$B%;%-%e%j%F%#%[!<%k(B memo - 2010.10

Last modified: Mon May 30 01:36:58 2011 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2010.10.29

$B"#(B $B$$$m$$$m(B (2010.10.29)
(various)

$B"#(B APSB10-25: Security update available for Shockwave Player
(Adobe, 2010.10.28)

$B!!(BShockwave Player 11.5.9.615 $BEP>l!#(B APSA10-04: Security Advisory for Adobe Shockwave Player (Adobe, 2010.10.21) (CVE-2010-3653) $B$N7o$r4^$`!"(B 11 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B APSA10-05: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat
(Adobe, 2010.10.28)

$B!!(BFlash Player 10.1.85.3 $B0JA0!"(BFlash Player for Android 10.1.95.2 $B0JA0!"(B $B$*$h$S(B Adobe Reader / Acrobat 9.x $B$N(B authplay.dll $B$K(B 0-day $B7g4Y!#(B $B4{$K(B Adobe Reader / Acrobat 9.x $B8~$1$N96N,%W%m%0%i%`$,@$$K=P2s$C$F$$$k!#(B Flash Player $B8~$1$N96N,%W%m%0%i%`$O3NG'$5$l$F$$$J$$!#(B CVE-2010-3654$B!#(B Adobe Reader / Acrobat 8.x $B$K$3$N7g4Y$O$J$$!#(B kenics $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BFlash Player 10.x / Flash Player for Android 10.x $B8~$1$N99?7%W%m%0%i%`$O(B 2010.11.09 $B$K!"(BAdobe Reader / Acrobat 9.x $B8~$1$N99?7%W%m%0%i%`$O!V(B2010.11.15 $B$N=5!W$KDs6!$5$l$kM=Dj!#(B

$B!!(BAdobe Reader / Acrobat 9.x $B$N>l9g$O2sHrJ}K!$,B8:_$9$k!#(B

$B!!(B$B$^$?(B authplay.dll $B$G$9$+!D!D!#4XO"(B:

2010.11.03 $BDI5-(B:

$B!!(BAdobe Reader / Acrobat $B$@$1$G$J$/!"(BFlash $B$K$D$$$F$b(B in-the-wild $B>uBV$KFMF~$7$F$$$kLOMM$G$9!#(B

2010.11.04 $BDI5-(B:

$B!!(BAPSA10-05: Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat $B$,(B 2010.11.02 $BIU$G2~D{$5$l$F$^$9!#(BFlash Player 10.x for Windows / Mac / Unix $B$NDs6!M=Dj$,(B 2010.11.04 $B$KA0E]$7$5$l$^$7$?(B ($BL@F|$G$9$M(B)$B!#(BFlash Player 10.x for Android $B$O(B 2010.11.09 $B$N$^$^!#(B

2010.11.05 $BDI5-(B:

$B!!!D!D?7HG=P$^$7$?(B: APSB10-26: Security update available for Adobe Flash Player (Adobe, 2010.11.04)

$B!!4XO"(B:

2010.11.15 $BDI5-(B:

$B!!(BPrenotification: Out-of-Cycle Security Updates for Adobe Reader and Acrobat (Adobe PSIRT Blog, 2010.11.12)$B!#(BUS $B;~4V$G(B 2010.11.16 $B$@$=$&$G$9!#F|K\$@$H(B 2010.11.17 $B?eMKF|$G$9$M!#(B

2010.11.17 $BDI5-(B:

$B!!(B APSB10-28: Security updates available for Adobe Reader and Acrobat (Adobe, 2010.11.16)$B!#(BAdobe Reader / Acrobat 9.4.1 $BEP>l!D!D$G$9$,!"(BWindows / Mac $BHG$N$_!#(BUnix $BHG$O(B 2010.11.30 $B$@$=$&$G$9!#(B


$B"#(B 2010.10.28

$B"#(B $B$$$m$$$m(B (2010.10.28)
(various)

$B"#(B $BDI5-(B

HTTP$B%;%C%7%g%s%O%$%8%c%C%/$rl(B

$B!!(BFiresheep $B$K4X$9$k(B Mozilla $B%;%-%e%j%F%#%A!<%`$+$i$N%3%a%s%H(B (Mozilla Japan $B%V%m%0(B, 2010.10.28)

$B9qFb(B100$Be$G46@wHo32$r3NG'!#!I(Bmstmp$B!I(B $B!I(Blib.dll$B!I(B $B$N%U%!%$%kL>$G3H;6$9$kIT@5%W%m%0%i%`(B

$B!!$O$^$b$H$5$s$K$h$k8=>l$+$i$NJs9p(B: $B$$$-$J$j=1$C$F$-$?!V(Bmstmp$B!W%&%#%k%9$KBg$o$i$o(B ($BF|7P(B IT Pro, 2010.10.28)$B!#(B

$B!!?^(B3$B$N%&%#%k%946@w7PO)$N?^$K1h$C$F@bL@$7$h$&!#$^$:!"Ho32o$NJ}K!$G(BWeb$B%5%$%H$r1\Mw$9$k!J?^(B3$B$N4]?t;z(B1$B!K!#$9$k$H!"%[!<%`%Z!<%8%5!<%P!<$KKd$a9~$^$l$?%"%/%;%92r@O%5%$%H$N%W%m%0%i%`$K$h$j%"%/%;%92r@O%5%$%H$XE>Aw$5$l$k!JF1(B2$B!K!#%"%/%;%92r@O%5%$%H$X%"%/%;%9$7$?%f!<%6!<$N(BPC$B$,2~$6$s$5$l$?%9%/%j%W%H$rFI$_9~$s$G

$B!!!V%"%/%;%92r@O%5%$%H!W$C$F!"$=$&$$$&$3$H$G$9$+!D!D!#(B

$B!!$J$*!"$3$l$i$N46@w7PO)$ND4::$K$O%M%C%H%o!<%/%U%)%l%s%8%C%/5!4o$N%Q%1%C%H%V%i%C%/%[!<%k$,;H$o$l$?!#:#2s$N$h$&$JJ#?t$N%I%a%$%s$r$^$?$,$j46@w7PO)$,B?4t$KEO$k$h$&$J>l9g!"K\Ev$K$I$3$,967b85$+$rH=Dj$9$k$N$O!"%I%a%$%sA+0\$7$+$o$+$i$J$$%W%m%-%7%m%0$N>pJs$@$1$G$O;jFq$N6H$G$"$k!#

$B!!$J$k$[$I!D!D!#(B

Critical vulnerability in Firefox 3.5 and Firefox 3.6

$B!!=$@5HG=P$^$7$?!#(BFirefox 3.6.12 / 3.5.15$B!"(BThunderbird 3.1.6 / 3.0.10$B!"(B SeaMonkey 2.0.10$B!#(B

$B!!4XO"(B:


$B"#(B 2010.10.27

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS10-074$B!"@HPowerZip 7.21 (Build 4010) Stack Buffer Overflow (exploit-db.com)$B!"(B CVE-2010-3227

$B9qFb(B100$Be$G46@wHo32$r3NG'!#!I(Bmstmp$B!I(B $B!I(Blib.dll$B!I(B $B$N%U%!%$%kL>$G3H;6$9$kIT@5%W%m%0%i%`(B

$B!!4XO"(B:

$B"#(B Critical vulnerability in Firefox 3.5 and Firefox 3.6
(Mozilla.org, 2010.10.26)

$B!!(BFirefox 3.5 / 3.6 $B$N(B JavaScript $Bu$G2sHr$9$k$K$O!"(BJavaScript $B$rL58z2=$9$k$7$+$J$$!#(B $B4XO"(B:

2010.10.28 $BDI5-(B:

$B!!=$@5HG=P$^$7$?!#(BFirefox 3.6.12 / 3.5.15$B!"(BThunderbird 3.1.6 / 3.0.10$B!"(B SeaMonkey 2.0.10$B!#(B

$B!!4XO"(B:

2010.11.01 $BDI5-(B:

$B!!(BUsing the Browser Cache to Bypass Security (Symantec, 2010.10.28) $B$NF|K\8lHG(B: $B%V%i%&%6$N%-%c%C%7%e$rMxMQ$7$?%;%-%e%j%F%#$N2sHr(B ($B%7%^%s%F%C%/(B, 2010.10.28)


$B"#(B 2010.10.26

$B"#(B [Full-disclosure] VSR Advisories: Linux RDS Protocol Local Privilege Escalation
(Virtual Security Research, 2010.10.20)

$B!!(BLinux 2.6.30 $B!A(B 2.6.36-rc8 $B$K7g4Y!#(BReliable Datagram Sockets (RDS) $B%W%m%H%3%k$N=hM}$K7g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rC%CVE-2010-3904

$B!!(BLinux 2.6.36 $B$G$OD>$C$F$$$k$_$?$$!#4XO"(B:

