$kOC$,=P$F$$$^$9!#(B

2010.04.18 $BDI5-(B:

$B!!$+$$$H$5$s$K$h$k(B Windows / Linux $BMQ$N(B PDF $B%S%e!<%"$G$N(B /Launch /Action $B$N%5%]!<%H>u67$N$^$H$a$,8x3+$5$l$F$$$^$9(B ($B$+$$$H$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)$B!#(B

2010.04.30 $BDI5-(B:

$B!!(B/Launch /Action $B$r;H$C$?967b(B PDF $B%U%!%$%k$,9-$/=P2s$C$F$$$k$h$&$G$9!#(B

2010.07.02 $BDI5-(B:

$B!!(BAdobe Reader / Acrobat 9.3.3 / 8.2.3 $B$K$O!"(B/Launch /Action $B$N7o$KBP$9$kBP1~$,4^$^$l$F$$$k!#(B

  • $B56Au%a%C%;!<%8$NM^;_(B

  • $B%3%^%s%I

$B!!$7$+$7\:Y(B:

2010.08.24 $BDI5-(B:

$B!!(BAPSB10-17: Security Advisory for Adobe Reader and Acrobat (adobe) $B$,=P$F$$$^$9!#$3$l$K$O(B CVE-2010-1240 $B$N=$@5$,4^$^$l$F$$$k$=$&$J$N$G!"$b$7$+$7$?$i!">e5-$N!X!V%3%^%s%I


$B"#(B 2010.04.02

$B"#(B [Full-disclosure] Zabbix <= 1.8.1 SQL Injection
(Full-disclosure, 2010.04.01)

$B!!(BZabbix 1.8.1 $B0JA0$K(B SQL Injection $B7g4Y$,$"$j!"(B Zabbix 1.8.2 $B$G=$@5$5$l$F$$$k$=$&$G!#(B CVE-2010-1277

$B"#(B The Upcoming Black Hat Europe 2010 presentation
(Fortinet blog, 2010.03.31)

$B!!(BAnd, we will also show a working exploit for a PDF zero-day vulnerability we discovered recently in the latest Adobe Reader 9.3.1 (where DEP is enabled by default) $B$J$s$F=q$+$l$F$^$9$h1|$5$s(B! Adobe Reader 9.3.1 $B$G(B PDF $B%U%!%$%k$r3+$/$HL57Y9p$GEEBn$,5/F0$9$k%G%bF02h$,7G:\$5$l$F$$$k!#(B Adobe PSIRT $B$K3+<(:Q$@$=$&$G!#(B CVE-2010-1241

$B"#(B Firefox 3.6.3 $B%j%j!<%9%N!<%H(B
(mozilla.jp, 2010.04.01)

$B!!(BCanSecWest Pwn2Own $B%O%C%-%s%0%3%s%F%9%H(B $B$G%d%i$l$?7o$,=$@5$5$l$F$$$^$9(B: MFSA 2010-25: $B%9%3!<%W$N:.F1$K$h$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B (mozilla-japan.org)

$B!!4XO"(B: Firefox 3.6 $B$N%;%-%e%j%F%#%"%C%W%G!<%H(B (3.6.3) $B$r8x3+$7$^$7$?(B (mozilla.jp, 2010.04.02)

$B"#(B $BDI5-(B

CanSecWest Pwn2Own $B%O%C%-%s%0%3%s%F%9%H(B

$B!!(BFirefox $B$,%d%i$l$?7o!"(BFirefox 3.6.3 $B$G=$@5$5$l$^$7$?!#(B MFSA 2010-25: $B%9%3!<%W$N:.F1$K$h$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B (mozilla-japan.org)


$B"#(B 2010.04.01

$B"#(B $B$$$m$$$m(B (2010.04.01)
(various)

$B"#(B Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2010
(Oracle, 2010.03.30)

$B!!(BJava $B?7HGEP>l!#(B27 $B

$B!!(BCVE: CVE-2009-3555 CVE-2010-0082 CVE-2010-0084 CVE-2010-0085 CVE-2010-0087 CVE-2010-0088 CVE-2010-0089 CVE-2010-0090 CVE-2010-0091 CVE-2010-0092 CVE-2010-0093 CVE-2010-0094 CVE-2010-0095 CVE-2010-0837 CVE-2010-0838 CVE-2010-0839 CVE-2010-0840 CVE-2010-0841 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 CVE-2010-0845 CVE-2010-0846 CVE-2010-0847 CVE-2010-0848 CVE-2010-0849 CVE-2010-0850 $B!#(B

$B"#(B $BDI5-(B

CanSecWest Pwn2Own $B%O%C%-%s%0%3%s%F%9%H(B

$B"#(B $B%9%&%'!<%G%s$N(BIX$B$,Cf9q$N(BDNS$B%k!<%H!&%5!<%P$rC(B
(ComputerWorld.jp, 2010.03.29)

$B!!$3$l$G$9$,!"(B The Great DNS Wall of China $B$NFbMF$,30It$K1L$l=P$7$F$7$^$C$?$H$$$&OC$_$?$$!#>.=P$5$s!"(Biwata.n $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B Wireshark 1.2.7, 1.0.12, and 1.3.4 Released
(Wireshark.org, 2010.03.31)

$B!!=P$F$^$9!#(BWindows 2000 $B%5%]!<%HI|3h(B$B$J$I!#(B


[$B%;%-%e%j%F%#%[!<%k(B memo]
[$B;d$K$D$$$F(B]