$B%;%-%e%j%F%#%[!<%k(B memo - 2010.05

Last modified: Thu Jul 1 00:43:53 2010 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2010.05.31


$B"#(B 2010.05.29

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 4 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS10-020 patch $B$rE,MQ$9$k$H!"(BSMB 1.0 $B%Y!<%9$N%j%b!<%H%5!<%P(B ($BNc(B: Windows NT 4.0$B!"(BCisco WAAS$B!"(BNetApp DataOnTap) $B$H$N4V$G!"J8=q$NJ]B8$d%Q!<%_%C%7%g%s$NJQ99$,$G$-$J$/$J$k>l9g$,$"$k$=$&$G!#(B Cisco WAAS (Samba $B%Y!<%9$N


$B"#(B 2010.05.28

$B"#(B $BDI5-(B

Yahoo!$B%1!<%?%$$N0lItC


$B"#(B 2010.05.27


$B"#(B 2010.05.26


$B"#(B 2010.05.25

$B"#(B $BDI5-(B

4/22 $B$"$N:c;R@h@8$,5"$C$F$/$k(B?!

$B$$$m$$$m(B (2010.05.17)

$B!!(BMySQL 5.1.47 $B=P$^$7$?!#(B$B%@%&%s%m!<%I(B$B!#(B

$B"#(B $B$$$m$$$m(B (2010.05.25)
(various)


$B"#(B 2010.05.24

$B"#(B Yahoo!$B%1!<%?%$$N0lItC
(HASH$B%3%s%5%k%F%#%s%03t<02q

$B!!BP>]$H$J$kChttp://www.hash-c.co.jp/ajax/chkajax.php $B$K%"%/%;%9$7$F3F<+$G3NG'$7$h$&!#(B ($B%1!<%?%$$+$i$7$+%"%/%;%9$G$-$J$$$=$&$G$9(B)

2010.05.28 $BDI5-(B:

$B!!%=%U%H%P%s%/$+$i%"%J%&%s%9=P$^$7$?(B: $B%V%i%&%6$N%9%/%j%W%H@_Dj$K$D$$$F(B ($B%=%U%H%P%s%/(B, 2010.05.27)$B!#(B

$B"#(B $B=EMW$J$*CN$i$;(B - HP Notebook PC$B%P%C%F%j!<%Q%C%/<+
(HP, 2010.05.20)

$B!!BP>]5!

2007$BG/(B8$B7n!A(B2008$BG/(B5$B7n!J%N!<%H(BPC$B$N%7%j%"%kHV9f(Bxxx730xxxx$B!A(Bxxx821xxxx$B!K$K@=B$$5$l$?0J2<$N%N!<%H(BPC$B$KEk:\$9$k!"0lIt$N%P%C%F%j%Q%C%/$,BP>]$G$9!#(B

  • HP Compaq 6510b Notebook PC$B!JDI2C5!
  • HP Compaq 6515b Notebook PC$B!JDI2C5!
  • HP Compaq 6710b Notebook PC$B!JDI2C5!
  • HP Compaq 6715s Notebook PC$B!JDI2C5!
  • HP Compaq 6720s Notebook PC
  • HP Pavilion Notebook PC dv2000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv2405$B!J(BP/N: RX692AV$B!K(B
  • HP Pavilion Notebook PC dv2605/ dv2705/ dv2805$B!J(BP/N: RW026AV$B$^$?$O(BGP344AV$B!K(B
  • HP Pavilion Notebook PC dv2800$B!J(BP/N: GP364AV$B!K(B
  • HP Pavilion Notebook PC dv6000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv6200$B!J(BP/N: RD869AV$B$^$?$O(BRD870AV$B!K(B
  • HP Pavilion Notebook PC dv6205$B!J(BP/N: RD861AV$B$^$?$O(BRD862AV$B!K(B
  • HP Pavilion Notebook PC dv6500$B!J(BP/N: RL675AV$B$^$?$O(B RL676AV$B!K(B
  • HP Pavilion Notebook PC dv6700/ dv6800$B!J(BP/N: GP238AV$B$^$?$O(B GP239AV$B!K(B
  • HP Pavilion Notebook PC dv9000$B%7%j!<%:$N0J2<$N5!
  • HP Pavilion Notebook PC dv9500$B!J(BP/N: RL596AV$B$^$?$O(BGP236AV)
  • HP Pavilion Notebook PC dv9700$B!J(BP/N: GP236AV$B!K(B
  • HP G7000 Notebook PC
    • HP Compaq 6710s Notebook PC$B!JF|K\L$H/Gd!K(B
    • HP Compaq 6715b Notebook PC$B!JF|K\L$H/Gd!K(B
    • HP Pavilion Notebook PC dv2000/ dv2500/ dv2700/ dv6000/ dv9000$B!JF|K\L$H/Gd!K(B
    • HP G6000 Notebook PC$B!JF|K\L$H/Gd!K(B
    • HP Pavilion dx6000/ dx6500/ dx6700$B!JF|K\L$H/Gd!K(B
    • Compaq Presario A900/ C700/ F500/ F700 Notebook PC$B!JF|K\L$H/Gd(B
    • Compaq Presario V3000/ V3500/ V3700/ V6000/ V6500/ V6700 Notebook PC$B!JF|K\L$H/Gd!K(B

