$B%;%-%e%j%F%#%[!<%k(B memo - 2010.06

Last modified: Fri Sep 3 11:43:49 2010 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2010.06.30

$B"#(B Adobe Reader and Acrobat 9.3.3 and 8.2.3
(Adobe Reader blog, 2010.06.29)

$B!!(BAdobe Reader / Acrobat 9.3.3 / 8.2.3 $B$K$O!"(BAPSB10-15: Security updates available for Adobe Reader and Acrobat $B$NB>$K$b$$$m$$$m$"$k$=$&$G!#(B

2010.07.02 $BDI5-(B:

$B!!\:Y(B:

$B"#(B APSB10-15: Security updates available for Adobe Reader and Acrobat
(Adobe, 2010.06.29)

$B!!(BAdobe Reader / Acrobat 9.3.3 / 8.2.3 $BEP>l!#(BAPSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat $B$N7o(B (CVE-2010-1297) $B$r4^$a!"9g7W(B 17 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1297).
Note: There are reports that this issue is being actively exploited in the wild.

This update mitigates a social engineering attack that could lead to code execution (CVE-2010-1240).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-1285).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1295).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2168).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2201).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2202).

This update resolves a UNIX-only memory corruption vulnerability that could lead to code execution (CVE-2010-2203).

This update resolves a denial of service vulnerability; arbitrary code execution has not been demonstrated, but may be possible (CVE-2010-2204).

This update resolves an uninitialized memory vulnerability that could lead to code execution (CVE-2010-2205).

This update resolves an array-indexing error vulnerability that could lead to code execution (CVE-2010-2206).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2207).

This update resolves a dereference deleted heap object vulnerability that could lead to code execution (CVE-2010-2208).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2209).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2210).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2211).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2212).

$B!!4XO"(B: Adobe Reader 9.3.2 (CoolType.dll) Remote Memory Corruption / DoS Vulnerability (exploit-db.com)$B!#(BCVE-2010-2204 $B$N7o!#(B

2010.07.01 $BDI5-(B:

$B!!(BAdobe, Make My Day Too$B!D(B. (ESET Threat Blog, 2010.06.30)$B!#(BJavaScript $B$rL58z$K$7$?4D6-$G99?7$9$k$H!":F$S(B JavaScript $B$,M-8z$K$J$C$F$7$^$&(B ($B$H$$$&$+!"%G%U%)%k%H$KLa$k(B) $BLOMM!#Cm0U$7$^$;$&!#(B

2010.07.19 $BDI5-(B:

$B!!F|K\8lHG(B: APSB10-15 - Adobe Reader$B$*$h$S(BAcrobat$BMQ%;%-%e%j%F%#%"%C%W%G!<%H8x3+(B (Adobe)

$B"#(B $BDI5-(B

APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat

$B!!(BAdobe Reader / Acrobat 9.3.3 / 8.2.3 $B=P$^$7$?(B: APSB10-15: Security updates available for Adobe Reader and Acrobat (Adobe, 2010.06.29)$B!#(BCVE-2010-1297 $B$O(B Adobe Reader / Acrobat 9.x $B7O$K$@$11F6A$7$^$9$,!"B>$K$bBgNL$N=$@5$,$"$k$N$G!"(B8.x $B7O$K$D$$$F$b99?7HG(B 8.2.3 $B$,=P$F$$$^$9!#(B


$B"#(B 2010.06.29

$B"#(B CUPS 1.4.4
(cups.org, 2010.06.15)

$B!!(BCUPS 1.4.4 $BEP>l!#J#?t$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B libpng 1.4.3 / 1.2.44 $B%j%j!<%9(B
(libpng.org, 2010.06.25)

$B!!(Blibpng 1.4.3 / 1.2.44 $BEP>l!#G$0U$N%3!<%I$,CVE-2010-1205 $B$,=$@5$5$l$F$$$k!#(B

2010.07.01 $BDI5-(B:

$B!!(BCVE-2010-2249 $B$b$"$k$=$&$G!#$3$A$i$O(B DoS $B$NLOMM!#(B

$B"#(B $BDI5-(B

APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat

$B!!(BAdobe Reader, Acrobat $B$*$h$S(B Flash Player $B$N(Bauthplay.dll$B$N@HZ%l%]!<%H(B (NTT $B%G!<%?%;%-%e%j%F%#(B, 2010.06.15 $B99?7(B)

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2219475) Windows $B$N%X%k%W$H%5%]!<%H(B $B%;%s%?!<$N@H

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B(973811) $BG'>Z$KBP$9$kJ]8n$N6/2=(B


$B"#(B 2010.06.28

$B"#(B $B$$$m$$$m(B (2010.06.28)
(various)

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2219475) Windows $B$N%X%k%W$H%5%]!<%H(B $B%;%s%?!<$N@H

[JS10002] $B0lB@O:$N@H

$B"#(B $B!V(BRuby on Rails $B7HBS%5%$%H3+H/5;K!!WBh(B9$B>O$N%5%s%W%k%3!<%I$K4^$^$l$k@H
(Hideki SAKAMOTO $B$N;(5-(B, 2010.06.25)

$B$3$N%5%s%W%k%W%m%0%i%`$G;HMQ$5$l$F$$$k%;%C%7%g%s(BID$B$O%f!<%6!<$r<1JL2DG=!"$+$DC/$G$bF~pJs$N$_$r85$K@8@.$5$l$F$$$k$?$a!"B>?M$N%;%C%7%g%s(B ID$B$rMF0W$K?dB,!&:F8=2DG=$G$"$k(B

$B!!$@$=$&$G$9!#5-;vCf$G!"2~A1J}K!$,<($5$l$F$$$^$9!#(B

$B"#(B $B%Y%j%5%$%s$N(BSSL$B%5!<%P>ZL@=q$K(BMD2$B%"%k%4%j%:%`$,8=Lr(B
($B$G$s$7$c4Q;!%l%]!<%H(B, 2010.06.27)

$B!!(Bhttps://www2.kobayashi.co.jp/ $B$N>ZL@=q$O!VH/9TF|(B: 2010/03/11$B!W$@$1$I!">ZL@=q3,AX$r$?$I$C$F$$$/$H(B VeriSign Class 3 Primary Certification Authority $B$K$?$I$j$D$/!#$3$l$O(B MD2 $B$G=pL>$5$l$?%k!<%H>ZL@=q$G!"(BSSL$B%5!<%P>ZL@=q!"%3!<%I%5%$%K%s%0>ZL@=q$K$*$1$k(B $BG'>Z6I>ZL@=q(B($B%k!<%HG'>Z6I>ZL@=q!"Cf4VG'>Z6I>ZL@=q(B)$B$NJQ99!"$*$h$S%a%s%F%J%s%9$N$*CN$i$;(B ($B%Y%j%5%$%s(B, 2009.05.27 $B99?7(B) $B$G;H$o$l$J$/$J$C$?$O$:$8$c$J$+$C$?$N(B? $B$H$$$&OC!#NkLZ$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!$3$l$J$s$G$9$,!"(BImportant Update: VeriSign SSL, OFX and Code Signing Certificates moved to 1024-bit SHA-1 root as of May 17, 2009. (verisign, 2009.04.06) $B$H(B SSL$B%5!<%P>ZL@=q!"%3!<%I%5%$%K%s%0>ZL@=q$K$*$1$k(B $BG'>Z6I>ZL@=q(B($B%k!<%HG'>Z6I>ZL@=q!"Cf4VG'>Z6I>ZL@=q(B)$B$NJQ99!"$*$h$S%a%s%F%J%s%9$N$*CN$i$;(B ($B%Y%j%5%$%s(B, 2009.05.27 $B99?7(B) $B$N5-=R$,!"$J$s$@$+0c$&$_$?$$$J$s$G$9$h$M!#(B $BA0

How does VeriSign ensure that the new root CA Certificates and intermediates are trusted in browsers?
The new root CA "Class 3 Public Primary Certification Authority - G2" has existed since 1998, and as such is already embedded in the browsers. It simply was not used in the current hierarchy.