$B"#(B $BDI5-(B

GNU libc $B$N%@%$%J%_%C%/%j%s%+$K(B 2 $B$D$N7g4Y!#(B

APSB10-21: Security updates available for Adobe Reader and Acrobat

$B"#(B HTTP$B%;%C%7%g%s%O%$%8%c%C%/$rl(B
($B%^%$%3%_%8%c!<%J%k(B, 2010.10.26)

$B!!(BFirefox $BMQ$N%"%I%*%s(B Firesheep 0.1 $BEP>l!#(BAmazon $B$d(B Google$B!"(BWindows Live$B!"(BFacebook$B!"(BTwitter$B!"(BEvernote$B!"(BDropbox $B$J$I$KBP$7$F!"%*!<%W%s%o%$%d%l%9%M%C%H%o!<%/$K$*$1$k(B HTTP $B%;%C%7%g%s%O%$%8%c%C%/$,2DG=$JLOMM!#(B

$B!!4XO"(B:

2010.10.28 $BDI5-(B:

$B!!(BFiresheep $B$K4X$9$k(B Mozilla $B%;%-%e%j%F%#%A!<%`$+$i$N%3%a%s%H(B (Mozilla Japan $B%V%m%0(B, 2010.10.28)

2010.11.09 $BDI5-(B:

$B!!(BBlackSheep - $B62I]$N%O%$%8%c%C%+!l(B (techcrunch, 2010.11.09)

2010.11.11 $BDI5-(B:

$B!!4XO"(B:

2010.11.24 $BDI5-(B:

$B!!(B$B%;%C%7%g%s%O%$%8%c%C%/%D!<%k(BFiresheep$B$HBP93%"%I%*%s(BBlacksheep$B$r8!>Z$7$F$_$?(B (security.gs, 2010.11.20)


$B"#(B 2010.10.25

$B"#(B $B$$$m$$$m(B (2010.10.25)
(various)


$B"#(B 2010.10.24


$B"#(B 2010.10.23

$B"#(B GNU libc $B$N%@%$%J%_%C%/%j%s%+$K(B 2 $B$D$N7g4Y!#(B
(Tavis Ormandy, 2010.10.18)

$B!!(BGNU libc $B$N%@%$%J%_%C%/%j%s%+$K(B 2 $B$D$N7g4Y!"(Blocal user $B$,(B root $B8"8B$rC%

$B!!=$@59pCN(B:

$B!!4XO"(B:

2010.10.26 $BDI5-(B:

$B!!(BRHSA-2010:0793-1 - Important: glibc security update (RHEL 5)$B!"(B USN-1009-1: GNU C Library vulnerabilities (Ubuntu)$B!"(B[CentOS-announce] CESA-2010:0793 Important CentOS 5 x86_64 glibc (CentOS)$B!"(B JVNVU#537223: glibc $B$K8"8B>:3J$N@H (JVN, 2010.10.26) $B$rDI5-!#(B

$B"#(B $BDI5-(B

$B9qFb(B100$Be$G46@wHo32$r3NG'!#!I(Bmstmp$B!I(B $B!I(Blib.dll$B!I(B $B$N%U%!%$%kL>$G3H;6$9$kIT@5%W%m%0%i%`(B

$B!!(B$B!V(Bmstmp$B!W7O%&%#%k%9Jd407W2h(B ($B%O%K!<%]%C%?!<$NIt20(B, 2010.10.22)$B!#(B $B%^%+%U%#!<$,$@$a$@$a$@$C$?LOMM$G$9$,!"%^%+%U%#!<$J?M$O(B Artemis $B;H$C$F$F$b$@$a$@$a$@$C$?$N$+$J$"!#(BArtemis $B;H$C$F$J$$>l9g!"%^%+%U%#!<$OA4$/;H$$J*$K$J$i$J$$$H8D?ME*$K$O;W$C$F$^$9!#(B

$B!!$BN6C+Bg3XM}9)3XIt$K$*$1$k%&%$%k%946@w;vNc(B part 2


$B"#(B 2010.10.22

$B"#(B $B8:B;8=C$9JT=85;=Q(B
(techcrunch, 2010.10.22)

$B!!$$$h$$$h%j%"%k$K$3$&$$$&;~Be$K$J$C$F$-$?!#(B

$B"#(B $B9qFb(B100$Be$G46@wHo32$r3NG'!#!I(Bmstmp$B!I(B $B!I(Blib.dll$B!I(B $B$N%U%!%$%kL>$G3H;6$9$kIT@5%W%m%0%i%`(B
($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.10.22)

$B!!$J$s$+9-$,$C$F$$$k$i$7$$(B mstmp $BOC!#(B

$B%H%l%s%I%^%$%/%m$N%5%]!<%H%;%s%?!<$X$NLd$$9g$o$;$O!"(B2010$BG/(B10$B7n(B14$BF|0J9_!"(B100$B
$B46@wJs9p$NBgH>$OF|K\9qFb$K=8Cf$7$F$*$j!"F|K\$rI8E*$H$7$?%?!<%2%C%H967b$G$"$k2DG=@-$b9M$($i$l$^$9!#(B

$B!!F|K\$G$@$19-$,$C$F$$$k$?$a$K!"@$3&E*$K$OOCBj$K$J$C$F$J$$(B?

2010.10.23 $BDI5-(B:

$B!!(B$B!V(Bmstmp$B!W7O%&%#%k%9Jd407W2h(B ($B%O%K!<%]%C%?!<$NIt20(B, 2010.10.22)$B!#(B $B%^%+%U%#!<$,$@$a$@$a$@$C$?LOMM$G$9$,!"%^%+%U%#!<$J?M$O(B Artemis $B;H$C$F$F$b$@$a$@$a$@$C$?$N$+$J$"!#(BArtemis $B;H$C$F$J$$>l9g!"%^%+%U%#!<$OA4$/;H$$J*$K$J$i$J$$$H8D?ME*$K$O;W$C$F$^$9!#(B

$B!!$BN6C+Bg3XM}9)3XIt$K$*$1$k%&%$%k%946@w;vNc(B part 2

2010.10.27 $BDI5-(B:

$B!!4XO"(B:

2010.10.28 $BDI5-(B:

$B!!$O$^$b$H$5$s$K$h$k8=>l$+$i$NJs9p(B: $B$$$-$J$j=1$C$F$-$?!V(Bmstmp$B!W%&%#%k%9$KBg$o$i$o(B ($BF|7P(B IT Pro, 2010.10.28)$B!#(B

$B!!?^(B3$B$N%&%#%k%946@w7PO)$N?^$K1h$C$F@bL@$7$h$&!#$^$:!"Ho32o$NJ}K!$G(BWeb$B%5%$%H$r1\Mw$9$k!J?^(B3$B$N4]?t;z(B1$B!K!#$9$k$H!"%[!<%`%Z!<%8%5!<%P!<$KKd$a9~$^$l$?%"%/%;%92r@O%5%$%H$N%W%m%0%i%`$K$h$j%"%/%;%92r@O%5%$%H$XE>Aw$5$l$k!JF1(B2$B!K!#%"%/%;%92r@O%5%$%H$X%"%/%;%9$7$?%f!<%6!<$N(BPC$B$,2~$6$s$5$l$?%9%/%j%W%H$rFI$_9~$s$G

$B!!!V%"%/%;%92r@O%5%$%H!W$C$F!"$=$&$$$&$3$H$G$9$+!D!D!#(B

$B!!$J$*!"$3$l$i$N46@w7PO)$ND4::$K$O%M%C%H%o!<%/%U%)%l%s%8%C%/5!4o$N%Q%1%C%H%V%i%C%/%[!<%k$,;H$o$l$?!#:#2s$N$h$&$JJ#?t$N%I%a%$%s$r$^$?$,$j46@w7PO)$,B?4t$KEO$k$h$&$J>l9g!"K\Ev$K$I$3$,967b85$+$rH=Dj$9$k$N$O!"%I%a%$%sA+0\$7$+$o$+$i$J$$%W%m%-%7%m%0$N>pJs$@$1$G$O;jFq$N6H$G$"$k!#

$B!!$J$k$[$I!D!D!#(B

2010.11.01 $BDI5-(B:

$B!!(B$B!ZCm0U4-5/![Bg%5%$%H$N1\Mw$GH/@8$7$?%3%s%T%e!<%?%&%$%k%946@w$K$D$$$F(B (LAC, 2010.10.29)

$B2<5-(BIP$B%"%I%l%9$X$N%"%/%;%9$r9T$C$F$$$k(BPC$B$O!"46@w$7$F$$$k2DG=@-$,$"$k$?$a!"3:Ev$9$k(BPC$B$,$J$$$+$r$43NG'$$$?$@$/$3$H!"$^$?3:Ev(BPC$B$,$"$k>l9g$O$=$l$rFCDj$7!"%&%$%k%9$N6n=|$r9T$C$F$/$@$5$$!#(B
$B!N(B64.27.25.223$B!O!"!N(B64.27.25.224$B!O!"!N(B88.80.7.152$B!O!"!N(B85.17.209.3$B!O!"!N(B95.211.111.229$B!O!"(B $B!N(B95.211.108.93$B!O!"!N(B178.63.62.19$B!O(B