    $B"#(B 2010.05.23


    $B"#(B 2010.05.22


    $B"#(B 2010.05.21


    $B"#(B 2010.05.20

    $B"#(B $B$$$m$$$m(B (2010.05.20)
    (various)

    $B"#(B BIND 9.7.0-P2 / 9.6.2-P2 / 9.6-ESV-R1 / 9.5.2-P4 / 9.4-ESV-R2 $B$,8x3+$5$l$F$$$^$9(B
    (ISC.org, 2010.03.20)

    $B!!$3$l$r=$@5$9$k$?$a$@$=$&$G!#(B

    2876. [bug] Named could return SERVFAIL for negative responses from unsigned zones. [RT #21131]

    $B"#(B 2010.05.19

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2028859) Canonical Display Driver $B$N@H
    (Microsoft, 2010.05.19)

    $B!!(BWindows 7 / Server 2008 R2 $B$K7g4Y!#(B Canonical Display Driver (cdd.dll) $B$K7g4Y$,$"$j!"(Bremote $B$+$i(B OS $B$r:F5/F0$G$-$k!#(B $BG$0U$N%3!<%I$rExploitability Index $B$O(B 3 $B$G$"$j(B$B!"6K$a$F:$Fq$HG'<1$5$l$F$$$k!#(B CVE-2009-3678

    $B!!(Bpatch $B$O$^$@$J$$!#(BWindows Aero $B$rL58z$H$9$k(B ([$B%Y!<%7%C%/(B $B%F!<%^$H%O%$(B $B%3%s%H%i%9%H(B $B%F!<%^(B] $B$KJ,N`$5$l$F$$$k%F!<%^$r;HMQ$9$k(B) $B$3$H$G7g4Y$r2sHr$G$-$k!#(B

    $B!!4XO"(B: CDD.dll vulnerability: Difficult to exploit (Microsoft Security Research & Defense, 2010.05.18)

    $B"#(B PostgreSQL Security Update
    (PostgreSQL.org, 2010.05.17)

    $B!!(BPostgreSQL 8.4.4 / 8.3.11 / 8.2.17 / 8.1.21 / 8.0.25 / 7.4.29 $BEP>l!#(B 3 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B

    $B!!(BCVE-2010-1169 $B$H(B CVE-2010-1170 $B$O(B 8.4.4 $B%j%j!<%9%N!<%H(B$B$J$I$G2r@b$5$l$F$$$k$1$l$I!"(BCVE-2010-1447 $B$O$I$&$$$&FbMF$J$s$@$m$&!#(B


    $B"#(B 2010.05.18

    $B"#(B Modern cars vulnerable to malicious hacks
    (newscientist.com, 2010.05.14)

    $B!!(BExperimental Security Analysis of a Modern Automobile (autosec.org) $B$N7o!#$$$^$I$-$N%/%k%^$N@)8f$K;H$o$l$k(B Controller Area Network (CAN) $B$O!">pJs%;%-%e%j%F%#E*$K$O%\%m%\%m$N$h$&$G!#$^$!!"$=$&$@$m$&$J$!!#(B

    $B!!FlexRay $B$H$$$&$b$N$,$"$k$=$&$G!#(B $B;OF0$9$k(BFlexRay (EDN Japan, 2009.04) $B$K$h$k$H!"(B

    $B!!2C$($F!"(BFlexRay$B$O!"(BCAN$B$h$j$b9b$$?.Mj@-$r3NJ]$G$-$k$h$&$K$J$C$F$$$k!#Nc$($P!"(B2$B$D$N4pK\%A%c%s%M%k$rHw$($k$3$H$G!"%M%C%H%o!<%/$rFs=E2=$7!">iD9@-$r9b$a$F$$$k!#$^$?!"%P%9%,!<%G%#%"%s!J(BBG$B!K$K$h$j!"DL?.%9%1%8%e!<%k$r4F;k$7!"IT@5$JDL?.$,$"$C$?>l9g$K$ODL?.$re$GI,MW$J!"DL?.%5%$%/%k$NF14|%?%$%_%s%0$rJd@5$9$k5!G=$bHw$($F$$$k!#$b$H$b$H!"(BFlexRay$B$O!"(BFRC$B$N@_N);~$+$i!"5!3#E*$J9=B$$rMxMQ$;$:$K!"40A4$JEE;R@)8f$@$1$GA`BI$d%V%l!<%-$NF0:n$r

    $B!!$"$/$^$G%(%i!