$B$H$J$C$F$$$F!"?7$7$$>ZL@=q$O(B Class 3 Public Primary Certification Authority - G2 $B$+$i$O$8$^$k3,AX$K$J$k$H$5$l$F$$$^$9!#$H$3$m$,(B SSL$B%5!<%P>ZL@=q!"%3!<%I%5%$%K%s%0>ZL@=q$K$*$1$k(B $BG'>Z6I>ZL@=q(B($B%k!<%HG'>Z6I>ZL@=q!"Cf4VG'>Z6I>ZL@=q(B)$B$NJQ99!"$*$h$S%a%s%F%J%s%9$N$*CN$i$;(B ($B%Y%j%5%$%s(B, 2009.05.27 $B99?7(B) $B$G$O!"(B

Q: $B:#2s$NJQ99$K$h$j!"%k!<%H>ZL@=q$HCf4V>ZL@=q$NN>J}$,JQ99$5$l$k$N$G$7$g$&$+!)(B
A: $B$O$$!"%k!<%HG'>Z6I>ZL@=q$HCf4VG'>Z6I>ZL@=q$NN>J}$H$bJQ99$K$J$j$^$9!#(B
$B!&%;%-%e%"!&%5!<%P(BID$B!"(B$B%3!<%I%5%$%K%s%0>ZL@=q(B
$B!JJQ998e$N%k!<%HG'>Z6I>ZL@=q!K(B Class 3 Public Primary Certification Authority - G2 [1024bit / sha1]

$B!&%0%m!<%P%k!&%5!<%P(BID$B!"%0%m!<%P%k!&%5!<%P(BID EV$B!"%0%m!<%P%k!&%5!<%P(BID EV for Mobile$B!"%;%-%e%"!&%5!<%P(BID EV$B!"(B $B%3!<%I%5%$%K%s%0>ZL@=q(B
$B!JJQ998e$N%k!<%HG'>Z6I>ZL@=q!K(B VeriSign Class 3 Public Primary Certification Authority [1024bit / sha1]

$B$H$J$C$F$$$F!"BgH>$O0MA3$H$7$F(B VeriSign Class 3 Public Primary Certification Authority $B$+$i$D$J$,$k$h$&$G$9!#$G!"$3$l$O(B SHA1 $B$8$c$J$/$F(B MD2 $B$N$h$&$J$N$G$9!#(B

$B!!:#5$$,$D$$$?$1$I!"(Bhttps://www.google.com/ $B$b(B VeriSign Class 3 Public Primary Certification Authority $B$N2<$K$"$k$h$&$G!#(B

$B!!$3$NB>$K$b!"(BVeriSign $B$O(B VeriSign 2048 bit Root Migration (VeriSign, 2010.01.20) $B$G(B RSA 2048bit $B2=(B (VeriSign Class 3 Secure Server CA - G3) $B$r?d?J$7$F$$$k0lJ}$G!"(B $B!Z$4Cm0U$/$@$5$$![(B KDDI$Be$N(B EZ$B%"%W%j(B(BREW) $B8~$1%5!<%S%9$K$*$$$F(B SSL$B%5!<%P>ZL@=q$r$4MxMQ$N>l9g$NCm0UE@(B ($B%Y%j%5%$%s(B, 2010.06.01) $B$J$s$FOC$,$"$k$=$&$G$9!#(B


$B"#(B 2010.06.25

$B"#(B $BDI5-(B

APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat


$B"#(B 2010.06.24

$B"#(B IPv6 Support in iOS 4
(SANS ISC, 2010.06.23)

$B!!(BiOS 4 $B$O(B IPv6 $B$KBP1~$7$F$$$k$N$@$=$&$G$9!#$=$l$O$$$$$N$G$9$,!"(B


$B"#(B 2010.06.23

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 6 $B7n$N%;%-%e%j%F%#>pJs(B

Thunderbird 3.0.5 $B%j%j!<%9%N!<%H(B

$B!!(BFirefox 3.6.4 $B$,%j%j!<%9$5$l$?$N$G!"%;%-%e%j%F%#%"%I%P%$%6%j$b8x3+$5$l$^$7$?!#(B

SA $BHV9f(B $B=EMWEY(B $B35MW(B
MFSA 2010-30$B:G9b(BXSLT $B%N!<%I$NJB$YBX$($K$*$1$k@0?t%*!<%P!<%U%m!<(B
MFSA 2010-29$B:G9b(BnsGenericDOMDataNode::SetTextInternal $B$K$*$1$k%R!<%W%P%C%U%!%*!<%P!<%U%m!<(B
MFSA 2010-26$B:G9b(B$B%a%b%jGK2u$N7A@W$,$"$k%/%i%C%7%e(B (rv:1.9.2.4/ 1.9.1.10)
MFSA 2010-25$B:G9b(B$B%9%3!<%W$N:.F1$K$h$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B

$B"#(B Firefox $B$N%;%-%e%j%F%#%"%C%W%G!<%H(B (3.5.10/3.6.4) $B8x3+!"(BFirefox 3.6.4 $B$O?7$?$K%/%i%C%7%eKI;_5!G=$rEk:\$7$^$7$?(B
(Mozilla Japan $B%V%m%0(B, 2010.06.23)

$B!!(BFirefox 3.6.4 / 3.5.10 $BEP>l!#(B7 $B7o(B / 9 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B MFSA 2010-25 $B$O(B Firefox 3.6.3 $B$G=$@5:Q!"(BMFSA 2010-27 $B$O(B Firefox 3.6.x $B$K$O1F6A$7$J$$!#(B

SA $BHV9f(B $B=EMWEY(B $B35MW(B
MFSA 2010-33$BDc(BMath.random() $B$r;HMQ$7$?%5%$%H4V$G$N%f!<%6%H%i%C%-%s%0(B
MFSA 2010-32$BCf(BContent-Type: multipart $B@_Dj;~$K(B Content-Disposition: attachment $B$,L5;k$5$l$k(B
MFSA 2010-31$BCf(Bfocus() $B$N5sF0$,%-!<%\!<%IA`:n$NCmF~$b$7$/$OO3$($$$K;HMQ$5$l$k(B
MFSA 2010-30$B:G9b(BXSLT $B%N!<%I$NJB$YBX$($K$*$1$k@0?t%*!<%P!<%U%m!<(B
MFSA 2010-29$B:G9b(BnsGenericDOMDataNode::SetTextInternal $B$K$*$1$k%R!<%W%P%C%U%!%*!<%P!<%U%m!<(B
MFSA 2010-28$B:G9b(B$B%W%i%0%$%s%$%s%9%?%s%94V$G$N2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B
MFSA 2010-27$B:G9b(BnsCycleCollector::MarkRoots() $B$K$*$1$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B
MFSA 2010-26$B:G9b(B$B%a%b%jGK2u$N7A@W$,$"$k%/%i%C%7%e(B (rv:1.9.2.4/ 1.9.1.10)
MFSA 2010-25$B:G9b(B$B%9%3!<%W$N:.F1$K$h$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B

$B!!%j%j!<%9%N!<%H(B:

$B!!$^$?!"(BFirefox 3.6.4 $B$K$OBTK>$N!"%5!<%I%Q!<%F%#@=%W%i%0%$%s$r(B Firefox $B$HJ,N%$9$k$3$H$K$h$j!"%5!<%I%Q!<%F%#@=%W%i%0%$%s$K$h$k%/%i%C%7%e$rKI;_$9$k5!G=$,

$B"#(B JVN#34729123: Explzh $B$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H
(JVN, 2010.06.22)

$B!!(BExplzh $B$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H (ponsoftware.com) $B$K$h$k$H!"(B

LZH $B=q8K$N3HD%%X%C%@$N%3%a%s%HIU$-(B LHA $B$N=hM}$G!"3F%U%!%$%k$XIU2C$5$l$?%3%a%s%H$N9g7WJ8;z$N%P%$%H?t$,(B 32KB $B0J>e$N>l9g$K%P%C%U%!!<%*!<%P!<%U%m!<$,H/@8$7$^$9!#(B

$B!!$J$s$@$+!"(BMHVI#20100425$B!'(B LZH $B=q8K$N%X%C%@!<=hM}$K$*$1$k@H $B$N$D$E$-$C$]$$$h$&$J!D!D!#(B

$B!!$7$+$b!"(B

$BK\@H $B0lO"$N(B LZH $B$N@H

$B!!$"$N!D!D!#(BJVNVU#545953: $BJ#?t$N%"%s%A%&%#%k%9@=IJ$K@H$B$O(B CERT-FI Advisory on Antivirus Signature Evasion Using Archive Files $B$N(B JVN $B7?HV$K2a$.$J$$>e!"%*%j%8%J%k(B (CERT-FI Advisory) $B$G$O(B $B!V(BZIP, CAB, GZIP, 7Z and RAR$B!W$,BP>]$J$N$G$9$+$i!"(B $B!V0lO"$N(B LZH $B$N@H

$B!!$J$*!"7g4Y$O(B Explzh Ver.5.63 $B$G=$@5$5$l$F$$$^$9!#(B CVE-2010-2434


$B"#(B 2010.06.22

$B"#(B APPLE-SA-2010-06-21-1 iOS 4
(Apple, 2010.06.21)

$B!!(BiOS 4 $BEP>l!#(B65 $BiOS 4 $B%=%U%H%&%'%"%"%C%W%G!<%H(B (Apple) $B$r;2>H!#(B

$B!!Dj0LCV$K$b=P$F$?(B: About the security content of iOS 4 (Apple, 2010.06.21)

$B"#(B Opera 10.54 for Windows changelog
(Opera.com, 2010.06.21)

$B!!(BOpera 10.54 for Windows / Mac $BEP>l(B$B!#N>%W%i%C%H%[!<%`$K6&DL$9$k(B 4 $B$D$N>\:YL$8x3+$N7g4Y$H!"(B Opera for Windows $B$K$N$_1F6A$9$k(B 1 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B $B9b66$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!!V(BOpera for Windows $B$K$N$_1F6A$9$k(B 1 $B$D$N7g4Y!W$O!"(B MS10-032 $B$G=$@5$5$l$F$$$k(B $B!V(BWin32k $B$N(B TrueType $B%U%)%s%H$N2r@O$N@HCVE-2010-1255$B!W(B $B$N7o$H;W$o$l!#K\

$B!!!V(B4 $B$D$N>\:YL$8x3+$N7g4Y!W$O!"(B

  • Fixed an extremely severe issue; details will be disclosed at a later date.
  • Fixed a highly severe issue; details will be disclosed at a later date.
  • Fixed a moderately severe issue; details will be disclosed at a later date.
  • Fixed a less severe issue; details will be disclosed at a later date.

