$B%;%-%e%j%F%#%[!<%k(B memo - 2011.07

Last modified: Sun Nov 20 00:02:05 2011 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2011.07.31

$B"#(B $B$$$m$$$m(B (2011.07.31)
(various)


$B"#(B 2011.07.29

$B"#(B $B$$$m$$$m(B (2011.07.29)
(various)

$B"#(B $BDI5-(B

SquirrelMail 1.4.22 $B%j%j!<%9(B

$B!!(BCVE-2011-2023 $B$bD>$C$F$$$k$_$?$$!#(B

Fixed in Apache Tomcat 7.0.17 (not yet released)

$B!!(BCVE-2011-2204 $B$N7o!"(BTomcat 7.0.19 $B$G=$@5$5$l$?!#(BTomcat 7.0.17 / 7.0.18 $B$O%j%j!<%9$5$l$F$$$J$$!#(B


$B"#(B 2011.07.28

$B"#(B $B$$$m$$$m(B (2011.07.28)
(various)

$B"#(B phpMyAdmin 3.4.3.2 and 3.3.10.3 are released
(phpMyAdmin, 2011.07.23)

$B!!(BphpMyAdmin 3.4.3.2 / 3.3.10.3 $BEP>l!#(B4 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B $B3F%"%I%P%$%6%j$K$O(B patch $B$bMQ0U$5$l$F$$$k!#(B


$B"#(B 2011.07.27

$B"#(B osCommerce $BMxMQ%5%$%H$KBP$9$kBg5,LO$J2~$6$s967b$,9T$o$l$F$$$kLOMM(B
(various)

$B!!$3$N$X$s(B:

2011.08.02 $BDI5-(B:

$B!!(B$B%7%g%C%T%s%0%5%$%HA@$&Bg5,LO2~$6$sH/@8!"9qFb%5%$%H$b%&%$%k%946@w$N62$l(B (so-net $B%;%-%e%j%F%#DL?.(B, 2011.07.28)

$B"#(B iWork: Security features in the iWork 9.1 Update
(Apple, 2011.07.25)

$B!!(BiWork 9.0$B!A(B9.0.5 $B$K(B 3 $B$D$N7g4Y!#96N,(B Excel $BJ8=q$d96N,(B Word $BJ8=q$r3+$/$HG$0U$N%3!<%I$,CVE-2010-3785 CVE-2010-3786 CVE-2011-1417

$B!!(BiWork 9.1 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B iOS 4.2.10 / 4.3.5 $BEP>l(B
(Apple, 2011.07.25)

$B!!FCDj$N>u672<$G(B SSL/TLS $B$rGK$C$F%G!<%?$rCVE-2011-0228

$B!!4XO"(B: Unpatched iPhones/iPads secure connections not so secure (Sophos, 2011.07.26)$B!"(Bsslsniff: Anniversary Edition (thoughtcrime.org, 2011.07.25)$B!#(B

Oddly the flaw in iOS was a widespread flaw in WebKit and Microsoft's CryptoAPI nine years ago. It allows any valid certificate purchased from a Certificate Authority to sign any other certificate, which the client device will then consider valid.

$B!!$D$^$j!"%*%l%*%l>ZL@=q$r42MF$K

The really bad news? If you are using an iPod Touch generation one or two, or an iPhone older than the 3GS, you will be perpetually vulnerable. Owners of these devices should not use them for any purpose for which security or privacy is required.

$B!!$&$2$'!D!D!#$7$+$7!"!V$$$D$b$N(B Apple $B>&K!!W$H$$$&5$$,$7$J$$$G$b$J$$!#(B


$B"#(B 2011.07.26


$B"#(B 2011.07.25

$B"#(B $B$$$m$$$m(B (2011.07.25)
(various)

2011.09.28 $BDI5-(B:

$B!!(BFoxit Reader 5.0.2 $B$N7o(B:


$B"#(B 2011.07.24

$B"#(B MacBook$B$N%P%C%F%j!<$K@H
(engadget, 2011.07.23)

$B!!%U%!!<%`%&%'%"$r=q$-$+$($F!"0-$N8B$j$r?T$/$;$kLOMM!#(B

$B%;%-%e%j%F%#!<8&5f

2011.07.25 $BDI5-(B:

$B!!4XO"(B:


$B"#(B 2011.07.23


$B"#(B 2011.07.22

$B"#(B $BDI5-(B

About the security content of Safari 5.1 and Safari 5.0.6

$B!!(BMac OS X 10.6 $B$G$O(B Safari 5.0.6 $B$G$O$J$/(B Safari 5.1 $B$J$N$G!"5-=R$r$=$N$h$&$K=$@5$7$?!#(B