    $B"#(B 2010.05.17

    $B"#(B $B$$$m$$$m(B (2010.05.17)
    (various)

    2010.05.25 $BDI5-(B:

    $B!!(BMySQL 5.1.47 $B=P$^$7$?!#(B$B%@%&%s%m!<%I(B$B!#(B

    $B"#(B $BDI5-(B

    $B$$$m$$$m(B (2010.05.12)


    $B"#(B 2010.05.14


    $B"#(B 2010.05.13

    $B"#(B Microsoft 2010 $BG/(B 5 $B7n$N%;%-%e%j%F%#>pJs(B
    (Microsoft, 2010.05.12)

    $B!!(B$BM=9p(B$B$I$*$j(B 2 $B7o!#(B

    MS10-030 - $B6[5^(B: Outlook Express $B$*$h$S(B Windows $B%a!<%k$N@H

    MS10-031 - $B6[5^(B: Microsoft Visual Basic for Applications (VBA) $B$N@H

    $B!!(BVisual Basic for Applications (VBA) $B$K7g4Y!#(B VBA $B$,(B ActiveX $B%3%s%H%m!<%k$r8!:w$9$kJ}K!$K7g4Y$,$"$j!"(B ActiveX $B%3%s%H%m!<%k$r4^$`96N,%U%!%$%k$r(B VBA $B%i%s%?%$%`$KEO$9$HG$0U$N%3!<%I$rCVE-2010-0815

    $B!!(BExploitability Index: 2

    $B!!(BOffice XP / 2003 / 2007 $B$K$O(B VBA $B$,4^$^$l$k$?$a$3$N7g4Y$N1F6A$rl9g$,$"$k!#(B

    $B%5!<%I(B $B%Q!<%F%#$N%"%W%j%1!<%7%g%s8~$1$N(B VBE6.DLL $B$r99?7$9$k$K$O!"(BVBA $B$N%5!<%I(B $B%Q!<%F%#$N%"%W%j%1!<%7%g%s$N)$5$l$k:GA1:v=>$C$F!"%5%$%I(B $B%P%$%5%$%I$N%"%;%s%V%j$H$7$F6&M-$N%3%s%]!<%M%s%H$r;HMQ$9$k$3$H$r3NG'$7$?>l9g!"(BMicrosoft Visual Basic for Applications (KB974945) $B$N99?7%W%m%0%i%`$rE,MQ$9$k$H!"6&M-$N>l=j$N(B VBE6.DLL $B$,$3$N%;%-%e%j%F%#>pJs$G@bL@$7$F$$$k@H
    $B0lJ}$G!"%5!<%I%Q!<%F%#$N%"%W%j%1!<%7%g%s$,!"?d>)$5$l$?:GA1:vDL$j$K6&M-$N>l=j$K(B VBE6.DLL $B$rG[CV$7$J$$>l9g!"%5!<%I%Q!<%F%#$N%"%W%j%1!<%7%g%s3+H/pJs$G@bL@$7$F$$$k@Hl9g$b$"$k$?$a!"(BVBE6.DLL $B$r%$%s%9%H!<%k$9$k%5!<%I%Q!<%F%#$N%"%W%j%1!<%7%g%s$9$Y$F$,$3$N%;%-%e%j%F%#>pJs$G@bL@$7$F$$$k@H

    $B!!A0

    $B!!4XO"(B: MS10-031: VBE6 Single-Byte Stack Overwrite (Microsoft Security Research & Defense, 2010.05.11)

    $B"#(B APSB10-12: Security update available for Shockwave Player
    (Adobe, 2010.05.11)

    $B!!(BShockwave Player 11.5.6.606 $B0JA0$K(B 18 $B7$/2DG=@-$,$"$j!";D$j(B 16 $B7$/!#(B CVE-2010-0127 CVE-2010-0128 CVE-2010-0129 CVE-2010-0130 CVE-2010-0986 CVE-2010-0987 CVE-2010-1280 CVE-2010-1281 CVE-2010-1282 CVE-2010-1283 CVE-2010-1284 CVE-2010-1286 CVE-2010-1287 CVE-2010-1288 CVE-2010-1289 CVE-2010-1290 CVE-2010-1291 CVE-2010-1292

    $B!!(BShockwave Player 11.5.7.609 $B$G=$@5$5$l$F$$$k!#(Bhttp://get.adobe.com/shockwave/ $B$+$iF~

    $B!!4XO"(B:


    $B"#(B 2010.05.12

    $B"#(B $B$$$m$$$m(B (2010.05.12)
    (various)

    2010.05.17 $BDI5-(B:

    $B!!(BKHOBE $B4XO"(B:

    $B"#(B Plugin Check for Everyone
    (Mozilla Security Blog, 2010.05.11)

    $B!!(BPlugin Check (mozilla.com)$B!"(B Firefox $B$NB>$K(B Safari 4, Chrome 4, Opera 10.5 $B$K40A4BP1~!"(BIE 7 / 8 $B$K$b8BDjBP1~$7$?$=$&$G$9!#(B$BBP1~>u67(B$B!#(B

    Why is IE Support Limited?