$B!!(Bextremely severe issue $B$N=$@5(B (Windows / Mac $BN>J}(B) $B$,4^$^$l$F$$$k$=$&$J$N$G!"(BOpera $BMxMQ

$B!!(BOpera 10.54 for Mac changelog $B$K$O!"B?$/$N0BDj@-8~>e9`L\$b5-:\$5$l$F$$$k!#(B

2010.07.01 $BDI5-(B:

$B!!(B10.54 $B$G$N=$@59`L\$,8x3+$5$l$?!#!V(B4 $B$D$N>\:YL$8x3+$N7g4Y!W$O$3$&$$$&FbMF$@$C$?!#(B

  • Fixed an issue where Data URIs could be used to allow cross-site scripting; see our advisory (http://www.opera.com/support/search/view/955/).
  • Fixed an issue where unrestricted File I/O could be used by Widgets to execute arbitrary code; see our advisory (http://www.opera.com/support/search/view/962/).
  • Fixed an issue which could allow certain characters to be used for domain name spoofing; see our advisory (http://www.opera.com/support/search/view/961/).
  • Fixed an issue where file inputs could disclose the path to selected files; see our advisory (http://www.opera.com/support/search/view/960/).

$B"#(B 2010.06.21

$B"#(B Adobe InDesign CS3 INDD File Handling Buffer Overflow Vulnerability
(exploit-db.com, 2010.06.11)

$B!!(BAdobe InDesign CS3 $B$K7g4Y$,$"$j!"96N,(B .indd $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$r

# Vendor status:
#
# [16.09.2009] Vulnerability discovered.
# [09.03.2010] Vulnerability reported to vendor with sent PoC files.
# [21.03.2010] Asked confirmation from the vendor.
# [21.03.2010] Vendor asked for PoC files due to communication errors.
# [22.03.2010] Re-sent PoC files to vendor.
# [04.04.2010] Vendor confirms vulnerability.
# [03.06.2010] Vendor informs that they discontinued support for CS3 since CS5 is out.
# [04.06.2010] Public advisory released.

$B!!2?$3$l!D!D!#(BCVE-2010-2321

$B"#(B $B:#$3$=%1!<%?%$(BID$BLdBj$N2r7h$K8~$1$F(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2010.06.19)

$BF|K\$N%$%s%?!<%M%C%H$r=*N;$5$;$J$$$?$a$K!"$$$^$+$i!V$+$s$?$s%m%0%$%s!W$rE1GQ$7!"%m%0%$%s>uBV$N0];}$r(Bcookie$B$K$h$k

$B"#(B 2010.06.20


$B"#(B 2010.06.18

$B"#(B Bug 594921 - CVE-2010-1635, CVE-2010-1642 samba: denial of service vulnerabilities
(redhat.com, 2010.05.21)

$B!!(Bsamba < 3.4.8 / 3.5.2 $B$K$O!"(BDoS $B967b$r

$B!!(Bsamba 3.4.8 / 3.5.2 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B CVE-2010-2063: Memory Corruption Vulnerability (samba)
(samba.org, 2010.06.16)

$B!!(Bsamba 3.0.x$B!A(B3.3.12 $B$K7g4Y!#(BSMB1 $B%Q%1%C%H$N=hM}$K7g4Y$,$"$j!"96N,%Q%1%C%H$K$h$C$F%5!<%P!<$,(B crash $B$9$k!#G$0U$N%3!<%I$NCVE-2010-2063

$B!!(Bsamba 3.3.13 $B$G=$@5$5$l$F$$$k!#(Bsamba 3.4.x $B0J9_$K%"%C%W%0%l!<%I$7$F$b$h$$!#(B

2010.06.20 $BDI5-(B:

$B!!(BSamba 3.3.12 Memory Corruption Vulnerability (iDefense, 2010.06.16)

$B"#(B SYM10-008: Symantec Workspace Streaming $B$KIT@5%@%&%s%m!<%I$N@H
($B%7%^%s%F%C%/(B, 2010.06.16)

$B!!(BSymantec AppStream 5.2.x / Symantec Workspace Streaming 6.1.x $B$K7g4Y!#(B $B!V(BSymantec Workspace Streaming $B%/%i%$%"%s%H$,%5!<%P!<>e$N%U%!%$%k$r%@%&%s%m!<%I$9$kA0$K!"%5!<%P!<$rE,@Z$KG'>Z!W$7$J$$$?$a!"96N,(B Workspace Streaming $B%5!<%P!<$K@\B3$9$k$H!"G$0U$N%U%!%$%k$,%@%&%s%m!<%I$5$l$k!#(BCVE-2008-4389$B!#$C$F!"(B2 $BG/A0$N7g4Y$J$N(B?

$B!!(BSymantec Workspace Streaming 6.1 SP4 $B$G=$@5$5$l$F$$$k!#(B Symantec AppStream 5.2.x $B$K$D$$$F$O!"(BSymantec Workspace Streaming 6.1 $B$K%"%C%W%0%l!<%I$7$?>e$G(B SP4 $B$rE,MQ$9$k!#(B

$B"#(B Thunderbird 3.0.5 $B%j%j!<%9%N!<%H(B
(mozilla.jp, 2010.06.18)

$B!!(BThunderbird 3.0.5 $BEP>l!#%;%-%e%j%F%#=$@5$,4^$^$l$F$$$kLOMM$@$,!"(B

$B%;%-%e%j%F%#%"%I%P%$%6%j$O(B Firefox 3.6.4 $B$N%j%j!<%9$K9g$o$;$F8eF|8x3+$H$J$j$^$9!#(B

2010.06.23 $BDI5-(B:

$B!!(BFirefox 3.6.4 $B$,%j%j!<%9$5$l$?$N$G!"%;%-%e%j%F%#%"%I%P%$%6%j$b8x3+$5$l$^$7$?!#(B

SA $BHV9f(B $B=EMWEY(B $B35MW(B
MFSA 2010-30$B:G9b(BXSLT $B%N!<%I$NJB$YBX$($K$*$1$k@0?t%*!<%P!<%U%m!<(B
MFSA 2010-29$B:G9b(BnsGenericDOMDataNode::SetTextInternal $B$K$*$1$k%R!<%W%P%C%U%!%*!<%P!<%U%m!<(B
MFSA 2010-26$B:G9b(B$B%a%b%jGK2u$N7A@W$,$"$k%/%i%C%7%e(B (rv:1.9.2.4/ 1.9.1.10)
MFSA 2010-25$B:G9b(B$B%9%3!<%W$N:.F1$K$h$k2rJ|:Q$_%*%V%8%'%/%H$N:F;HMQ(B

$B"#(B 2010.06.17

$B"#(B $BEEGH%A%'%C%+!<$N@H
($B?eL57n$P$1$i$N$($SF|5-(B, 2010.06.12)

$B!!(B$BEEGH%A%'%C%+!<(B$B$O!"8=:_BP1~Cf$N$h$&$G!#(B

$B$*CN$i$;(B
$BIT@5%W%m%0%i%`$r;HMQ$9$k$3$H$G!"JL$N(BiPhone$B$GEPO?$7$?7WB,7k2L!JEEGH>u67$H$=$N0LCV>pJs!K$,CO?^$KI=<($5$l$k2DG=@-$,$"$j$^$9$?$a!">pJs$NJ]8n$rBh0l$H$7$F0BA4@-$,3NG'$9$k$^$G4V!"EPO?$$$?$@$$$?>pJs$NI=<($rDd;_$5$;$F$$$?$@$-$^$9!#(B

$B"#(B About the security content of iTunes 9.2
(apple, 2010.06.16)

$B!!(BiTunes 9.2 $BEP>l!#(BWindows $BHG$G$N$_!"0J2<$N7g4Y$,=$@5$5$l$F$$$k!#(B

  • embedded ColorSync profile $BCf$N2hA|$N=hM}$K7g4Y$,$"$j!"96N,2hA|$K$h$C$FG$0U$N%3!<%I$rCVE-2009-1726

