$B%;%-%e%j%F%#%[!<%k(B memo - 2011.09

Last modified: Wed Jan 11 19:07:25 2012 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2011.09.30

$B"#(B $BDI5-(B

$BDL?.$rJ]8n$9$k!V(BSSL$B!?(BTLS$B!W$N@H

$B!!$$$m$$$m=P$F$-$F$^$9!#(B

Firefox 7.0 / 3.6.23$B!"(BThunderbird 7.0 / 3.1.15$B!"(BSeaMonkey 2.4 $BEP>l(B

$B!!(BFirefox 7.0.1 $B=P$^$7$?!#(BThunderbird 7.0.1 $B$b(B$B:#F|?$B$@$=$&$G$9!#(Biida $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BMFSA 2011-38 $B$O!"(B Firefox 7.0 / SeaMonkey 2.4 $B$G$O$J$/(B Firefox 6.0 / SeaMonkey 2.3 $B$G=$@5$5$l$F$$$k$H$5$l$F$$$^$9!#(BFirefox 3.6 $B7ONs$G$O(B 3.6.23 $B$G=$@5$J$N$G!"$=$l$^$GHs8x3+$@$C$?$h$&$G$9!#(B $B$9$:$-$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2011.09.29

$B"#(B Firefox 7.0 / 3.6.23$B!"(BThunderbird 7.0 / 3.1.15$B!"(BSeaMonkey 2.4 $BEP>l(B
(various, 2011.09.27)

$B!!(BFirefox 7.0 / 3.6.23$B!"(BThunderbird 7.0 / 3.1.15$B!"(BSeaMonkey 2.4 $BEP>l$G$9!#(B $B=$@59`L\$O0J2<$N$H$*$j!#(B

SA $BHV9f(B $B=EMWEY(B $B35MW(B F 7.0 F 3.6.23 T 7.0 T 3.1.15 S 2.4
MFSA 2011-36 $B:G9b(B $BMM!9$J%a%b%j0BA4@-$NLdBj(B (rv:7.0 / rv:1.9.2.23) X X X ? X
MFSA 2011-37 $B:G9b(B JavaScript RegExp $B;HMQ;~$N@0?t%*!<%P!<%U%m!<(B X
MFSA 2011-38 $B9b(B $B%W%i%0%$%s$H1#$Z$$$5$l$?(B window.location $B%*%V%8%'%/%H$rDL$8$?(B XSS X X X ? X
MFSA 2011-39 $BCf(B CRLF $B%$%s%8%'%/%7%g%s$K$h$kJ#?t(B Location $B%X%C%@$X$NBP:v(B X X X ? X
MFSA 2011-40 $B:G9b(B Enter $B%-!<$N2!2<7QB3$K$h$k%3!<%I$N%$%s%9%H!<%k(B X X X ? X
MFSA 2011-41 $B:G9b(B $B@x:_E*$K0-MQ2DG=$J(B WebGL $B$N%/%i%C%7%e(B X X
MFSA 2011-42 $B:G9b(B YARR $B@55,I=8=%i%$%V%i%j$K$*$1$k@x:_E*$K0-MQ2DG=$J%/%i%C%7%e(B X X X
MFSA 2011-43 $B:G9b(B loadSubScript $B$K$h$C$F(B XPCNativeWrapper $B$N%9%3!<%W0z?t$,8x3+$5$l$kLdBj(B X X
MFSA 2011-44 $B:G9b(B OGG $B%X%C%@$NFI$_9~$_$K$*$1$k2rJ|8e;HMQ$NLdBj(B X X X
MFSA 2011-45 $BCf(B $BF0:n%G!<%?$K4p$E$/%-! X X

$B!!(BThunderbird 3.1.15 $B$N=$@59`L\(B$B$O$^$@8x3+$5$l$F$$$J$$$N$G!">e5-$G$O!"B?J,$3$3$@$m$&$H;W$C$?$H$3$m$K(B ? $B$r$D$1$F$^$9!#(B

$B!!4XO"(B:

2011.09.30 $BDI5-(B:

$B!!(BFirefox 7.0.1 $B=P$^$7$?!#(BThunderbird 7.0.1 $B$b(B$B:#F|?$B$@$=$&$G$9!#(Biida $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BMFSA 2011-38 $B$O!"(B Firefox 7.0 / SeaMonkey 2.4 $B$G$O$J$/(B Firefox 6.0 / SeaMonkey 2.3 $B$G=$@5$5$l$F$$$k$H$5$l$F$$$^$9!#(BFirefox 3.6 $B7ONs$G$O(B 3.6.23 $B$G=$@5$J$N$G!"$=$l$^$GHs8x3+$@$C$?$h$&$G$9!#(B $B$9$:$-$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2011.09.28

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2011.07.25)

$B!!(BFoxit Reader 5.0.2 $B$N7o(B:


$B"#(B 2011.09.27

$B"#(B $BDI5-(B

$BDL?.$rJ]8n$9$k!V(BSSL$B!?(BTLS$B!W$N@H

$B!!=P$?$h$&$G(B:

$B!!$^$H$a$k$H!"$3$&$G$9$+$M(B:

  • $BJ#?t$N>r7o$r%/%j%"$G$-$l$P!"%f!<%6$K5$$E$+$l$k$3$H$J$/(B HTTPS $B%H%i%U%#%C%/$r2rFI$G$-$k!#(B