$B"#(B 2011.07.21

$B"#(B $B$$$m$$$m(B (2011.07.21)
(various)

$B"#(B About the security content of Safari 5.1 and Safari 5.0.6
(Apple, 2011.07.20)

$B!!(BSafari 5.1 (Mac OS X 10.6 / 10.7, Windows) $B$*$h$S(B 5.0.6 (Mac OS X 10.5) $BEP>l!#(B $B9g7W(B 58 $B

$B!!4XO"(B: Safari 5.1 $B$H(B Acrobat/Adobe Reader $B$N8_49@-$K$D$$$F(B (Adobe)$B!#(BMac OS X $B$G$NOC!#(B

2011.07.22 $BDI5-(B:

$B!!(BMac OS X 10.6 $B$G$O(B Safari 5.0.6 $B$G$O$J$/(B Safari 5.1 $B$J$N$G!"5-=R$r$=$N$h$&$K=$@5$7$?!#(B

2011.08.02 $BDI5-(B:

$B!!(BBizarre Apple Safari cookie bug perplexes users (Sophos, 2011.07.30)$B!#(BSafari 5.1 / Mac OS X 10.6.8 $B$N(B cookie $B$^$o$j$NIT6q9g$J$I!#(B

$B"#(B Oracle Critical Patch Update Advisory - July 2011
(Oracle, 2011.07.20)

$B!!M=Dj$I$*$j$$$C$Q$$=P$F$^$9!#(B


$B"#(B 2011.07.20


$B"#(B 2011.07.19

$B"#(B SquirrelMail 1.4.22 $B%j%j!<%9(B
(SquirrelMail.org, 2011.07.12)

$B!!(BSquirrelMail 1.4.22 $BEP>l!#(B

$B!!4XO"(B:

2011.07.29 $BDI5-(B:

$B!!(BCVE-2011-2023 $B$bD>$C$F$$$k$_$?$$!#(B


$B"#(B 2011.07.18

$B"#(B $B$$$m$$$m(B (2011.07.18)
(various)

2011.08.24 $BDI5-(B:

$B!!(BTrendMicro Control Manager CASProcessor.exe BLOB Remote Code Execution Vulnerability (ZeroDay Initiative, 2011.07.12) $B$N7o$NF|K\8lHG(B patch:

$B"#(B Skype$B$N%;%-%e%j%F%#%[!<%k$,8+$D$+$k(B - $BMh=5Cf$K$O%Q%C%A$,(B
(techcrunch, 2011.07.16)

$B!!(BWindows / Mac $BHG$N(B Skype 5.3.0.120 ($B:G?7HG(B) $B0JA0$K7g4Y!#(B $B%W%m%U%#!<%k$N(B mobile phone $B%(%s%H%j(B ($BF|K\8lHG$@$H!V7HBSEEOC!W$G$9$+$M!D!D(B) $B$N=hM}$K(B XSS $B7g4Y$,$"$j!"%;%C%7%g%s(B cookie $B$N%O%$%8%c%C%/$J$I$,2DG=$H$J$k!#(B Linux $BHG$K$O$3$N7g4Y$O$J$$!#(B

$B!!:#=5Cf$K(B patch $B$,=P$k$i$7$$$,!"$^$@=P$F$$$J$$!#(B

$B!!>\:Y!"(BPoC: http://www.noptrix.net/advisories/skype_xss.txt

$B"#(B $BDI5-(B

SoftBank$B%,%i%1!<$NCWL?E*$J@HC(B

$B!!(Bsecure.softbank.ne.jp$BGQ;_$G$-$^$;$s(B!? ($B?eL57n$P$1$i$N$($SF|5-(B, 2011.07.07)

JailbreakMe 3.0

$B!!(BiOS 4.2.9 / 4.3.4 $B$G=$@5$5$l$?LOMM!#(B

$B!!$7$+$7!"iOS 4.3.4 Jailbroken Already On iPhone, iPad, iPod touch Using PwnageTool Bundle [Tutorial] (redmondpie.com, 2011.07.15)

$B"#(B VLC 1.1.11 $B%j%j!<%9(B
(VideoLAN.org, 2011.07.15)

$B!!(BVLC 1.1.11 $BEP>l!#(B2 $B7o$N7g4Y$,=$@5$5$l$F$$$^$9!#(B


$B"#(B 2011.07.13

$B"#(B Microsoft 2011 $BG/(B 7 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2011.07.13)

$B!!M=Dj$I$*$j(B 4 $B7o!#(B

MS11-053 - $B6[5^(B: Bluetooth $B%9%?%C%/$N@H

MS11-054 - $B=EMW(B: Windows $B%+!<%M%k%b!<%I%I%i%$%P!<$N@H:3J$5$l$k(B (2555917)