  • TIFF $B%U%!%$%k$N=hM}$K7g4Y$,$"$j!"96N,(B TIFF $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2010-1411

  • Safari 5.0 / 4.1 $B$G=$@5$5$l$?!"BgNL$N(B WebKit $B$N7g4Y$r(B iTunes $B$G$b=$@5!#(B

$B!!4XO"(B: $B!V(BiTunes 9.2$B!W8x3+!"(BiPhone 4/iOS 4/iBooks 1.1$B$KBP1~(B (Internet Watch, 2010.06.17)$B!#Nc$K$h$C$F%;%-%e%j%F%#=$@5$K$O?($l$:!#(B


$B"#(B 2010.06.16

$B"#(B $BDI5-(B

$B"#(B Host Data Loss Prevention 3.0 / 9.0 $B$GH/8+$5$l$?(B HTTP $B$N@H
($B%^%+%U%#!<(B, 2010.06.15)

$B!!(BHost Data Loss Prevention (HDLP) 3.0 / 9.0 $B$K7g4Y!#(B HDLP Agent $B$K7g4Y$,$"$j!"%-%c%W%A%c$7$?%G!<%?$,30It$KO31L$7$?$j!"%j%b!<%H$+$i%m!<%+%k%U%!%$%k$K%"%/%;%9$G$-$?$j$9$kLOMM!#(B

$B!!(BHDLP Agent 3.0.100.10 / 9.0.0.421 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

$B"#(B Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player
(Adobe, 2010.06.15)

$B!!(B$B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-004$B!?(BMac OS X v10.6.4 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B (Apple, 2010.06.15) $B$rE,MQ$9$k$H!"(B Flash Player $B$,Bg7j$D$-$N%P!<%8%g%s$KLa$C$F$7$^$&$N$GCm0U!"$H$$$&OC!#E,MQ8e$K!"I,$:(B Flash Player $B$r(B 10.1.53.64 $B$K99?7(B$B$7$^$7$g$&!#(B ($BBg13$@$C$?$N$G"-$K=q$-$J$*$7(B: tss_0101 $B$5$s46

$B!!(B$B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-004$B!?(BMac OS X v10.6.4 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B (Apple, 2010.06.15) $B$K$O8E$$%P!<%8%g%s$N(B Flash Player $B$,4^$^$l$F$$$k$N$GCm0U$7$F$M$H$$$&OC!#4{$K:G?7HG$K%"%C%W%G!<%H$5$l$F$$$k>l9g$O!">e=q$-$5$l$k$3$H$O$J$$$_$?$$$@$1$I!"G0$N$?$a%P!<%8%g%s$r3NG'$7$F$M!"$@$=$&$G!#(B http://www.adobe.com/software/flash/about/ $B$K%"%/%;%9$7$F$_$^$;$&!#(B

$B"#(B $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-004$B!?(BMac OS X v10.6.4 $B$N%;%-%e%j%F%#%3%s%F%s%D$K$D$$$F(B
(Apple, 2010.06.15)

$B!!(BMac OS X 10.6.4 / $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-004 (Mac OS X 10.5.8 $BMQ(B) $B$,8x3+$5$l$F$$$k!#$N$O$$$$$N$@$,!"(B

Flash Player $B%W%i%0%$%s(B

CVE-ID$B!'(BCVE-2010-0186$B!"(BCVE-2010-0187

$BBP>]$H$J$k%P!<%8%g%s!'(BMac OS X v10.5.8$B!"(BMac OS X Server v10.5.8$B!"(BMac OS X v10.6 $B!A(B v10.6.3$B!"(BMac OS X Server v10.6 $B!A(B v10.6.3

$B1F6A!'(BAdobe Flash Player $B%W%i%0%$%s$KJ#?t$N@H
$B@bL@!'(BAdobe Flash Player $B%W%i%0%$%s$KJ#?t$NLdBj$,B8:_$7!"$b$C$H$b?<9o$J>l9g$O!"L$>5G'$N%/%m%9%I%a%$%s%j%/%(%9%H$,\$7$/$O!"(BAdobe $BH$7$F$/$@$5$$!#(B

$B!!Bg7j$D$-$N%P!<%8%g%s$K%"%C%W%G!<%H$7$F$I$&$9$k$h(B Apple$B!D!D!#(B $B$H$$$&$o$1$G!"(BMac OS X 10.6.4 / $B%;%-%e%j%F%#%"%C%W%G!<%H(B 2010-004 $BE,MQ8e$9$0$K!"(B Flash Player $B$r(B 10.1.53.64 $B$K99?7(B$B$7$^$7$g$&!#(B $B4{$K(B FLash Player $B$r%"%C%W%G!<%H:Q$N>l9g$O!"$=$l$,>e=q$-$5$l$k$3$H$O$J$$$_$?$$$@$1$I!"G0$N$?$a(B http://www.adobe.com/software/flash/about/ $B$G%P!<%8%g%s$r3NG'$7$^$;$&!#(B $B4XO"(B: Apple Security Update 2010-004 / Mac OS X v10.6.4 Shipping with Outdated Version of Adobe Flash Player (Adobe, 2010.06.15)


$B"#(B 2010.06.15

$B"#(B JVN#67120749: ActiveGeckoBrowser $B$K$*$1$kJ#?t$N@H
(JVN, 2010.06.14)

$B"#(B $BDI5-(B

$B"#(B MHVI#20100425$B!'(B LZH $B=q8K$N%X%C%@!<=hM}$K$*$1$k@H
(Micco's HomePage, 2010.04.25)

$B!!(BLZH $B=q8K$K!VBP1~!W$7$F$$$kJ#?t$N%"%s%A%&%$%k%9%=%U%H$K$*$$$F!"(BLZH $B=q8K$X$NBP1~$,IT==J,$J$?$a!"FCDj$N7A<0$N(B LZH $B=q8K$rG'<1$G$-$:!"7k2L$H$7$F(B LZH $B=q8KFb$N%&%$%k%9$r8+F($7$F$7$^$&!#J!8w$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BLZH $B=q8K$,FCDj$N7A<0$N%X%C%@$r;}$C$F$$$k>l9g$K!"0[>o$@$HH=CG$7$F=hM}$r9T$o$J$$$?$a$KH/@8$9$kLOMM!#$3$Ne$KE83+%$%a!<%8$,:n@.$5$l$k$h$&$J=hM}!W$GLdBj$H$J$k$=$&$@!#6qBNE*$K$O!"

$B%X%C%@!<7A<0(B $B8+F($7$,H/@8$9$k@=IJNc(B
4KB $B$rD6$($k3HD%%X%C%@!<(B ESET NOD32 Antivirus 4 4.0.474.9
4KB $B$rD6$($k%X%C%@!<(B Norton Internet Security 2010 17.6.0.32
$B%&%$%k%9%P%9%?!<(B 2010 17.50.1647.0000
McAfee $B%"%s%A%&%$%k%9(B $B%W%i%9(B 2010 13.15.117
Virus Security ZERO 10.0.0058
avast! Free Antivirus 5.0.507
$B%X%C%@!<(B CRC $B$H@09g$7$J$$%X%C%@!<(B $B%&%$%k%9%P%9%?!<(B 2010 17.50.1647.0000
McAfee $B%"%s%A%&%$%k%9(B $B%W%i%9(B 2010 13.15.117
CA Anti-Virus r8.1 8.1.660.0
h2 $B7A<0$N%X%C%@!<(B (h2 $B7A<0$N=q8K(B) CA Anti-Virus r8.1 8.1.660.0

$B!!F1MM$NLdBj$O(B ARJ $B=q8K$N=hM}$K$*$$$F$bB8:_$9$k$=$&$@!#(B

$B%X%C%@!<7A<0(B $B8+F($7$,H/@8$9$k@=IJNc(B
$B4pK\%X%C%@!<$,Ls(B 2.5KB $B$rD6$($k%X%C%@!<(B McAfee $B%"%s%A%&%$%k%9(B $B%W%i%9(B 2010 13.15.117
$B4pK\%X%C%@!<$,(B 2.3KB $B$rD6$($k%X%C%@!<(B Microsoft Security Essentials 1.0.1961.0
$B%&%$%k%9%P%9%?!<(B 2010 17.50.1647.0000
F-Secure Anti-Virus 2010 10.00
AVG Anti-Virus Free 9.0.716
Norton Internet Security 2010 17.6.0.32
$B%X%C%@!<(B CRC $B$H@09g$7$J$$%X%C%@!<(B Microsoft Security Essentials 1.0.1961.0
$B%&%$%k%9%P%9%?!<(B 2010 17.50.1647.0000
F-Secure Anti-Virus 2010 10.00
AVG Anti-Virus Free 9.0.716
$B%X%C%@!$,5-O?$5$l$F$$$k(B F-Secure Anti-Virus 2010 10.00

$B!!(BMicco $B$5$s$O!"(BNorton Internet Security 2010 17.6.0.32 $B$K$D$$$F$O!"(B $B4pK\%X%C%@!<$,(B 2.3KB $BL$K~$G$bH/@8$9$k$HJ,N`$7$F$$$^$9$,!"e5-$G$O!V4pK\%X%C%@!<$,(B 2.3KB $B$rD6$($k%X%C%@!