$B!!(B$B%"%U%#%j%(%$%H$K$h$k6bA, ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.10.29)

2010.11.03 $BDI5-(B:

$B!!(BCompromised Websites Use Java Flaws, Hit Japanese Users (trendmicro blog, 2010.11.02)

2010.11.12 $BDI5-(B:

$B!!(BCompromised Websites Used For Affiliate Scams (trendmicro blog, 2010.11.11)$B!#(B$B%"%U%#%j%(%$%H$K$h$k6bA, ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.10.29) $B$N1Q8lHG$+$J!#(B

$B"#(B $B$$$m$$$m(B (2010.10.22)
(various)

2010.10.29 $BDI5-(B:

$B!!(BAPSA10-04: Security Advisory for Adobe Shockwave Player (Adobe, 2010.10.21) $B$G$9$,!"(BAPSB10-25 (Adobe, 2010.10.28) $B$G=$@5$5$l$^$7$?!#(B

$B"#(B $BDI5-(B

Sleipnir 2.9.5 $B@5<0HG(B $B%j%j!<%9%N!<%H(B[2010/10/21]

Firefox 3.6.11 / 3.5.14$B!"(BThunderbird 3.1.5 / 3.0.9 $BEP>l(B

$B!!(BSeaMonkey 2.0.9 $B$b=P$F$$$^$9!#(Btvb19131 $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2010.10.21

$B"#(B $B$$$m$$$m(B (2010.10.21)
(various)

$B"#(B Sleipnir 2.9.5 $B@5<0HG(B $B%j%j!<%9%N!<%H(B[2010/10/21]
($B%U%'%s%j%k(B, 2010.10.21)

$B!!(BSleipnir 2.9.5 $BEP>l!#!V(BDLL $B%U%!%$%kFI$_9~$_$K4X$9$k@H

2010.10.22 $BDI5-(B:

$B!!(BJVN $B$+$i$b=P$^$7$?(B:

$B!!(BGrani $B$K$bF1$8LdBj$,$"$j!"(BGrani 4.4 $B$G=$@5$5$l$F$$$^$9!#(B

$B"#(B JVN#71138390: Apsaly $B$K$*$1$k
(JVN, 2010.10.21)

$B!!(BApsaly 3.74 $B$G=$@5$5$l$F$$$k$=$&$G$9!#4XO"(B: $B@H$B!#(B

$B"#(B JVN#48097065: TeraPad $B$K$*$1$k(B DLL $BFI$_9~$_$K4X$9$k@H
(JVN, 2010.10.21)

$B!!(BTeraPad 1.00 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

$B"#(B $BDI5-(B

Oracle Java SE and Java for Business Critical Patch Update Advisory - October 2010

$B!!(BMac OS X 10.6 $BMQ(B Java $B$b(B Java SE 6 Update 22 $B$K$J$j$^$7$?!#(B Mac OS X 10.5 $B$K$O(B Java SE 5.0 Update 26 $B$,MQ0U$5$l$^$7$?!#(B (Java SE 5.0 Update 26 $B$O!"$"$k0UL#!"5.=E$J$h$&$J!D!D(B)

$B!!4XO"(B: In other Apple news... Java updates (Sophos, 2010.10.20)


$B"#(B 2010.10.20

$B"#(B Kaspersky$B$N%5%$%H2~$6$s!!%f!<%6!<$r56%5%$%H$KE>Aw(B
(ITmedia, 2010.10.20)

$B!!(BKaspersky USA $B$,%O%/$i$l$F!"(BProduct Downloads > KIS > 2011 > English(USA/Canada) $B$+$i!"$K$;%"%s%A%&%$%k%9%5%$%H$KHt$P$5$l$F$$$?7o!#4XO"(B:

$B"#(B $BDI5-(B

$BJ#?t$N%"!<%+%$%V%=%U%H$K$*$1$k%P%$%J%j!&%W%i%s%F%#%s%0LdBj(B

$B"#(B Apache httpd 2.2.17 / 2.0.64 $BEP>l(B
(Apache.org, 2010.10.19)

$B!!(BApache httpd 2.2.16 2.2.17 $BEP>l!#(B

$B!!$3$l$K$"$o$;$F$+!"(BApache 2.0.64 $B$H(B APR-util 0.9.19 $B$bEP>l$7$F$$$^$9!#(B $B$I$A$i$K$b%;%-%e%j%F%#=$@5$,4^$^$l$F$$$^$9!#(B

$B"#(B Google Chrome Stable Channel Update
(Google Chrome Release blog, 2010.10.19)

$B!!(BGoogle Chrome 7.0.517.41 $BEP>l!#(B10 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B Firefox 3.6.11 / 3.5.14$B!"(BThunderbird 3.1.5 / 3.0.9 $BEP>l(B
(Mozilla Japan $B%V%m%0(B, 2010.10.20)

$B!!=P$F$^$9!#(B

2010.10.22 $BDI5-(B:

$B!!(BSeaMonkey 2.0.9 $B$b=P$F$$$^$9!#(Btvb19131 $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2010.10.19

$B"#(B $BJ#?t$N%"!<%+%$%V%=%U%H$K$*$1$k%P%$%J%j!&%W%i%s%F%#%s%0LdBj(B
($B1v7n(B $B@??M(B, 2010.10.18)

$B!!$3$l$N7o(B:

$B!!$3$&$$$&OC$@$=$&$G(B:

$B:#2sH/3P$7$?0lO"$N%"!<%+%$%V%=%U%H$N@H]$H$J$k>l9g$,B?$$$N$G$9$,!"(BEXE$B%U%!%$%k$K$D$$$F$bF1MM$NLdBj$,H/@8$9$k$N$GCm0U$,I,MW$H$5$l$^$9!#(B
($BCfN,(B)
Lhaplus$B$H(BLhasa$B$O:#2s$N=$@5$G!"(Bexplorer.exe$B$r%U%k%Q%9$G5/F0$9$k$h$&$KJQ99$5$l$^$7$?(B(Lhaplus$B$K$OIT@5$J(BDLL$B$r%m!<%I$7$F$7$^$&LdBj$b$"$j$^$7$?$,!"$=$l$K$D$$$F$b=$@5$5$l$F$$$^$9(B)$B!#$^$?(BXacRett$B$O!"%+%l%s%H%G%#%l%/%H%j$r%$%s%9%H!<%k%U%)%k%@$K@_Dj$7$F$+$i(BWinExec$B$r8F$S=P$9$h$&$K=$@5$5$l$^$7$?!#(B
($BCfN,(B)
$B$A$J$_$K$3$N$h$&$KIT@5$J(BEXE$B$rl9g$H$O0[$J$j!"%^%$%/%m%=%U%H$,2sHr:v$N0l$D$H$7$FDs6!$7$F$$$k!V(BCWDIllegalInDllSearch$B!W$N@_Dj(B[9]$B$G$O2sHr$G$-$^$;$s$N$GCm0U$,I,MW$G$9!#(B

$B!!4XO"(B:

2010.10.20 $BDI5-(B:

$B!!$D$E$-$C$]$$!#(B

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

MS10-071 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (2360131)

$B!!(BIE 6 / 7 / 8 $B$K(B 10 $B8D$N7g4Y!#(B

  • $B%*!<%H%3%s%W%j!<%H$N>pJsO3$($$$N@HCVE-2010-0808

    Windows XP / Vista $B>e$N(B IE 6 / 7 $B$N7g4Y!#(B $B!V%*!<%H%3%s%W%j!<%H5!G=$,M-8z$K$5$l$F$$$?>l9g!"%U%)!<%`(B $B%U%#!<%k%I$KF~NO$5$l$?FbMF$r%-%c%W%A%c$9$k2DG=@-$,$"$j$^$9!W(B

  • HTML $B$N%5%K%?%$%:$N@HCVE-2010-3243

    IE 8 $B$N(B toStaticHTML API $B$N7g4Y!"(BXSS $B$,H/@8!#!V%f!<%6!<$N%;%-%e%j%F%#(B $B%3%s%F%-%9%H$G(B Web $B%5%$%H$KBP$7%9%/%j%W%H$,

  • HTML $B$N%5%K%?%$%:$N@HCVE-2010-3324

    IE 8 $B$N(B toStaticHTML API $B$N7g4Y!"(BXSS $B$,H/@8!#!V%f!<%6!<$N%;%-%e%j%F%#(B $B%3%s%F%-%9%H$G(B Web $B%5%$%H$KBP$7%9%/%j%W%H$,

  • CSS $BFCpJsO3$($$$N@HCVE-2010-3325

    IE 6 / 7 / 8 $B$N7g4Y!#!V(BInternet Explorer $B$,(B CSS $B$NFC

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3326

    IE 6 $B$N7g4Y!#96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B%"%s%+!pJsO3$($$$N@HCVE-2010-3327