$B!!(BWindows XP / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B Windows $B%+!<%M%k$K(B 15 $Be>:$,2DG=!#(B

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1874

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1875

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1876

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1877

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1878

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1879

  • Win32k $B$N(B NULL $B%]%$%s%?!<5U;2>H$N@HCVE-2011-1880

  • Win32k $B$N(B NULL $B%]%$%s%?!<5U;2>H$N@HCVE-2011-1881

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1882

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1883

  • Win32k $B$N2rJ|8e;HMQ$N@HCVE-2011-1884

  • Win32k $B$N(B NULL $B%]%$%s%?!<5U;2>H$N@HCVE-2011-1885

  • Win32k $B$NITE,@Z$J%Q%i%a!<%?!<8!>Z$K$h$k>pJsO3$($$$N@HCVE-2011-1886

  • Win32k $B$N(B NULL $B%]%$%s%?!<5U;2>H$N@HCVE-2011-1887

  • Win32k $B$N(B NULL $B%]%$%s%?!<5U;2>H$N@HCVE-2011-1888

MS11-055 - $B=EMW(B: Microsoft Visio $B$N@H

MS11-056 - $B=EMW(B: Windows $B%/%i%$%"%s%H(B/$B%5!<%P!<(B $B%i%s%?%$%`(B $B%5%V%7%9%F%`$N@H:3J$5$l$k(B (2507938)

$B!!(BWindows XP / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B CSRSS $B$N(B 5 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$d(B DoS $B967b$,2DG=!#(B

  • CSRSS $B%m!<%+%k(B EOP AllocConsole $B$N@HCVE-2011-1281

  • CSRSS $B%m!<%+%k(B EOP SrvSetConsoleLocalEUDC $B$N@HCVE-2011-1282

  • CSRSS $B%m!<%+%k(B EOP SrvSetConsoleNumberOfCommand $B$N@HCVE-2011-1283

  • CSRSS $B%m!<%+%k(B EOP SrvWriteConsoleOutput $B$N@HCVE-2011-1284

  • CSRSS $B%m!<%+%k(B EOP SrvWriteConsoleOutputString $B$N@HCVE-2011-1870

$B!!4XO"(B: MS11-056: Vulnerabilities in the Client/Server Runtime Subsystem and Console Host (Microsoft SRD, 2011.07.12)

$B!!4XO"(B:

$B"#(B $BDI5-(B

SoftBank$B%,%i%1!<$NCWL?E*$J@HC(B

$B!!(Bsecure.softbank.ne.jp$BGQ;_$NIqBfN"(B ($B?eL57n$P$1$i$N$($SF|5-(B, 2011.07.02)


$B"#(B 2011.07.12

$B"#(B $B$$$m$$$m(B (2011.07.12)
(various)


$B"#(B 2011.07.11


$B"#(B 2011.07.08

$B"#(B 2011 $BG/(B 7 $B7n(B 13 $BF|$N%;%-%e%j%F%#(B $B%j%j!<%9M=Dj(B ($B7nNc(B)
($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2011.07.08)

$B!!6[5^(B x 1$B!"=EMW(B x 3$B!#(BVisio 2003 $B$N=$@5$"$j!#(B

$B"#(B JailbreakMe 3.0
(jailbreakme.com, 2011.07.06)

$B!!(BJailbreakMe 3.0 $BEP>l!#(BiOS 4.3.3 $B0JA0$K$O%U%)%s%H$N=hM}$K7g4Y$,$"$j!"96N,(B PDF $B%U%!%$%k$r;H$C$F(B iOS $B$r(B jailbreak $B$G$-$kLOMM!#(B

$B!!8x<0$J=$@5$O$^$@$J$$!#(B

2011.07.18 $BDI5-(B:

$B!!(BiOS 4.2.9 / 4.3.4 $B$G=$@5$5$l$?LOMM!#(B

$B!!$7$+$7!"iOS 4.3.4 Jailbroken Already On iPhone, iPad, iPod touch Using PwnageTool Bundle [Tutorial] (redmondpie.com, 2011.07.15)

$B"#(B $BDI5-(B

SoftBank$B%,%i%1!<$NCWL?E*$J@HC(B

$B!!(B$B$_$:$[%@%$%l%/%H$NFf(B (ockeghem($BFA4]9@(B)$B$NF|5-(B, 2011.07.08)


$B"#(B 2011.07.07

$B"#(B $BDI5-(B


$B"#(B 2011.07.06

$B"#(B $B$$$m$$$m(B (2011.07.06)
(various)

$B"#(B $BDI5-(B

$B"#(B BIND $B$M$?(B 2 $B7o(B ($B6[5^$"$j(B)
(JPRS, 2011.07.05)