$B!!$5$F!">e5-$N7g4Y$K$D$$$F!"(BIPA $B$,@He$N?75,3+H/$O9T$o$J$$$3$H$K$7$?!"$H$$$&$3$H$,OCBj$K$J$C$F$$$^$9(B: $B!X(BLHA $B$N@H (Micco's HomePage, 2010.06.02)$B!#:G=*E*$K$O!"(B

Jun.7,2010 $BDI5-(B

$B!!1g8npJs$H$7$F07$&7A$KMn$ACe$$$?$h$&$G$9!#(B $B$$$d!$(B $B3N$+$K85!9!V;29M>pJs$H$7$F07$&(B ($B2?$N$H$O<($5$l$F$$$J$$!#(B)$B!W$H$OJ9$$$F$$$^$7$?$1$l$I!#(B $B$=$l$O$H$b$+$/!$(B CVE-2010-0098 $B$KD>@\7k$S$D$$$?(B JVNVU#545953 $B$K>pJsDI2C$7$?$N$G$O!$(B $B%Y%s%@!<$r4^$a$F:.Mp$9$k$@$1$N$h$&$J5$$,$7$J$$$G$b!D!#(B $B$H$j$"$($:$OMM;R8+$G$9$M!#(B

$B$@$=$&$J$N$G$9$,!"(B

$B!!$5$i$K!"(BVector $B$,$3$s$JH/I=$r$7$F$$$^$9(B: UNLHA32.DLL$BEy$N3+H/Cf;_$HJ@ (Vector, 2010.06.07)$B!#%j%M!<%8%e;qNA<<$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$BJ@

$B!!$=$7$F

$B3t<02qu67$KBP$7$FJ@e5-4|F|$G$N(B
$B!!!!EPO?Dd;_$NBP>]30$H$5$;$F$$$?$@$-$^$9!#(B
$B!!!!>\$7$/$O2<5-!VEPO?Dd;_$NGX7J!&>\:Y$H$4BP1~J}K!$K$D$-$^$7$F!W(B
$B!!!!$r$4Mw$/$@$5$$!#(B

$B!!!|8=:_!"J@7A<0$X$NJQ99$r$*4j$$$9$k$b$N$G$O$"$j$^$;$s!#(B
$B!!!!?75,!&:9$7BX$(!&DI2CEPO?;~$N=q8K7A<0$H$7$F(BLZH$B0J30$N$b$N$r(B
$B!!!!$*;H$$$$$?$@$/$h$&$*4j$$$9$k$b$N$G$9!#(B

$B%i%$%V%i%j:ne$2$^$9!#(B


======================================================================
$B"#EPO?Dd;_$NGX7J!&>\:Y$H$4BP1~J}K!$K$D$-$^$7$F(B
======================================================================

$B8=:_(B UNLHA32.DLL $BEy$N:n)$7$J$$$3$H!W(B
$B5Z$S!V3+H/$NDd;_0U8~I=L@!W$,$J$5$l$^$7$?!#(B

$B!!(Bhttp://www2.nsknet.or.jp/~micco/notes/ann.htm
$B!!(Bhttp://www2.nsknet.or.jp/~micco/incidents/2010/inci1006.htm
$B!!!J$?$@$7(B6$B7n(B7$BF|$NDI5-$K$h$j!"B?>/>u67$NJQ2=$,$"$j$^$9!K(B

$B$3$l$K$H$b$J$$!"J@l9g$K$O!";j5^(BZIP$BEy(B
$B$NB>$N7A<0$G:n@.$7$F$$$?$@$-$^$9$h$&$*4j$$$$$?$7$^$9!J4{B8$N%U%!%$%k$N(B
$B7A<0JQ99$@$1$K$h$k:9$7BX$($NI,MW$O$"$j$^$;$s!K!#(B

LZH$B$N<+8JE83+7A<0$G%$%s%9%H!<%i!<$H$7$F;HMQ$7$F$$$k$J$I$N>l9g!"B>$N(B
$B7A<0$X$NJQ99$OF0:n4D6-$N3NG'$J$I$K;~4V$,I,MW$+$H;W$o$l$^$9$N$G!":n6H$,(B
$B40N;]$+$i$O30$5$;$F$$$?$@$-$^$9!#(B

$B"(%"!<%+%$%P!<$=$N$b$N$NFbIt7A<0$,(BLZH$B$N$b$N5Z$S(BLZH$B$N<+8JE83+7A<0$r:n@.(B
$B!!$G$-$k%"!<%+%$%P!<$,BP>]$G$9!#(BWinRAR$B$N$h$&$K(BLZH$B7A<0$K0MB8$7$F$$$J$$(B
$B!!$b$N$O$=$b$=$b8x3+Dd;_$NBP>]$G$O$"$j$^$;$s!#(B

---
($B3t(B)$B%Y%/%?!<(B $B%a%G%#%"It(B vector@vector.co.jp
 - $B$40FFb(B http://www.vector.co.jp/info/web_form/webform_info.html
 - FAQ    http://www.vector.co.jp/for_authors/upload/faq.html

$B!!(BVector $B$NH?1~$O7c$7$9$.$k$H;W$&$1$I!D!D!#(B

$B!!$"$H!"(BIPA$B$N$;$$$G(BUNLHA32.DLL$B$,3+H/Dd;_!"$N8m2r(B ($B?eL57n$P$1$i$N$($SF|5-(B, 2010.06.07) $B$G$9$,!"(BIPA $B$,?75,0F7o$H$7$F

$B3N$+$KLdBj$,$"$k$H8@$($P$"$j$^$9$,!"$=$l$[$I=EBg$JLdBj$G$7$g$&$+!#$?$H$($P!"%H%l%s%I%^%$%/%m$N(BInterScan$B$O%a!<%k$KE:IU$5$l$?(BZIP$B%U%!%$%k$r%A%'%C%/$7$^$9$,!"%Q%9%o!<%I$,$D$$$F$$$?$j!"Cf?H$N%U%!%$%k$,(B100$B8D0J>e$"$C$?$j$9$k$H!"!V%A%'%C%/$G$-$J$+$C$?!W$H$$$&7Y9p%a%C%;!<%8$r;D$7$D$D$b%a!<%k$ODL$7$F$7$^$$$^$9!#(B

$B!!0BA4B&$KE]$l$k$N$G$"$l$P!"!V8!>Z$G$-$J$+$C$?$b$N$K$D$$$F$O%5!<%P$G;_$a$k!W$H$$$&%*%W%7%g%s$,$[$7$$$H$3$m$G$7$g$&!#(B


$B"#(B 2010.06.14


$B"#(B 2010.06.13


$B"#(B 2010.06.12


$B"#(B 2010.06.11

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2219475) Windows $B$N%X%k%W$H%5%]!<%H(B $B%;%s%?!<$N@H
(Microsoft, 2010.06.11)

$B!!(BWindows XP / Server 2003 $B$K(B 0-day $B7g4Y!#(B[Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly (Full-disclosure ML, 2010.06.10) $B$N7o!#!V(BHCP $B%W%m%H%3%k$NEPO?$r2r=|$9$k!W$3$H$G2sHr$G$-$k!#(B

$B!!4XO"(B: Help and Support Center vulnerability full-disclosure posting (Microsoft Security Research & Defense, 2010.06.10)$B!"(B CVE-2010-1885

2010.06.15 $BDI5-(B:

$B!!(BMicrosoft Fix it $B=P$^$7$?(B: Microsoft KB 2219475$B!#(B

2010.06.16 $BDI5-(B:

$B!!(Bin the wild $B$K$J$C$?LOMM$G$9!#(B

2010.06.28 $BDI5-(B:

$B!!(BWindows $B$N%X%k%W$H%5%]!<%H%;%s%?!<$NL$=$@5$N@H (JPCERT/CC, 2010.06.28)

2010$BG/(B6$B7n(B28$BF|!"(BJPCERT/CC $B$G$O!V$$$o$f$k(BGumblar $B%&%$%k%9!W$K$h$k(BWeb $B%5%$%H2~$6$s967b$K$*$$$FK\@H

2010.06.29 $BDI5-(B:

$B!!4XO"(B:

$B!!=$@5$K;~4V$,$+$+$j$9$.$k$H$$$&LdBj$,$"$k$o$1$G!#(B

2010.07.01 $BDI5-(B:

$B!!(BAttacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885) (Microsoft Malware Protection Center, 2010.06.30)

2010.07.16 $BDI5-(B:

$B!!(BMS10-042 - $B6[5^(B: $B%X%k%W$H%5%]!<%H(B $B%;%s%?!<$N@H (Microsoft) $B$G=$@5$5$l$^$7$?!#(B

$B"#(B $B$$$m$$$m(B (2010.06.11)
(various)

2010.06.16 $BDI5-(B:

$B!!(BMultiple vulnerabilities in Wireshark version 0.8.20 to 1.0.13 (wireshark.org, 2010.06.09)$B!#(BWireshark 1.2.9 / 1.0.14 $B$G$O(B 5 $B7o$N7g4Y$,=$@5$5$l$F$$$^$9!#(B

$B"#(B $BDI5-(B

APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat

$B!!(BFlash Player $B$H(B Adobe Air $B$N(B fix $B=P$^$7$?(B: APSB10-14: Security update available for Adobe Flash Player (adobe, 2010.06.10)$B!#(BFlash Player 10.1.53.64 / 9.0.277.0$B!"(BAir 2.0.2.12610 $B$G=$@5$5$l$F$$$^$9!#(B

$B!!$J$*!"(BSolaris $BMQ$N(B Flash Player 10.1 $B$O$^$@@5<0%j%j!<%9$5$l$F$^$;$s!#(B 10.1 RC $B$GN?$.$^$7$g$&!#(B

$B!!$7$+$7!"=$@50lMw$,$9$4$$$J$"!#(B

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1297).
Note: There are reports that this issue is being actively exploited in the wild.