    IE 6 / 7 / 8 $B$N7g4Y!#!V:o=|:Q$_$N>pJs$,(B HTML $B%3%s%F%s%D$K;D$k2DG=@-$,$"$j$^$9!W(B

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3328

    IE 6 / 7 / 8 $B$N7g4Y!#96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3329

    IE 7 / 8 $B$N7g4Y!#(BHtmlDlgHelper Class COM $B%*%V%8%'%/%H$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B%/%m%9(B $B%I%a%$%s$N>pJsO3$($$$N@HCVE-2010-3330

    IE 6 / 7 / 8 $B$N7g4Y!#!V(BInternet Explorer $B$N%;%-%e%j%F%#(B $B%>!<%s$^$?$OJL$N%I%a%$%s$+$i%3%s%F%s%D$r1\Mw$9$k2DG=@-$,$"$j$^$9!W!#(BExploitability Index: 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3331

    IE 6 / 7 / 8 $B$N7g4Y!#96N,(B Word $B%I%-%e%a%s%H$r3+$-!"JD$8$k$HG$0U$N%3!<%I$,

$B!!(BHotfix $B$K4^$^$l$kHs%;%-%e%j%F%#$J=$@5$O$3$A$i(B: KB 2360131

MS10-072 - $B=EMW(B: SafeHTML $B$N@HpJsO3$($$$,5/$3$k(B (2412048)

$B!!(BSharePoint Services 3.0$B!"(BSharePoint Foundation 2010$B!"(B SharePoint Server 2007$B!"(BGroove Server 2010$B!"(BOffice Web Apps $B$K!">pJsO31L$K4X$9$k(B 2 $B$D$N7g4Y!#(BSafeHTML $B$K7g4Y$,$"$j!"(BXSS $B$,H/@8!"(Blocal user $B$N%3%s%F%-%9%H$G967b%9%/%j%W%H$,CVE-2010-3243 (Exploitability Index: 3)$B!"(B CVE-2010-3324 (Exploitability Index: 3)

MS10-073 - $B=EMW(B: Windows $B%+!<%M%k%b!<%I(B $B%I%i%$%P!<$N@H:3J$5$l$k(B (981957)

$B!!(BWidnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B%+!<%M%k%b!<%I%I%i%$%P!<$K(B 3 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B

  • Win32k $B$N;2>H%+%&%s%H$N@HCVE-2010-2549

    Windows Vista / Server 2008 $B$N7g4Y!#(BExploitability Index: 3

  • Win32k $B$N%-!<%\!<%I$N%l%$%"%&%H$N@HCVE-2010-2743

    Widnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N7g4Y!#(BWidnows XP $B$O!V=EMW!W!"$=$NB>$O!VCm0U!W!#$3$N7g4Y$rMxMQ$9$k%^%k%&%'%"$,B8:_!#(BExploitability Index: 1

  • Win32k $B$N%&%#%s%I%&(B $B%/%i%9$N@HCVE-2010-2744

    Widnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N7g4Y!#(BExploitability Index: 1

MS10-074 - $B7Y9p(B: Microsoft Foundation Classes $B$N@H

MS10-075 - $B6[5^(B: Windows Media Player $B%M%C%H%o!<%/6&M-%5!<%S%9$N@H

MS10-076 - $B6[5^(B: Embedded OpenType $B%U%)%s%H(B $B%(%s%8%s$N@H

MS10-077 - $B6[5^(B: .NET Framework $B$N@H

MS10-078 - $B=EMW(B: OpenType $B%U%)%s%H(B (OTF) $B7A<0%I%i%$%P!<$N@H:3J$5$l$k(B (2279986)

$B!!(BWindows XP / Server 2003 $B$K7g4Y!#(B OpenType $B%U%)%s%H(B (OTF) $B7A<0%I%i%$%P!<$K(B 2 $B$D$N7g4Y$,$"$j!"(B local user $B$K$h$k8"8B>e>:$,2DG=!#(B $B96N,(B OpenType $B%U%)%s%H$rKd$a9~$s$@(B Web $B%Z!<%8$r(B (IE $B$G$O$J$/(B) 3rd party $B@=(B Web $B%/%i%$%"%s%H$G3+$/$H967b$,@.N)$9$k!#(B

  • OpenType $B%U%)%s%H$N2r@O$N@HCVE-2010-2740$B!#(BExploitability Index: 1

  • OpenType $B%U%)%s%H$N8!>Z$N@HCVE-2010-2741$B!#(BExploitability Index: 1

MS10-079 - $B=EMW(B: Microsoft Word $B$N@H

$B!!(BWord 2002 / 2003 / 2007 / 2010$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWord Viewer$B!"(BOffice Web Apps$B!"(BWord Web App $B$K(B 11 $B8D$N7g4Y!#BgH>$N7g4Y$O(B Word 2002 $B$H(B Office 2004 for Mac $B$K$7$+1F6A$7$J$$!#(B

  • Word $B$N=i4|2=$5$l$F$$$J$$%]%$%s%?!<$N@HCVE-2010-2747

    Exploitability Index: 2

  • Word $B$N6-3&%A%'%C%/$N@HCVE-2010-2748

    Exploitability Index: 2

  • Word $B$N%$%s%G%C%/%9$N@HCVE-2010-2750

    Exploitability Index: 2

  • Word $B$N%9%?%C%/(B $B%*!<%P!<%U%m!<$N@HCVE-2010-3214

    Word 2002 / 2003 / 2007 / 2010$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWord Viewer$B!"(BOffice Web Apps$B!"(BWord Web App $B$N7g4Y!#(BExploitability Index: 1

  • Word $B$NLa$jCM$N@HCVE-2010-3215

    Exploitability Index: 2

  • Word $B$N%V%C%/%^!<%/$N@HCVE-2010-3216

    Exploitability Index: 1

  • Word $B$N%]%$%s%?!<$N@HCVE-2010-3217

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N%R!<%W(B $B%*!<%P!<%U%m!<$N@HCVE-2010-3218

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N%$%s%G%C%/%9$N2r@O$N@HCVE-2010-3219

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N2r@O$N@HCVE-2010-3220

    Exploitability Index: 2

  • Word $B$N2r@O$N@HCVE-2010-3221

    Word 2002 / 2003$B!"(BOffice 2004 for Mac$B!"(BWord Viewer $B$N7g4Y!#(BExploitability Index: 2

MS10-080 - $B=EMW(B: Microsoft Excel $B$N@H

$B!!(BExcel 2002 / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K(B 13 $B8D$N7g4Y!#(B

  • Excel $B$N%l%3!<%I$N2r@O$N@0?t%*!<%P!<%U%m!<$N@HCVE-2010-3230

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Excel $B%l%3!<%I2r@O$N%a%b%jGKB;$N@HCVE-2010-3231

    Excel 2002$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$N7g4Y!#(BExploitability Index: 2

  • Excel $B$N%U%!%$%k7A<0$N2r@O$N@HCVE-2010-3232

    Excel 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(BExcel 2002 $B$K$3$N7g4Y$O$J$$!#(BExploitability Index: 1

  • Lotus 1-2-3 $B$N%o!<%/%V%C%/$N2r@O$N@HCVE-2010-3233

    Excel 2002 / 2003 $B$N7g4Y!#(BExploitability Index: 2

  • $B?t<0$N%5%V%7%9%F%`$N%a%b%jGKB;$N@HCVE-2010-3234

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B?t<0$N(B Biff $B$N%l%3!<%I$N@HCVE-2010-3235

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B6-3&30$NG[Ns$N@HCVE-2010-3236

    Excel 2002$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$N7g4Y!#(BExploitability Index: 1

  • $B%;%k$N7k9g$N%l%3!<%I(B $B%]%$%s%?!<$N@HCVE-2010-3237

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

  • Negative Future Function $B$N@HCVE-2010-3238

    Excel 2002 / 2003$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 1

  • $B$=$NB>$N6-3&30$N%l%3!<%I$N2r@O$N@HCVE-2010-3239

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B%j%"%k(B $B%?%$%`$N%G!<%?G[Ns$N%l%3!<%I$N@HCVE-2010-3240

    Excel 2002 / 2007$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$N7g4Y!#(BExploitability Index: 2

  • $B2r@O$K$*$1$k6-3&30$N%a%b%j$N=q$-9~$_$N@HCVE-2010-3241

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

  • $BHsCVE-2010-3242

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

MS10-081 - $B=EMW(B: Windows $B%3%b%s(B $B%3%s%H%m!<%k(B $B%i%$%V%i%j$N@H

MS10-082 - $B=EMW(B: Windows Media Player $B$N@H

MS10-083 - $B=EMW(B: Windows $B%7%'%k$*$h$S%o!<%I%Q%C%I$N(B COM $B$N8!>Z$N@H

MS10-084 - $B=EMW(B: Windows $B%m!<%+%k(B $B%W%m%7!<%8%c!<(B $B%3!<%k$N@H:3J$5$l$k(B (2360937)