    Unlike other modern browsers, Internet Explorer lacks a plugins JavaScript object. Instead of dynamically checking the plugins object to discover installed plugins, with IE plugin version checking is done with specific ActiveX code against a limited list of plugins. We'd love to check more plugins, patches welcome here.

    $B!!$G$b!"(BAcrobat 8.2.2 $B$r(B outdated $B$H8@$C$F$/$l$?$j$9$k$J$"!#(B $B$$$^$$$A;H$($J$$!#(B


    $B"#(B 2010.05.11

    $B"#(B $B$$$m$$$m(B (2010.05.11)
    (various)

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2010 $BG/(B 5 $B7n(B
    (Microsoft, 2010.05.07)

    $B!!L@F|$G$9!#(B


    $B"#(B 2010.05.10

    $B"#(B $B3F
    (sourceforge.jp, 2010.05.06)

    $B!!$3$l$r;H$&$H!"3F)!#(B

    $B!!5$$,$D$$$?$3$H(B:

    • Adobe Reader 9.3.2 $B$,%$%s%9%H!<%k$5$l$?4D6-$G$O!"(B $B!V(BAdobe Reader 9.3$B!W$H!V(BAdobe Reader 9.3.2$B!W$NN>J}$,%$%s%9%H!<%k$5$l$F$$$k$HH=Dj$7$A$c$&$h$&$G!#(B

    • Flash Player $B$O%W%i%0%$%sHG$7$+99?7$7$J$$$_$?$$!#(B $B$U$D$&$N?M$O(B ActiveX $BHG$r;H$C$F$$$k$H;W$&$N$@$,!#(B

    $B!!$H$$$&$o$G


    $B"#(B 2010.05.09


    $B"#(B 2010.05.08


    $B"#(B 2010.05.07

    $B"#(B [Clamav-announce] problem with daily.cvd 10938
    (Clamav.net, 2010.05.07)

    $B!!(Bdaily.cvd 10938 $B$r(B ClamAV < 0.96 $B$+$D(B 32bit $B$J>uBV$G;H$&$H(B segmentation fault $B$9$k$3$H$,$"$k$=$&$G!#(Bdaily.cvd 10939 $B$G=$@5$5$l$F$$$k!#(B

    $B"#(B $B$$$m$$$m(B (2010.05.07)
    (various)


    $B"#(B 2010.05.06


    $B"#(B 2010.05.05


    $B"#(B 2010.05.02

    $B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (983438) Microsoft SharePoint $B$N@H:3J$5$l$k(B
    (Microsoft, 2010.04.30)

    $B!!(BSharePoint Services 3.0 / SharePoint Server 2007 $B$K(B XSS $B7g4Y!#(BXSS in Microsoft SharePoint Server 2007 (bugtraq, 2010.04.29) $B$N7o!#(B/_layouts/help.aspx $B$K(B XSS $B7g4Y$,$"$k$h$&$G!#(B

    $B!!(Bpatch $B$O$^$@$J$$!#(BSA 983438 $B$G$O!"2sHr:v$H$7$F(B Help.aspx $B%U%!%$%k$X$N(B ACL $B@_Dj(B ($B%"%/%;%95qH]@_Dj(B) $B$rDs<($7$F$$$k!#(B

    $B!!4XO"(B: Sharepoint XSS issue (Microsoft Security Research & Defense, 2010.04.29)$B!#(B IE8 $B$N(B XSS $B%U%#%k%?$G$I$&$J$k$+!"$H$$$&OC!#(B

    2010.06.11 $BDI5-(B:

    $B!!(BMS10-039 - $B=EMW(B: Microsoft SharePoint $B$N@H:3J$5$l$k(B (2028554) $B$G=$@5$5$l$^$7$?!#(B

    $B"#(B $B$$$m$$$m(B (2010.05.02)
    (various)

    $B"#(B $BDI5-(B

    $B$$$m$$$m(B (2010.04.28)

    $B!!(BOpera 10.53 $B=P$^$7$?(B: 10.53 released (Opera Desktop Team, 2010.04.30)$B!#(B SA39590: Opera Content Writing Uninitialised Memory Vulnerability (secunia, 2010.04.27) $B$N7o$,=$@5$5$l$F$$$^$9!#(B


    $B"#(B 2010.05.01


    [$B%;%-%e%j%F%#%[!<%k(B memo]