This update resolves a memory exhaustion vulnerability that could lead to code execution (CVE-2009-3793).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2160).

This update resolves an indexing vulnerability that could lead to code execution (CVE-2010-2161).

This update resolves a heap corruption vulnerability that could lead to code execution (CVE-2010-2162).

This update resolves multiple vulnerabilities that could lead to code execution (CVE-2010-2163).

This update resolves a use after free vulnerability that could lead to code execution (CVE-2010-2164).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2165).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2166).

This update resolves multiple heap overflow vulnerabilities that could lead to code execution (CVE-2010-2167).

This update resolves a pointer memory corruption that could lead to code execution (CVE-2010-2169).

This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2010-2170).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2171).

This update resolves a denial of service issue on some UNIX platforms (Flash Player 9 only) (CVE-2010-2172).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2173).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2174).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2175).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2176).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2177).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2178).

This update resolves a URL parsing vulnerability that could lead to cross-site scripting (Firefox and Chrome browsers only) (CVE-2010-2179).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2180).

This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2010-2181).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2182).

This update resolves a integer overflow vulnerability that could lead to code execution (CVE-2010-2183).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2184).

This update resolves a buffer overflow vulnerability that could lead to code execution (CVE-2010-2185).

This update resolves a denial of service vulnerability that can cause the application to crash. Arbitrary code execution has not been demonstrated, but may be possible. (CVE-2010-2186).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2187).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2189).
Note: This issue occurs only on VMWare systems with VMWare Tools enabled.

This update resolves a denial of service issue (CVE-2008-4546).

$B!!4XO"(B: Adobe Flash Player $B$*$h$S(B Adobe Acrobat/Reader $B$N@H (JPCERT/CC, 2010.06.11)


$B"#(B 2010.06.10

$B"#(B Microsoft 2010 $BG/(B 6 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2010.06.09)

$B!!M=Dj$I$*$j=P$^$7$?!#(B

MS10-032 - $B=EMW(B: Windows $B%+!<%M%k(B $B%b!<%I(B $B%I%i%$%P!<$N@H:3J$5$l$k(B (979559)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B%+!<%M%k$K(B 3 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B

MS10-033 - $B6[5^(B: $B%a%G%#%"2rE`$N@H

MS10-034 - $B6[5^(B: ActiveX $B$N(B Kill Bit $B$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (980195)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B2 $B$D$N(B ActiveX $B%3%s%H%m!<%k$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • Microsoft Data Analyzer $B$N(B ActiveX $B%3%s%H%m!<%k$N@HCVE-2010-0252

  • Microsoft Internet Explorer 8 Developer Tools $B$N@HCVE-2010-0811

MS10-035 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (982381)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BIE 5.01 / 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B%/%m%9(B $B%I%a%$%s$N>pJsO3$($$$N@HCVE-2010-0255

    Exploitability Index: 2

    $B4XO"(B: MS10-035: Cross-Domain Information Disclosure Vulnerability (Microsoft Security Research & Defense, 2010.06.08)

  • toStaticHTML $B$N>pJsO3$($$$N@HCVE-2010-1257

    Exploitability Index: 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-1259

    Exploitability Index: 1

  • HTML $BMWAG$N%a%b%jGKB;$N@HCVE-2010-1260

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-1261

  • $B%a%b%jGKB;$N@HCVE-2010-1262

    Exploitability Index: 1

MS10-036 - $B=EMW(B: Microsoft Office $B$N(B COM $B$N8!>Z$N@H

MS10-037 - $B=EMW(B: OpenType Compact Font Format (CFF) $B%I%i%$%P!<$N@H:3J$5$l$k(B (980218)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BOpenType Compact Font Format (CFF) $B%I%i%$%P!<$K7g4Y$,$"$j!"(B local user $B$K$h$k8"8B>e>:$r>7$/!#(BCVE-2010-0819

$B!!(BExploitability Index: 2

MS10-038 - $B=EMW(B: Microsoft Office Excel $B$N@H

$B!!(BExcel 2002 / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BExcel Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K!"7W(B 14 $B8D$N7g4Y!#(B

  • Excel $B%l%3!<%I2r@O$N%a%b%jGKB;$N@HCVE-2010-0821

    Exploitability Index: 2

  • Excel $B%*%V%8%'%/%H$N%9%?%C%/(B $B%*!<%P!<%U%m!<$N@HCVE-2010-0822

    Exploitability Index: 1

  • Excel $B$N%a%b%jGKB;$N@HCVE-2010-0823

    Exploitability Index: 2

  • Excel $B%l%3!<%I$N%a%b%jGKB;$N@HCVE-2010-0824

    Exploitability Index: 1

  • Excel $B%l%3!<%I$N%a%b%jGKB;$N@HCVE-2010-1245

    Exploitability Index: 1

  • Excel $B$N(B RTD $B%a%b%jGKB;$N@HCVE-2010-1246

    Exploitability Index: 1

  • Excel $B$N%a%b%jGKB;$N@HCVE-2010-1247

    Exploitability Index: 1

  • Excel HFPicture $B$N%a%b%jGKB;$N@HCVE-2010-1248

    Exploitability Index: 1

  • Excel $B$N%a%b%jGKB;$N@HCVE-2010-1249

    Exploitability Index: 1

  • Excel $B$N(B EDG $B%a%b%jGKB;$N@HCVE-2010-1250

    Exploitability Index: 1

  • Excel $B$N%l%3!<%I(B $B%9%?%C%/GKB;$N@HCVE-2010-1251

    Exploitability Index: 2

  • Excel $B$N(B $BJ8;zNsJQ?t$N@HCVE-2010-1252

    Exploitability Index: 2

  • Excel $B$N(B ADO $B%*%V%8%'%/%H$N@HCVE-2010-1253

    Exploitability Index: 1

  • Mac Office Open XML $B$N%"%/%;%95v2D$N@HCVE-2010-1254

    Exploitability Index: 1

MS10-039 - $B=EMW(B: Microsoft SharePoint $B$N@H:3J$5$l$k(B (2028554)

$B!!(BInfoPath 2003 / 2007$B!"(BSharePoint Server 2007$B!"(BSharePoint Services 3.0 $B$K(B 3 $B$D$N7g4Y!#(B

MS10-040 - $B=EMW(B: $B%$%s%?!<%M%C%H(B $B%$%s%U%)%a!<%7%g%s(B $B%5!<%S%9$N@H

MS10-041 - $B=EMW(B: Microsoft .NET Framework $B$N@H

$B!!(B.NET Framework 1.0 / 1.1 / 2.0 / 3.5 $B$K7g4Y!#(B W3C XML $B=pL>$N9=J8$*$h$S=hM}(B (XMLDsig) $B$N?d>):v$N$5$l$?(B XML $B%3%s%F%s%D$r2~$6$s$G$-$k!#(B CVE-2009-0217$B!#(B $B$J$*!"(B .NET Framework 3.0 / 4.0 $B$*$h$S!"(B Vista SP2 / Server 2008 SP2 + .NET Framework 3.5 $B$N>l9g$K$O7g4Y$,$J$$!#(B

$B!!(BExploitability Index: 3

$B!!4XO"(B: MS10-041: XML Signature HMAC Truncation Bypass Vulnerability (Microsoft Security Research & Defense, 2010.06.08)

2010.06.16 $BDI5-(B:

$B!!(BMS10-036 - $B=EMW(B: Microsoft Office $B$N(B COM $B$N8!>Z$N@H $B$G$O(B Office XP $BMQ$N=$@5$,9T$o$l$F$$$J$$!#(B KB 983235 $B$K(B Microsoft Fix it $B$,7G:\$5$l$F$$$k$N$G!"$3$l$rE,MQ$7$h$&!#(B