$B!!(BWindows XP / Server 2003 $B$N(B Remote Procedure Call Subsystem (RPCSS) $B$K7g4Y!#(B RPCSS $B$K4^$^$l$k(B LRPC Server (Local RPC Server; RPC EndPoint Mapper) $B$H!"(B LPC (Local Procedure Call) $B$H$N4V$N%]!<%H%a%C%;!<%8$N=hM}$K(B buffer overrun $B$9$k7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:(B (LocalSystem $BC%CVE-2010-3222$B!#(BExploitability Index: 1

MS10-085 - $B=EMW(B: SChannel $B$N@H

MS10-086 - $B7Y9p(B: Windows $B6&M-%/%i%9%?!<(B $B%G%#%9%/$N@H

$B!!(BWindows Server 2008 R2 $B$K7g4Y!#6&M-%U%'!<%k%*!<%P!<%/%i%9%?!<$H$7$F;HMQ$7$F$$$k>l9g$K!"!V4IM}Z$5$l$F$$$J$$%f!<%6!<(B (Everyone) $B$K%U%'!<%k%*!<%P!<(B $B%/%i%9%?!<(B $B%G%#%9%/$N4IM}MQ6&M-$X$NFI$_CVE-2010-3223

$B!!(Bhotfix $B$rE,MQ$7$?8e$G!"4{$K@_Dj$5$l$F$$$k%U%'!<%k%*!<%P!<%/%i%9%?!<%G%#%9%/$K$D$$$F$O!"(B Everyone $B%U%k%3%s%H%m!<%k$r(B Administrators $B%U%k%3%s%H%m!<%k$KJQ99$9$k$3$H!#(B

$B"#(B RealNetworks, Inc.$B!"%;%-%e%j%F%#@H
(RealNetworks, 2010.10.15)

$B!!(BWindows / Mac / Linux $BHG$N(B RealPlayer $B$K?7$?$J(B 7 $B


$B"#(B 2010.10.18


$B"#(B 2010.10.16


$B"#(B 2010.10.15

$B"#(B JP$B%>!<%s$K$*$1$k(BDNSSEC$B=pL>$N3+;O$K$h$k1F6A$K$D$$$F(B
(JPRS, 2010.10.15)

$B!!$$$h$$$h$O$8$^$k$h(B!

JPRS$B$G$O!"(BJP$B%I%a%$%sL>%5!<%S%9$X$N(BDNSSEC$B$NF3F~$K@hN)$A!"(B2010$BG/(B10$B7n(B17$BF|$h$j(BJP$B%>!<%s$K$*$1$k(BDNSSEC$B=pL>(B($B0J2!W$H$7$^$9(B)$B$r3+;O$7$^$9!#(B
$B%P!<%8%g%s(B9.3$B0J9_$N(BBIND 9$B$d(BUnbound$B$J$I!"%-%c%C%7%e(BDNS$B%5!<%P!<$+$i$N(BDNS$BLd$$9g$o$;$K$*$$$F(BDO$B%S%C%H$,M-8z$K@_Dj$5$l$F$$$k>l9g$O!":#2s$N(BDNSSEC$B=pL>$K$h$C$F%-%c%C%7%e(BDNS$B%5!<%P!A08!>Z$rM-8z$K@_Dj$7$F$$$k!?$$$J$$$K$+$+$o$i$:!"(BJP DNS$B$+$i$N1~Ez$K(BDNSSEC$B4XO"$N>pJs$,DI2C$5$l$k$h$&$K$J$j$^$9!#(B

$B$3$l$K$h$j(BJP DNS$B$+$i$N(BDNS$B1~Ez%5%$%:$,A}Bg$7!"%-%c%C%7%e(BDNS$B%5!<%P!<$K$*$$$FJ];}$5$l$k>pJs$bA}Bg$7$^$9!#$=$N$?$a!"(BDNSSEC$B=pL>$N3+;O8e!"3F%-%c%C%7%e(BDNS$B%5!<%P!<$K$*$1$k%M%C%H%o!<%/$N;HMQ>u67$N3NG'$d!"(Bnamed$B$d(Bunbound$B$J$I$N%M!<%`%5!<%P!<%W%m%0%i%`$K$*$1$k%a%b%j;HMQ>u67$N3NG'$r

$B!!8=>u$G4{$K$+$D$+$D$@$H!"$A$g$C$H$"$l$+$b$7$l$^$;$s!#Cm0U$7$^$;$&!#(B

$B"#(B facebook$B$N(BDelete$B%\%?%s!!$I$&$d$i2hA|$r>C$9$N$K(B1$BG/0J>e$+$+$kMM;R(B
(gizmodo, 2010.10.14)

$B!!>C$7$?$O$:$,!"C$($F$J$$$=$&$G!#(B

$B:8$Ne$Kl$G$9$0>C$($?$N$O!"$3$N

$B!!@NJ9$$$?;w$?$h$&$JOC(B: $B%^%$%^%C%W$r:o=|$7$F$b!V$9$0!W$K$O>C$($J$$(B ($BMn8`Do;R$N%V%m%0(B, 2008.11.07)

$B"#(B Oracle Critical Patch Update Advisory - October 2010
(Oracle, 2010.10.13)

$B!!(BOracle $BJ}LL!"$$$m$$$mBgNL$K=P$F$$$^$9!#(B

$B"#(B $B$$$m$$$m(B (2010.10.15)
(various)

$B"#(B $BDI5-(B


$B"#(B 2010.10.14

$B"#(B Oracle Java SE and Java for Business Critical Patch Update Advisory - October 2010
(Oracle, 2010.10.13)

$B!!(BJava SE 6 Update 22 $BEP>l!#(B29 $B$B%@%&%s%m!<%I(B

$B!!4{$K(B Java SE 5.0 $B$O(B End of Servie Life (EOSL) $B$r7^$($F$$$k$N$GCm0U!#(B for Business Support $B$K$D$$$F$O$^$@$^$@B3$$$F$$$k$h$&$G$9$,!#(B JavaSE and Java for Business Support Roadmap (Oracle)$B!#(B Java SE 6 $B$bMhG/Kv$K$O(B EOSL $B$H$J$k$h$&$G$9!#(B

2010.10.21 $BDI5-(B:

$B!!(BMac OS X 10.6 $BMQ(B Java $B$b(B Java SE 6 Update 22 $B$K$J$j$^$7$?!#(B Mac OS X 10.5 $B$K$O(B Java SE 5.0 Update 26 $B$,MQ0U$5$l$^$7$?!#(B (Java SE 5.0 Update 26 $B$O!"$"$k0UL#!"5.=E$J$h$&$J!D!D(B)

$B!!4XO"(B: In other Apple news... Java updates (Sophos, 2010.10.20)


$B"#(B 2010.10.13

$B"#(B $BDI5-(B

$B"#(B $B%&%$%k%9%P%9%?!<(B2010$B$KB8:_$9$k@H
($B%H%l%s%I%^%$%/%m(B, 2010.10.13)

$B"#(B Opera 10.63 released
(Opera, 2010.10.13)

$B!!(BOpera 10.63 $B=P$^$7$?!#J#?t$N%;%-%e%j%F%#=$@5$,4^$^$l$F$$$^$9!#(B

$B"#(B Microsoft 2010 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2010.10.13)

$B!!=P$^$7$?!#(BMS10-071 $B!A(B MS10-086$B!#@h7n$N(B MS10-063 $B$K$R$-$D$E$-!":#7n$b(B OpenType $B$M$?$,$"$k$N$@$J$"!#(B($B$"$H$GDI5-$9$kM=Dj(B)

$B!!4XO"(B:

2010.10.19 $BDI5-(B:

MS10-071 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (2360131)

$B!!(BIE 6 / 7 / 8 $B$K(B 10 $B8D$N7g4Y!#(B

  • $B%*!<%H%3%s%W%j!<%H$N>pJsO3$($$$N@HCVE-2010-0808

    Windows XP / Vista $B>e$N(B IE 6 / 7 $B$N7g4Y!#(B $B!V%*!<%H%3%s%W%j!<%H5!G=$,M-8z$K$5$l$F$$$?>l9g!"%U%)!<%`(B $B%U%#!<%k%I$KF~NO$5$l$?FbMF$r%-%c%W%A%c$9$k2DG=@-$,$"$j$^$9!W(B

  • HTML $B$N%5%K%?%$%:$N@HCVE-2010-3243

    IE 8 $B$N(B toStaticHTML API $B$N7g4Y!"(BXSS $B$,H/@8!#!V%f!<%6!<$N%;%-%e%j%F%#(B $B%3%s%F%-%9%H$G(B Web $B%5%$%H$KBP$7%9%/%j%W%H$,

  • HTML $B$N%5%K%?%$%:$N@HCVE-2010-3324

    IE 8 $B$N(B toStaticHTML API $B$N7g4Y!"(BXSS $B$,H/@8!#!V%f!<%6!<$N%;%-%e%j%F%#(B $B%3%s%F%-%9%H$G(B Web $B%5%$%H$KBP$7%9%/%j%W%H$,