$B!J6[5^!K(BBIND 9.x$B$N@H]!"%P!<%8%g%s%"%C%W$r6/$/?d>)(B - (JPRS, 2011.07.05)

$B!!(BBIND 9.x $B$K7g4Y$,$"$j!"96N,(B DNS $B%Q%1%C%H$ro=*N;$9$k!#(B $B%-%c%C%7%e(B DNS $B%5!<%P!"8"0R(B DNS $B%5!<%P$NN>J}$K1F6A!#(B $B@_Dj$G$O2sHr$G$-$J$$!#(B CVE-2011-2464

$B!!(BBIND 9.6-ESV-R4-P3 / 9.7.3-P3 / 9.8.0-P4 $B$G=$@5$5$l$F$$$k!#(B

BIND 9.8.x$B$N(BResponse Policy Zones$B!J(BRPZ$B!K5!G=$Ne$N%P%0$K$h$k(B named$B$N%5!<%S%9Dd;_$K$D$$$F(B - $B%P!<%8%g%s%"%C%W$r6/$/?d>)(B - (JPRS, 2011.07.05)

$B!!(BBIND 9.8.x $B$K7g4Y!#(BResponse Policy Zones (RPZ) $B5!G=$K7g4Y$,$"$j!"(B $BFCDj$N>u67$K$*$$$FLd$$$"$o$;$ro=*N;$9$k!#(B $B%-%c%C%7%e(B DNS $B%5!<%P!"$+$D(B RPZ $B5!G=$,M-8z$G$"$k>l9g$K$N$_1F6A!#(B $B$3$N7g4Y$O(B BIND 9.7.x $B0JA0$K$OB8:_$7$J$$!#(B CVE-2011-2465

$B!!(BBIND 9.8.0-P4 $B$G=$@5$5$l$F$$$k!#(B


$B"#(B 2011.07.05

$B"#(B Alert: vsftpd download backdoored
(scarybeastsecurity.blogspot.com, 2011.07.03)

$B!!(Bvsftpd 2.3.4 $B$NG[I[%U%!%$%k$,!"$$$D$N$^$K$d$i%P%C%/%I%"IU$-$K$J$C$F$$$?7o!#(B $B%P%C%/%I%"IU$-$O(B:

2a4bb16562e0d594c37b4dd3b426cb012aa8457151d4718a5abd226cef9be3a5 vsftpd-2.3.4.tar.gz

$B!!@5$7$$%U%!%$%k$O(B https://security.appspot.com/vsftpd.html $B$GG[I[Cf!#(BFreeBSD ports $B$N(B distinfo $B$G$3$&$J$C$F$k$H$*$j$G$"$k$3$H$r3NG'$7$?!#(B

SHA256 (vsftpd-2.3.4.tar.gz) = b466edf96437afa2b2bea6981d4ab8b0204b83ca0a2ac94bef6b62b42cc71a5a
SIZE (vsftpd-2.3.4.tar.gz) = 187043

$B!!(Bgpg ./vsftpd-2.3.4.tar.gz.asc $B$r

2011.07.07 $BDI5-(B:

$B!!(Bvsftpd 2.3.4$B$K4^$^$l$?%P%C%/%I%"$K4X$9$k8!>Z%l%]!<%H(B (NTT$B%G!<%?@hC<5;=Q(B, 2011.07.06)

$B"#(B $BDI5-(B


$B"#(B 2011.07.04

$B"#(B SoftBank$B%,%i%1!<$NCWL?E*$J@HC(B
($B9bLZ9@8w!w<+Bp$NF|5-(B, 2011.06.30)


$B"#(B 2011.07.01

$B"#(B Drupal 7.3$B$*$h$S(B7.4$B%j%j!<%9!">u67$K1~$8$FMxMQ$9$k%P!<%8%g%s$rA*Br$9$k$h$&%"%I%P%$%9(B
(sourceforge.jp, 2011.07.01)

$B!!(BDrupal 7.3 / 7.4 $BEP>l!#(B Drupal 7.3 $B$O!"(BDrupal 7.2 $B$K%;%-%e%j%F%#=$@5(B SA-CORE-2011-002 - Drupal core - Access bypass (Drupal, 2011.06.30) $B$r;\$7$?$b$N!#(B Drupal 7.4 $B$O!"(BDrupal 7.3 $B$KB>$N%P%0=$@5$r;\$7$?$b$N!#4XO"(B:

$B"#(B WordPress 3.1.4
(WordPress.org, 2011.06.29)

$B!!J#?t$N%;%-%e%j%F%#=$@5$,4^$^$l$l$F$$$k$=$&$G$9!#(B


[$B%;%-%e%j%F%#%[!<%k(B memo]