2010.06.23 $BDI5-(B:

$B!!(BMS10-041 - $B=EMW(B: Microsoft .NET Framework $B$N@H $B$N(B .NET Framework 1.1 SP1 $BMQ(B patch $B$r%$%s%9%H!<%k$7$h$&$H$9$k$H!"(B $B8E$$%P!<%8%g%s$N%"%s%A%&%$%k%9%=%U%H$,H?1~$7$F$7$^$&$3$H$,$"$kLOMM!#(B

2010.07.02 $BDI5-(B:

$B!!(B$B%^%$%/%m%=%U%H&IJ$X$N1F6A$K$D$$$F(B ($BIY;N%<%m%C%/%9(B, 2010.07.02)$B!#(BApeosWare $BJ}LL$GIT6q9g$,=P$kLOMM!#(B $B2sHr%D!<%k$,8x3+$5$l$F$$$k!#(B

$BK\8=>]$r2sHr$9$k$?$a$N%D!<%k$rDs6!$$$?$7$^$9!#(B
$BBP>]>&IJ$N$4;HMQ;~$KK\%D!<%k$r&IJ$,@5>o$K5/F0$G$-$k$h$&$K$J$j$^$9(B($BL58z2=$5$l$?5!G=$r0l;~E*$KM-8z$K$7$^$9(B)$B!#(B
$B%D!<%k$O>&IJ$4;HMQ$NETEY!"Kh2s $B$J$*!"K\%D!<%k$O!"%^%$%/%m%=%U%HpJs$r$b$H$K:n@.$7$F$$$^$9!#(B

2010.09.03 $BDI5-(B:

$B!!(B$B%^%$%/%m%=%U%H&IJ$X$N1F6A$K$D$$$F(B ($BIY;N%<%m%C%/%9(B, 2010.09.01 $B99?7(B)$B!#(BApeosWare $BB&$G$NBP1~$,$h$&$d$/40N;!#(B

$B"#(B $BDI5-(B


$B"#(B 2010.06.09

$B"#(B Google Chrome Stable Channel Update
(Google Chrome Release blog, 2010.06.08)

$B!!(BGoogle Chrome 5.0.375.70 $BEP>l!#(B$2000 $B5i$r4^$`!"(B11 $B

$B"#(B $BDI5-(B


$B"#(B 2010.06.08

$B"#(B $BDI5-(B

APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat

$B!!(B APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat (Adobe) $B$,2~D{$5$l$?!#(B

  • Windows / Mac / Linux $BHG(B Flash Player 10.x $B$K$D$$$F$O!"(B 2010.06.10 $B$K=$@5HG$r8x3+M=Dj!#(B

  • Solaris $BHG(B Flash Player 10.x $B$K$D$$$F$O!"L$Dj!#(B

  • Windows / Mac / Linux $BHG(B Adobe Reader / Acrobat 9.x $B$K$D$$$F$O!"(B 2010.06.29 $B$K=$@5HG$r8x3+M=Dj!#(B $B4XO"(B: Background on APSA10-01 Patch Schedule (Adobe, 2010.06.07)

$B"#(B About the security content of Safari 5.0 and Safari 4.1
(Apple, 2010.06.07)

$B!!(BSafari 5.0 (Windows / Mac OS X 10.5 / 10.6)$B!"(BSafari 4.1 (Mac OS X 10.4) $BEP>l!#BgNL$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$k!#B?$/$O(B WebKit $B$N7g4Y!#(B

$B!!(Bhttp://www.apple.com/jp/safari/ $B$O$^$@(B Safari 4 $B$K$J$C$F$$$k$,!"%@%&%s%m!<%I%j%s%/$r$?$I$k$H(B Safari 5 $B$,=P$F$/$k!#(B


$B"#(B 2010.06.07

$B"#(B $BDI5-(B


$B"#(B 2010.06.06

  • $B!U(B $B%&%k%H%i%;%V%s(B $BBh(B12$BOC!VM7@1$h$j0&$r$3$a$F!W(B$B!#(B $BNc$N!VIu0u:nIJ!W!#(B

    • $B%&%k%H%i%;%V%s(B12$BOC!VM7@1$h$j0&$r$3$a$F!W(B ($B8+3X>&Gd(B, 2005.11.23)$B!#(BFLASH 2008.11.22 $B9f$K!VAmNO%k%]!*!!$J$

      $B$=$7$F$3$N5-;v$NL\6L$O!"935D$N!HH/CW7bE*$@$C$?!#<+J,$b%&%k%H%i%;%V%s$N%U%!%s$H$7$F!";a$rE($N$h$&$K9M$($F$$$?$N$G!"?=$7Lu$J$$5$;}$A$K$J$C$?!#(B

      $B5-;v$O!"!V935D$5$l$k$N$,LLE]!W$H$P$+$j$K:nIJ$r$J$-$b$N$K$7$F$7$^$C$?1_C+%W%m$H!"Bg$2$5$K5-;v$r=q$-N)$F$??7J9
    • $BM7@1$h$j0&$r$3$a$F!&!&(B ($B$"$l$+$i(B4$B#0G/!&!&%"%s%L$N$R$H$j$4$H(B, 2006.02.28)$B!#5SK\$N:4!9LZ

      $B;d$b!X@'Hs!&2r6X$r!*!Y$H4j$C$F$$$k$R$H$j$@!#(B
      $BIu0u$r$7$F$$$k1_C+%W%m$b0l6ZFl$G$O$$$+$J$$Fq$7$$LdBj$H$O=E!92r$k$,!"2?$H$+2r6X$rJ}8~IU$1$k7hCG$@$1$G$b$7$FLc$$$?$$!#(B
      $B:BCL2q$G$N:4!9LZ;a$N8@MU!&!&(B
      $B!X1_C+%W%m$K4hD%$C$F$b$i$$$?$$!#$7$s$I$/$F$b>/$7=$@5$9$k$3$H$G:F8x3+$G$-$k$J$i$P!"$3$N:BCL2q$r$d$C$?2ACM$b=P$k!Y(B
      $B!&!&$H7k$s$G$$$^$9!#(B

      $BBh(B12$BOC$O!"$R$7H~$f$j;R$H:y0f9@;R$N6&1i$H$$$&!"%U%!%s$K$O$?$^$i$J$$2s$J$s$@$h$M!#(B

    • $BCfEgN5H~;a;`5n(B ($B!V(B1/49$B7W2h!W%5%]!<%H%Z!<%8(B $B7G<(HD(B, 2008.01.14)

    • $B!V(B1/49$B7W2h!W%5%]!<%H%Z!<%8(B

    $B!!(BTV $B$GN.$;$H$O8@$o$J$$$N$G!"%M%C%H$N%Z%$%Q!<%S%e!<$H$+$G!"(B $BCpC$9$N$G$O$J$/!"2?$,$^$:$+$C$?$N$+$r8!>Z!&2r@b$7$?>e$G!";KNA$H$7$FDs<($7$F$[$7$$$J$"!#(B

    $B!!!D!D$J$s$G$$$^$4$m$3$s$JOC$r$7$F$$$k$+$H$$$&$H!"$?$^$?$^D4$Y$?$+$i!#(B

$B"#(B $B$*5RMM$N%W%l%$%*%s%i%$%s(BID$B$K4X$9$k=EMW$J$*CN$i$;(B
(playonline.com, 2010.06.04)

$B!!!V0lIt$N$*5RMM$N%W%l%$%*%s%i%$%s(BID$B!"%W%l%$%*%s%i%$%s%Q%9%o!<%I!"$=$NB>EPO?>pJs$N0lIt$,O31L!W$7$?LOMM!#(B $B3:Ev$9$k(B ID $B$N%Q%9%o!<%I$K$D$$$F$O!"%W%l%$%*%s%i%$%s$,6/@)JQ99$7$?$_$?$$!#(B $B$I$NDxEY$N5,LO$J$N$+$O$^$@L$8x3+!#(B Ilion $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#4XO"(B:

$B"#(B APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat
(Adobe, 2010.06.04)

$B!!(BFlash Player 10.0.x / 9.x$B!"$*$h$S(B Adobe Reader / Acrobat 9.x $B$N(B authplay.dll $B$KCWL?E*$J7g4Y!#(B remote $B$+$i$N(B DoS$B!"$"$k$$$OG$0U$N%3!<%I$NCVE-2010-1297

$B!!=$@5HG$O$^$@$J$$!#(B Flash Player $B$K$D$$$F$O(B 10.1 RC $B$r;HMQ$9$k$3$H$G2sHr$G$-$k!#(B Adobe Reader / Acrobat 9.x $B$G$O!"(Bauthplay.dll $B$r(B rename $B$7$?$j!"(Bauthplay.dll $B$X$N%"%/%;%9$r6X;_$7$?$j$9$k$3$H$G2sHr$G$-$k!#(B