  • CSS $BFCpJsO3$($$$N@HCVE-2010-3325

    IE 6 / 7 / 8 $B$N7g4Y!#!V(BInternet Explorer $B$,(B CSS $B$NFC

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3326

    IE 6 $B$N7g4Y!#96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B%"%s%+!pJsO3$($$$N@HCVE-2010-3327

    IE 6 / 7 / 8 $B$N7g4Y!#!V:o=|:Q$_$N>pJs$,(B HTML $B%3%s%F%s%D$K;D$k2DG=@-$,$"$j$^$9!W(B

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3328

    IE 6 / 7 / 8 $B$N7g4Y!#96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3329

    IE 7 / 8 $B$N7g4Y!#(BHtmlDlgHelper Class COM $B%*%V%8%'%/%H$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$K$h$jG$0U$N%3!<%I$,

  • $B%/%m%9(B $B%I%a%$%s$N>pJsO3$($$$N@HCVE-2010-3330

    IE 6 / 7 / 8 $B$N7g4Y!#!V(BInternet Explorer $B$N%;%-%e%j%F%#(B $B%>!<%s$^$?$OJL$N%I%a%$%s$+$i%3%s%F%s%D$r1\Mw$9$k2DG=@-$,$"$j$^$9!W!#(BExploitability Index: 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-3331

    IE 6 / 7 / 8 $B$N7g4Y!#96N,(B Word $B%I%-%e%a%s%H$r3+$-!"JD$8$k$HG$0U$N%3!<%I$,

$B!!(BHotfix $B$K4^$^$l$kHs%;%-%e%j%F%#$J=$@5$O$3$A$i(B: KB 2360131

MS10-072 - $B=EMW(B: SafeHTML $B$N@HpJsO3$($$$,5/$3$k(B (2412048)

$B!!(BSharePoint Services 3.0$B!"(BSharePoint Foundation 2010$B!"(B SharePoint Server 2007$B!"(BGroove Server 2010$B!"(BOffice Web Apps $B$K!">pJsO31L$K4X$9$k(B 2 $B$D$N7g4Y!#(BSafeHTML $B$K7g4Y$,$"$j!"(BXSS $B$,H/@8!"(Blocal user $B$N%3%s%F%-%9%H$G967b%9%/%j%W%H$,CVE-2010-3243 (Exploitability Index: 3)$B!"(B CVE-2010-3324 (Exploitability Index: 3)

MS10-073 - $B=EMW(B: Windows $B%+!<%M%k%b!<%I(B $B%I%i%$%P!<$N@H:3J$5$l$k(B (981957)

$B!!(BWidnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B%+!<%M%k%b!<%I%I%i%$%P!<$K(B 3 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B

  • Win32k $B$N;2>H%+%&%s%H$N@HCVE-2010-2549

    Windows Vista / Server 2008 $B$N7g4Y!#(BExploitability Index: 3

  • Win32k $B$N%-!<%\!<%I$N%l%$%"%&%H$N@HCVE-2010-2743

    Widnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N7g4Y!#(BWidnows XP $B$O!V=EMW!W!"$=$NB>$O!VCm0U!W!#$3$N7g4Y$rMxMQ$9$k%^%k%&%'%"$,B8:_!#(BExploitability Index: 1

  • Win32k $B$N%&%#%s%I%&(B $B%/%i%9$N@HCVE-2010-2744

    Widnows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$N7g4Y!#(BExploitability Index: 1

MS10-074 - $B7Y9p(B: Microsoft Foundation Classes $B$N@H

MS10-075 - $B6[5^(B: Windows Media Player $B%M%C%H%o!<%/6&M-%5!<%S%9$N@H

MS10-076 - $B6[5^(B: Embedded OpenType $B%U%)%s%H(B $B%(%s%8%s$N@H

MS10-077 - $B6[5^(B: .NET Framework $B$N@H

MS10-078 - $B=EMW(B: OpenType $B%U%)%s%H(B (OTF) $B7A<0%I%i%$%P!<$N@H:3J$5$l$k(B (2279986)

$B!!(BWindows XP / Server 2003 $B$K7g4Y!#(B OpenType $B%U%)%s%H(B (OTF) $B7A<0%I%i%$%P!<$K(B 2 $B$D$N7g4Y$,$"$j!"(B local user $B$K$h$k8"8B>e>:$,2DG=!#(B $B96N,(B OpenType $B%U%)%s%H$rKd$a9~$s$@(B Web $B%Z!<%8$r(B (IE $B$G$O$J$/(B) 3rd party $B@=(B Web $B%/%i%$%"%s%H$G3+$/$H967b$,@.N)$9$k!#(B

  • OpenType $B%U%)%s%H$N2r@O$N@HCVE-2010-2740$B!#(BExploitability Index: 1

  • OpenType $B%U%)%s%H$N8!>Z$N@HCVE-2010-2741$B!#(BExploitability Index: 1

MS10-079 - $B=EMW(B: Microsoft Word $B$N@H

$B!!(BWord 2002 / 2003 / 2007 / 2010$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWord Viewer$B!"(BOffice Web Apps$B!"(BWord Web App $B$K(B 11 $B8D$N7g4Y!#BgH>$N7g4Y$O(B Word 2002 $B$H(B Office 2004 for Mac $B$K$7$+1F6A$7$J$$!#(B

  • Word $B$N=i4|2=$5$l$F$$$J$$%]%$%s%?!<$N@HCVE-2010-2747

    Exploitability Index: 2

  • Word $B$N6-3&%A%'%C%/$N@HCVE-2010-2748

    Exploitability Index: 2

  • Word $B$N%$%s%G%C%/%9$N@HCVE-2010-2750

    Exploitability Index: 2

  • Word $B$N%9%?%C%/(B $B%*!<%P!<%U%m!<$N@HCVE-2010-3214

    Word 2002 / 2003 / 2007 / 2010$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWord Viewer$B!"(BOffice Web Apps$B!"(BWord Web App $B$N7g4Y!#(BExploitability Index: 1

  • Word $B$NLa$jCM$N@HCVE-2010-3215

    Exploitability Index: 2

  • Word $B$N%V%C%/%^!<%/$N@HCVE-2010-3216

    Exploitability Index: 1

  • Word $B$N%]%$%s%?!<$N@HCVE-2010-3217

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N%R!<%W(B $B%*!<%P!<%U%m!<$N@HCVE-2010-3218

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N%$%s%G%C%/%9$N2r@O$N@HCVE-2010-3219

    Word 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Word $B$N2r@O$N@HCVE-2010-3220

    Exploitability Index: 2

  • Word $B$N2r@O$N@HCVE-2010-3221

    Word 2002 / 2003$B!"(BOffice 2004 for Mac$B!"(BWord Viewer $B$N7g4Y!#(BExploitability Index: 2

MS10-080 - $B=EMW(B: Microsoft Excel $B$N@H

$B!!(BExcel 2002 / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K(B 13 $B8D$N7g4Y!#(B

  • Excel $B$N%l%3!<%I$N2r@O$N@0?t%*!<%P!<%U%m!<$N@HCVE-2010-3230

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 2

  • Excel $B%l%3!<%I2r@O$N%a%b%jGKB;$N@HCVE-2010-3231

    Excel 2002$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$N7g4Y!#(BExploitability Index: 2

  • Excel $B$N%U%!%$%k7A<0$N2r@O$N@HCVE-2010-3232

    Excel 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(BExcel 2002 $B$K$3$N7g4Y$O$J$$!#(BExploitability Index: 1

  • Lotus 1-2-3 $B$N%o!<%/%V%C%/$N2r@O$N@HCVE-2010-3233

    Excel 2002 / 2003 $B$N7g4Y!#(BExploitability Index: 2

  • $B?t<0$N%5%V%7%9%F%`$N%a%b%jGKB;$N@HCVE-2010-3234

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B?t<0$N(B Biff $B$N%l%3!<%I$N@HCVE-2010-3235

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B6-3&30$NG[Ns$N@HCVE-2010-3236

    Excel 2002$B!"(BOffice 2004 / 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$N7g4Y!#(BExploitability Index: 1

  • $B%;%k$N7k9g$N%l%3!<%I(B $B%]%$%s%?!<$N@HCVE-2010-3237

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

  • Negative Future Function $B$N@HCVE-2010-3238

    Excel 2002 / 2003$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 1

  • $B$=$NB>$N6-3&30$N%l%3!<%I$N2r@O$N@HCVE-2010-3239

    Excel 2002 $B$N$_$N7g4Y!#(BExploitability Index: 1

  • $B%j%"%k(B $B%?%$%`$N%G!<%?G[Ns$N%l%3!<%I$N@HCVE-2010-3240

    Excel 2002 / 2007$B!"(BExcel Viewer$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$N7g4Y!#(BExploitability Index: 2

  • $B2r@O$K$*$1$k6-3&30$N%a%b%j$N=q$-9~$_$N@HCVE-2010-3241

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

  • $BHsCVE-2010-3242

    Excel 2002$B!"(BOffice 2004 for Mac $B$N7g4Y!#(BExploitability Index: 2

MS10-081 - $B=EMW(B: Windows $B%3%b%s(B $B%3%s%H%m!<%k(B $B%i%$%V%i%j$N@H

MS10-082 - $B=EMW(B: Windows Media Player $B$N@H

MS10-083 - $B=EMW(B: Windows $B%7%'%k$*$h$S%o!<%I%Q%C%I$N(B COM $B$N8!>Z$N@H

MS10-084 - $B=EMW(B: Windows $B%m!<%+%k(B $B%W%m%7!<%8%c!<(B $B%3!<%k$N@H:3J$5$l$k(B (2360937)

$B!!(BWindows XP / Server 2003 $B$N(B Remote Procedure Call Subsystem (RPCSS) $B$K7g4Y!#(B RPCSS $B$K4^$^$l$k(B LRPC Server (Local RPC Server; RPC EndPoint Mapper) $B$H!"(B LPC (Local Procedure Call) $B$H$N4V$N%]!<%H%a%C%;!<%8$N=hM}$K(B buffer overrun $B$9$k7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:(B (LocalSystem $BC%CVE-2010-3222$B!#(BExploitability Index: 1

MS10-085 - $B=EMW(B: SChannel $B$N@H

MS10-086 - $B7Y9p(B: Windows $B6&M-%/%i%9%?!<(B $B%G%#%9%/$N@H

$B!!(BWindows Server 2008 R2 $B$K7g4Y!#6&M-%U%'!<%k%*!<%P!<%/%i%9%?!<$H$7$F;HMQ$7$F$$$k>l9g$K!"!V4IM}Z$5$l$F$$$J$$%f!<%6!<(B (Everyone) $B$K%U%'!<%k%*!<%P!<(B $B%/%i%9%?!<(B $B%G%#%9%/$N4IM}MQ6&M-$X$NFI$_CVE-2010-3223

$B!!(Bhotfix $B$rE,MQ$7$?8e$G!"4{$K@_Dj$5$l$F$$$k%U%'!<%k%*!<%P!<%/%i%9%?!<%G%#%9%/$K$D$$$F$O!"(B Everyone $B%U%k%3%s%H%m!<%k$r(B Administrators $B%U%k%3%s%H%m!<%k$KJQ99$9$k$3$H!#(B

2011.01.11 $BDI5-(B:

$B!!(BMS10-081: Windows Common Control Library (Comctl32) Heap Overflow (exploit-db.com, 2011.01.10)

$B"#(B $B#M#E#L#I#L!?#C#SF3F~?^=q4[$NMxMQpJsEy$NO31L$K4X$9$k6[5^MW@A(B
($B$H$b$s$1$s%&%#!<%/%j!<(B, 2010.10.11)

$B!!2,:j?^=q4[(B $B"*(B MELIL/CS $BJ}LL!#(B

$B!!>pJsN.=P$N:G=*@UG$$O<+<#BN$K$"$j!"<+<#BN$K$O$I$N$h$&$J>pJs$,$I$N$h$&$J7P0^$GN.=P$7$?$+$rD4::$7!"8xI=$7!":#8e:FH/$7$J$$$h$&BP:v$r9V$8$k@UL3$,$"$j$^$9!#4IM}6H$^$7$$$N$G$9$,!"$=$l$,IT2DG=$G$"$C$?$H$7$F$b<+$i$N@UG$$K$*$$$FK\7o$K$D$$$FD4::!&8!>Z$9$kI,MW$,$"$j$^$9!#$I$N$h$&$J>pJs$,N.=P$7$F$$$?$+!"B>$N?^=q4[$N$I$N$h$&$J>pJs$,<+4[%7%9%F%`$K:.F~$7$F$$$?$+$r?^=q4[!&<+<#BN$,GD0.$;$:!"C1$KN.=P%G!<%?$N>C5nEy$,9T$J$o$l$F$$$k$N$G$"$l$PLdBj$G$9!#2,:j;TN)Cf1{?^=q4[$N>l9g!"#M#D#I#S$OB>$N?^=q4[$KN.=P$7$?%G!<%?$rA4$F:o=|$7$?8e!"2,:j;TN)Cf1{?^=q4[$K>pJsO31L$rJs9p$7$F$$$^$9!#D>$A$KJs9p$r9T$J$o$J$+$C$?$3$H$d!"N.=P$7$?B&$N?^=q4[$KN.=P%G!<%?$r:o=|$9$k:]==J,$JJs9p$r9T$J$C$?$+!"$J$IBP1~$K5?Ld$,;D$j$^$9!#(B

$B!!K\7o$O!"8D?M>pJs5Z$S?^=q4[4X78%G!<%?$NJ#?t<+<#BN$K$^$?$,$k>pJsO31L;v7o$H$7$F!"Hs>o$K=EBg$J$b$N$G$9!#$=$N=EBg@-$K4U$_!"K\7o>pJsO31L$K$D$$$F@53N$K>pJs$rGD0.$7:FH/$rKI$0$?$a!"2<5-$NBP1~$r6[5^$KMW@A$$$?$7$^$9!#(B

$B!!6H

$B!!$H8@$C$F$$$k$&$A$K!"(B$B$?$j$-$5$s$,$^$?$_$D$1$?(B$B$=$&$G!#(B $B$($S$N$N(BFTP$B$G8x3+$5$l$F$$$?$b$N$+$i(B$B$@$=$&$G$9!#(B


$B"#(B 2010.10.12

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 9 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!L@F|$K$O(B 10 $B7nJ,$N(B patch $B$,=P$k$H$$$&F|$K$h$&$d$/!D!D!#(B

MS10-061 - $B6[5^(B: $B0u:~%9%W!<%i!<(B $B%5!<%S%9$N@H

MS10-062 - $B6[5^(B: MPEG-4 $B%3!<%G%C%/$N@H

MS10-063 - $B6[5^(B: Unicode $B%9%/%j%W%H(B $B%W%m%;%C%5$N@H

MS10-064 - $B6[5^(B: Microsoft Outlook $B$N@H

$B!!(BOutlook 2002 / 2003 / 2007 $B$K7g4Y!#(BOutlook $B$K$*$1$kEE;R%a!<%k$N=hM}$K7g4Y$,$"$j!"96N,EE;R%a!<%k$K$h$C$FG$0U$N%3!<%I$,CVE-2010-2728 $B!#(B $B$?$@$7!"(B

  • $B%*%s%i%$%s%b!<%I$G(B Exchange $B%5!<%P!<$K@\B3$9$k>l9g$K$N$_7g4Y$,H/8=$9$k!#(BExchange $B%-%c%C%7%e%b!<%I(B ($B%G%U%)%k%H(B) $B$d!"(BPOP / IMAP $B%5!<%P$N$_$r;HMQ$9$k>l9g$K$O!"$3$N7g4Y$OH/8=$7$J$$!#(B

MS10-065 - $B=EMW(B: Microsoft $B%$%s%?!<%M%C%H(B $B%$%s%U%)%a!<%7%g%s(B $B%5!<%S%9(B (IIS) $B$N@H

$B!!(BIIS 5.1 / 6.0 / 7.0 / 7.5 $B$K(B 3 $B$D$N7g4Y!#(B

  • IIS $B$N7+$jJV$5$l$?%Q%i%a!<%?!<(B $B%j%/%(%9%H$N%5!<%S%95qH]$N@HCVE-2010-1899

    IIS 5.1 / 6.0 / 7.0 / 7.5 $B$K7g4Y!#(B ASP $B%9%/%j%W%H=hM}$K7g4Y$,$"$j!"(B.asp $B$X$N96N,%j%/%(%9%H$K$h$C$F(B stack overflow $B$,H/@8!"(BIIS $B$,1~Ez$rDd;_$9$k!#(B

  • $B%j%/%(%9%H(B $B%X%C%@!<$N%P%C%U%!!<(B $B%*!<%P!<%U%m!<$N@HCVE-2010-2730

    IIS 7.5 $B$K7g4Y!#(BFastCGI $B$,M-8z$J>l9g$N%j%/%(%9%H%X%C%@!<$N=hM}$K7g4Y$,$"$j!"(Bremote $B$+$iG$0U$N%3!<%I$r

  • $B%G%#%l%/%H%jG'>Z$N2sHr$N@HCVE-2010-2731

    IIS 5.1 $B$K7g4Y!#(BURL $B$N2r@O$K$*$$$F7g4Y$,$"$j!"96N,%j%/%(%9%H$K$h$C$F!"G'>Z$,I,MW$J$O$:$N%Z!<%8$KL5G'>Z$G%"%/%;%9$G$-$k!#(B

MS10-066 - $B=EMW(B: $B%j%b!<%H(B $B%W%m%7!<%8%c!<(B $B%3!<%k$N@H

MS10-067 - $B=EMW(B: $B%o!<%I%Q%C%I$N%F%-%9%H(B $B%3%s%P!<%?!<$N@H

MS10-068 - $B=EMW(B: Local Security Authority Subsystem Service (LSASS) $B$N@H:3J$5$l$k(B (983539)