2010.06.07 $BDI5-(B:

$B!!4XO"(B:

2010.06.08 $BDI5-(B:

$B!!(B APSA10-01: Security Advisory for Flash Player, Adobe Reader and Acrobat (Adobe) $B$,2~D{$5$l$?!#(B

  • Windows / Mac / Linux $BHG(B Flash Player 10.x $B$K$D$$$F$O!"(B 2010.06.10 $B$K=$@5HG$r8x3+M=Dj!#(B

  • Solaris $BHG(B Flash Player 10.x $B$K$D$$$F$O!"L$Dj!#(B

  • Windows / Mac / Linux $BHG(B Adobe Reader / Acrobat 9.x $B$K$D$$$F$O!"(B 2010.06.29 $B$K=$@5HG$r8x3+M=Dj!#(B $B4XO"(B: Background on APSA10-01 Patch Schedule (Adobe, 2010.06.07)

2010.06.09 $BDI5-(B:

$B!!4XO"(B:

2010.06.11 $BDI5-(B:

$B!!(BFlash Player $B$H(B Adobe Air $B$N(B fix $B=P$^$7$?(B: APSB10-14: Security update available for Adobe Flash Player (adobe, 2010.06.10)$B!#(BFlash Player 10.1.53.64 / 9.0.277.0$B!"(BAir 2.0.2.12610 $B$G=$@5$5$l$F$$$^$9!#(B

$B!!$J$*!"(BSolaris $BMQ$N(B Flash Player 10.1 $B$O$^$@@5<0%j%j!<%9$5$l$F$^$;$s!#(B 10.1 RC $B$GN?$.$^$7$g$&!#(B

$B!!$7$+$7!"=$@50lMw$,$9$4$$$J$"!#(B

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1297).
Note: There are reports that this issue is being actively exploited in the wild.

This update resolves a memory exhaustion vulnerability that could lead to code execution (CVE-2009-3793).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2160).

This update resolves an indexing vulnerability that could lead to code execution (CVE-2010-2161).

This update resolves a heap corruption vulnerability that could lead to code execution (CVE-2010-2162).

This update resolves multiple vulnerabilities that could lead to code execution (CVE-2010-2163).

This update resolves a use after free vulnerability that could lead to code execution (CVE-2010-2164).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2165).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2166).

This update resolves multiple heap overflow vulnerabilities that could lead to code execution (CVE-2010-2167).

This update resolves a pointer memory corruption that could lead to code execution (CVE-2010-2169).

This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2010-2170).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2171).

This update resolves a denial of service issue on some UNIX platforms (Flash Player 9 only) (CVE-2010-2172).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2173).

This update resolves an invalid pointer vulnerability that could lead to code execution (CVE-2010-2174).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2175).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2176).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2177).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2178).

This update resolves a URL parsing vulnerability that could lead to cross-site scripting (Firefox and Chrome browsers only) (CVE-2010-2179).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2180).

This update resolves an integer overflow vulnerability that could lead to code execution (CVE-2010-2181).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2182).

This update resolves a integer overflow vulnerability that could lead to code execution (CVE-2010-2183).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2184).

This update resolves a buffer overflow vulnerability that could lead to code execution (CVE-2010-2185).

This update resolves a denial of service vulnerability that can cause the application to crash. Arbitrary code execution has not been demonstrated, but may be possible. (CVE-2010-2186).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2187).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2188).

This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-2189).
Note: This issue occurs only on VMWare systems with VMWare Tools enabled.

This update resolves a denial of service issue (CVE-2008-4546).

$B!!4XO"(B: Adobe Flash Player $B$*$h$S(B Adobe Acrobat/Reader $B$N@H (JPCERT/CC, 2010.06.11)

2010.06.20 $BDI5-(B:

$B!!F|K\8lHG(B: APSA10-01: Flash Player$B!"(BAdobe Reader$B$*$h$S(BAcrobat$B$K4X$9$k%;%-%e%j%F%#>pJs(B (Adobe)

2010.06.25 $BDI5-(B:

$B!!4XO"(B:

$B!!(BAPSB10-15: Security Advisory for Adobe Reader and Acrobat (Adobe, 2010.06.24) $B=P$^$7$?!#8=:_$NFbMF$O!"4{Js$NM=9pJT(B (2010.06.29 $B$K=$@5HG$r8x3+M=Dj(B) $B$@$1$G$9!#(B

2010.06.29 $BDI5-(B:

$B!!(BAdobe Reader, Acrobat $B$*$h$S(B Flash Player $B$N(Bauthplay.dll$B$N@HZ%l%]!<%H(B (NTT $B%G!<%?%;%-%e%j%F%#(B, 2010.06.15 $B99?7(B)

2010.06.30 $BDI5-(B:

$B!!(BAdobe Reader / Acrobat 9.3.3 / 8.2.3 $B=P$^$7$?(B: APSB10-15: Security updates available for Adobe Reader and Acrobat (Adobe, 2010.06.29)$B!#(BCVE-2010-1297 $B$O(B Adobe Reader / Acrobat 9.x $B7O$K$@$11F6A$7$^$9$,!"B>$K$bBgNL$N=$@5$,$"$k$N$G!"(B8.x $B7O$K$D$$$F$b99?7HG(B 8.2.3 $B$,=P$F$$$^$9!#(B


$B"#(B 2010.06.05


$B"#(B 2010.06.04

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2010 $BG/(B 6 $B7n(B
(Microsoft, 2010.06.04)

$B!!7W(B 10 $B8D$N(B advisory$B!"7W(B 34 $B8D$N7g4Y!#(BOffice $B$"$j(B (Mac $BHG$bBP>](B)$B!#(B


$B"#(B 2010.06.03

$B"#(B $BDI5-(B

$B

$B!!(B$B9qFb4k6H$rI8E*$H$7$?%&%$%k%946@wD4::$rqY$k%&%$%k%9E:IU%a!<%k!"@)8fJ8;z(BRLO$B$r;H$C$?3HD%;R56Au$r3NG'(B ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.06.03)$B!#F2!9$H(B .scr $B$J$N$O$=$&$$$&$o$1$G$7$?$+!#(B

$B:#8e$N967b$KHw$($?BP:v(B

$B!!(BRLO $BBP:v$,4^$^$l$F$J$$$h%H%l%s%I%^%$%/%m!D!D!#(B $B$?$H$($P!"(B$BMU$C$QF|5-(B $B$r;2>H!#(B

$B"#(B $B$$$^0lHV4m$J$$$<$$
($BF|7P(B IT Pro, 2010.06.03)

$B"#(B OpenSSL Security Advisory [01-Jun-2010] Two security flaws have been fixed in OpenSSL 0.9.8o and OpenSSL 1.0.0a.
(OpenSSL.org, 2010.06.01)

$B!!(BOpenSSL $B$K(B 2 $B$D$N7g4Y!"(BOpenSSL 0.9.8o / 1.0.0a $B$G=$@5$5$l$F$$$k!#(B

  • Cryptographic Message Syntax (CMS) $B9=B$BN$N=hM}$K7g4Y$,$"$j!"(B $B8m$C$?%a%b%j%"%I%l%9$X$N=q$-9~$_$d!"%a%b%j$NFs=E2rJ|$,2DG=(B (typo fixed: iida $B$5$s46CVE-2010-0742

  • EVP_PKEY_verify_recover() $B4X?t$K7g4Y$,$"$j!"(BRSA $B80$N8!>Z%j%+%P%j$K<:GT$7$?>l9g$K!"%(%i!<%3!<%I$rJV$9$Y$-$J$N$K!"L$Dj5AD9$NL$=i4|2=%P%C%U%!$rJV$7$F$7$^$&!#(B $B$3$N7g4Y$O(B OpenSSL 1.0.0 $B$K$N$_B8:_$9$k!#(B CVE-2010-1633


$B"#(B 2010.06.02

$B"#(B $B$$$m$$$m(B (2010.06.02)
(various)

$B"#(B FreeBSD $BJ}LL(B
(FreeBSD.org, 2010.05.27)

$B"#(B $BDI5-(B

$B

$B!!(B$B!H(BVirus Check$B!I(B Malware Attack in Japanese (Symantec, 2010.06.01) $B$K$h$k$H!"Ev3:(B .scr $B%U%!%$%k$K$O!"$K$;$NEE;R=pL>$^$G$"$C$?$=$&$G!#(B


$B"#(B 2010.06.01

$B"#(B Google Chrome Stable Channel Update
(Google, 2010.05.25)

$B!!(BGoogle Chrome 5.0.375.55 $BEP>l!#(BMac OS $BMQ!"(BLinux $BMQ$b@5<0HG$K!#(B 6 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B $B
(JPCERT/CC, 2010.06.01)

$B"#(B [JS10002] $B0lB@O:$N@H
($B%8%c%9%H%7%9%F%`(B, 2010.06.01)


[$B%;%-%e%j%F%#%[!<%k(B memo]