$B!!(BWindows XP / Server 2003 / Vista (SP2 $B$N$_(B) / Server 2008 / 7 $B$K7g4Y!#96N,(B LSASS $B%a%C%;!<%8$K$*$$$F!"8"8B>e>:$,2DG=!#(B CVE-2010-0820

MS10-069 - $B=EMW(B: Windows $B%/%i%$%"%s%H(B/$B%5!<%P!<(B $B%i%s%?%$%`(B $B%5%V%7%9%F%`$N@H:3J$5$l$k(B (2121546)

$B!!(BWindows XP / Server 2003 $B$K7g4Y!#(B CSRSS $B$N%a%b%j4IM}$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B CVE-2010-1891 $B!#(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B!!(BAdobe Patches Vulnerabilities (Symantec, 2010.10.12)$B!#(BJavaScript $B$rL58z$K$7$F$b967b%3!<%I$,5/F0$5$l$k96N,(B PDF $B%U%!%$%k$,=P2s$C$F$$$k$=$&$G$9!#(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2269637) $B0BA4$G$J$$%i%$%V%i%j$N%m!<%I$K$h$j!"%j%b!<%H$G%3!<%I$,

Stuxnet worm 'targeted high-value Iranian assets'

$B!!(BDetecting PLC Infections (Symantec, 2010.10.08)

$B"#(B APSB10-21: Security updates available for Adobe Reader and Acrobat
(Adobe, 2010.10.05)

$B!!(BCVE-2010-2883 (APSA10-02: Security Advisory for Adobe Reader and Acrobat $B$N7o(B)$B!"(B CVE-2010-2884 (APSA10-03: Security Advisory for Flash Player $B$N7o(B) $B$NB>$K$b!"0J2<$,=$@5$5$l$F$$$k!#(B

$B"#(B JVN#82752978: Lhaplus $B$K$*$1$k(B DLL $BFI$_9~$_$K4X$9$k@H
(JVN, 2010.10.12)

$B"#(B JVN#88850043: Lhasa $B$K$*$1$k
(JVN, 2010.10.12)


$B"#(B 2010.10.11


$B"#(B 2010.10.09


$B"#(B 2010.10.08

$B"#(B $BDI5-(B

Stuxnet worm 'targeted high-value Iranian assets'

$B!!(BStuxnet (Schneier on Security, 2010.10.07)

$B"#(B 2010$BG/(B10$B7n(B13$BF|$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($B7nNc(B)
($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.10.07)

$B!!$&$o!"$b$&$=$s$J5(@a$@$h!D!D!#$7$+$b(B 16 $B8D$b$"$k$h(B ($B6[5^(B x 4$B!"=EMW(B x 10$B!"7Y9p(B x 2) $B!#(BOffice $B$b4^$^$l$F$k$J$"!#(BOffice 2010 $B$d(B Mac $BHG$b4^$^$l$F$k!#(B


$B"#(B 2010.10.07

$B"#(B $B$$$m$$$m(B (2010.10.07)
(various)

$B"#(B $BDI5-(B

$B"#(B Foxit Reader: Fixed identity theft issue caused by the security flaw of the digital signature.
(foxitsoftware.com, 2010.09.29)

$B!!(BFoxit Reader 4.1.x $B0JA0$K7g4Y!#>\:YITL@$@$,!"2~cb$5$l$?!&:>>N$5$l$?EE;R=pL>$N07$$$K7g4Y$,$"$kLOMM!#(BFoxit Reader 4.2 $B$G=$@5$5$l$F$$$k!#(B


$B"#(B 2010.10.06

$B"#(B PostgreSQL 2010-10-05 Security Update
(PostgreSQL.org, 2010.10.05)

$B!!(BPostgreSQL 9.0.1 / 8.4.5 / 8.3.12 / 8.2.18 / 8.1.22 / 8.0.26 / 7.4.30 $BEP>l!#(B

The security vulnerability allows any ordinary SQL users with "trusted" procedural language usage rights to modify the contents of procedural language functions at runtime. As detailed in CVE-2010-3433, an authenticated user can accomplish privilege escalation by hijacking a SECURITY DEFINER function (or some other existing authentication-change operation). The mere presence of the procedural languages does not make your database application vulnerable.

$B!!:#2s$N=$@5$G$O!"(B PL/Tcl $B$B$H(B PL/Perl$B$B!"$*$h$S(B SECURITY DEFINER $B$,=$@5$5$l$F$$$k!#(BPL/PHP $B$N=$@5$O$^$@!#(B $BB>$N(B trusted $B$J(B 3rd $B%Q!<%F%#@=

$B!!$J$*!"(BPostgreSQL 8.0.26 / 7.4.30 $B$O!"$3$l$,:G=*%j%j!<%9!#(B

$B"#(B $BDI5-(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B!!(BAdobe Reader / Acrobat 9.4 / 8.2.5 $B=P$^$7$?(B: APSB10-21: Security updates available for Adobe Reader and Acrobat (Adobe, 2010.10.05)

APSA10-03: Security Advisory for Flash Player

$B!!(BAdobe Reader / Acrobat 9.4 / 8.2.5 $B=P$^$7$?(B: APSB10-21: Security updates available for Adobe Reader and Acrobat (Adobe, 2010.10.05)


$B"#(B 2010.10.05

$B"#(B $BDI5-(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B!!(BAdobe Reader$B$N=$@5HG$,(B10$B7n(B5$BF|$K8x3+!"%<%m%G%$@HC(B ($BF|7P(B IT Pro, 2010.10.04)$B!"(BAPSB10-21: Adobe Reader $B$H(B Acrobat $B$K4X$9$k%;%-%e%j%F%#>pJs$N;vA09pCN(B (Adobe, 2010.09.30)$B!#F|K\;~4V$NL@F|8x3+M=Dj!#(Bcadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

APSA10-03: Security Advisory for Flash Player

$B!!(BAdobe Reader$B$N=$@5HG$,(B10$B7n(B5$BF|$K8x3+!"%<%m%G%$@HC(B ($BF|7P(B IT Pro, 2010.10.04)$B!"(BAPSB10-21: Adobe Reader $B$H(B Acrobat $B$K4X$9$k%;%-%e%j%F%#>pJs$N;vA09pCN(B (Adobe, 2010.09.30)$B!#F|K\;~4V$NL@F|8x3+M=Dj!#(Bcadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

Stuxnet worm 'targeted high-value Iranian assets'

$B!!F|K\8lHG(B: W32.Stuxnet $B$ND4::>\:Y(B (Symantec, 2010.09.30)$B!#(BPDF $BJ8=q(B $B$OF|K\8l2=$5$l$F$$$J$$!#(B

MS10-018 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (980182)

$B!!(BIE8 XSS Filter$B$N;EMM$,HyL/$KJQ99$5$l$F$$$?!#(B ($BMU$C$QF|5-(B, 2010.10.04)$B!#(BMS10-018 $B$K4^$^$l$k(B XSS Filter $B$NJQ99$N7o!#(B

$B!!$"$H!"!V$"$H$GDI5-!W$H8@$$$J$,$i2?$b$d$C$F$J$+$C$?$N$G$d$C$F$*$/!#(B

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-0267

    IE 6 / 7$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 3

  • $B%(%s%3!<%I8e$N>pJsO3$($$$N@HCVE-2010-0488

    IE 5.01 / 6 / 7$B!#(B $B>pJsO31L$r>7$/!#(B Exploitability Index: 3

  • $B6%9g>uBV$N%a%b%jGKB;$N@HCVE-2010-0489

    IE 5.01 / 6 / 7$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 2

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-0490

    IE 6 / 7 / 8$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 3

  • HTML $B%*%V%8%'%/%H$N%a%b%jGKB;$N@HCVE-2010-0491

    IE 5.01 / 6$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 1

  • HTML $B%*%V%8%'%/%H$N%a%b%jGKB;$N@HCVE-2010-0492

    IE 8$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 1

  • HTML $B%(%l%a%s%H$N%/%m%9(B $B%I%a%$%s$N@HCVE-2010-0494

    $B%j%b!<%H$+$i$N%3!<%IpJsO31L(B (IE 7 / 8) $B$r>7$/!#(B Exploitability Index: 1

  • $B%a%b%jGKB;$N@HCVE-2010-0805

    IE 5.01 / 6$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 2

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-0806

    IE 6 / 7$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 1

    $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (981374) Internet Explorer $B$N@H $B$N7o!#(B

  • HTML $B%l%s%@%j%s%0$N%a%b%jGKB;$N@HCVE-2010-0807

    IE 7$B!#(B $B%j%b!<%H$+$i$N%3!<%I7$/!#(B Exploitability Index: 1


$B"#(B 2010.10.04

$B"#(B $BDI5-(B


$B"#(B 2010.10.01

$B"#(B $BDI5-(B


[$B%;%-%e%j%F%#%[!<%k(B memo]