  • SSL 3.0 / TLS 1.0 $B$N7g4Y!#(BTLS 1.1 / 1.2 $B$K$O$3$N7g4Y$O$J$$!#(B $B$7$+$7(B TLS 1.1 / 1.2 $B$N%5%]!<%H>u67$O6K$a$F0-$$!#(B

  • CBC $B%b!<%I$r;HMQ$9$k0E9f72(B ($BNc(B: RSA-with-AES-256-CBC-SHA) $B$K$*$$$FH/8=!#(B $B%9%H%j!<%`0E9f$r;HMQ$9$k>l9g(B ($BNc(B: RSA-with-RC4-128-SHA) $B$K$OH/8=$7$J$$!#(B

    CPNI-957037: SSH $BDL?.$K$*$$$F0lIt%G!<%?$,O3$($$$9$k2DG=@-(B (2008.11) $B$N7o$r;W$$=P$7!"(BCTR $B%b!<%I$r;H$($P$$$$$N$K$H;W$C$?$N$@$1$I!"(BSSL / TLS $B$G$O(B CTR $B%b!<%I$O;H$($J$$(B ($BI8=`2=$5$l$F$$$J$$(B) $B$N$@$=$&$G(B: SSL cipher mode (OpenSSL-Dev ML)

$B!!8=;~E@$G$O!"(BRC4-128 $B$G2sHr$9$k$N$,8=


$B"#(B 2011.09.26

$B"#(B $B$$$m$$$m(B (2011.09.26)
(various)


$B"#(B 2011.09.25


$B"#(B 2011.09.23

$B"#(B $BDI5-(B


$B"#(B 2011.09.22

$B"#(B $BDI5-(B

$B"#(B APSB11-26: Security update available for Adobe Flash Player
(Adobe, 2011.09.21)

$B!!(BFlash Player 10.3.183.10$B!"(BFlash Player for Android 10.3.186.7 $BEP>l!#(B 6 $BCVE-2011-2426 CVE-2011-2427 CVE-2011-2428 CVE-2011-2429 CVE-2011-2430 CVE-2011-2444 $B$,=$@5$5$l$F$$$k!#(BCVE-2011-2444 ($B%f%K%P!<%5%k(B XSS $B7g4Y(B) $B$K$D$$$F$O!"4{$K(B Web $B%5%$%H$d(B Web $B%a!<%k$rDL$8$F0-MQ$5$l$k;vNc$,H/@8$7$F$$$k!#(B

$B!!4XO"(B:


$B"#(B 2011.09.21

$B"#(B $BDL?.$rJ]8n$9$k!V(BSSL$B!?(BTLS$B!W$N@H
(ITmedia, 2011.09.21)

$B!!$b$&$9$0>\:Y$,L@$i$+$K$J$k$h$&$J$N$G!"$H$j$"$($:MM;R8+!D!D(B

2011.09.27 $BDI5-(B:

$B!!=P$?$h$&$G(B:

$B!!$^$H$a$k$H!"$3$&$G$9$+$M(B:

  • $BJ#?t$N>r7o$r%/%j%"$G$-$l$P!"%f!<%6$K5$$E$+$l$k$3$H$J$/(B HTTPS $B%H%i%U%#%C%/$r2rFI$G$-$k!#(B

  • SSL 3.0 / TLS 1.0 $B$N7g4Y!#(BTLS 1.1 / 1.2 $B$K$O$3$N7g4Y$O$J$$!#(B $B$7$+$7(B TLS 1.1 / 1.2 $B$N%5%]!<%H>u67$O6K$a$F0-$$!#(B

  • CBC $B%b!<%I$r;HMQ$9$k0E9f72(B ($BNc(B: RSA-with-AES-256-CBC-SHA) $B$K$*$$$FH/8=!#(B $B$?$H$($P%9%H%j!<%`0E9f$r;HMQ$9$k>l9g(B ($BNc(B: RSA-with-RC4-128-SHA) $B$K$OH/8=$7$J$$!#(B

    CPNI-957037: SSH $BDL?.$K$*$$$F0lIt%G!<%?$,O3$($$$9$k2DG=@-(B (2008.11) $B$N7o$r;W$$=P$7!"(BCTR $B%b!<%I$r;H$($P$$$$$N$K$H;W$C$?$N$@$1$I!"(BSSL / TLS $B$G$O(B CTR $B%b!<%I$O;H$($J$$(B ($BI8=`2=$5$l$F$$$J$$(B) $B$N$@$=$&$G(B: SSL cipher mode (OpenSSL-Dev ML)

$B!!8=;~E@$G$O!"(BRC4-128 $B$G2sHr$9$k$N$,8=

2011.09.30 $BDI5-(B:

$B!!$$$m$$$m=P$F$-$F$^$9!#(B

2012.01.11 $BDI5-(B:

$B!!(BWindows patch $B=P$?!#$?$@$7!"(BMS12-006 - $B=EMW(B: SSL/TLS $B$N@HpJsO3$($$$,5/$3$k(B (2643584) $B$H(B MS11-099 - $B=EMW(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (2618444) $B$NN>J}$rE,MQ$9$kI,MW$,$"$k!#(B

$B"#(B Prenotification: Security Update for Flash Player
(Adobe PSIRT blog, 2011.09.20)

$B!!L@F|(B 9/21 (US $B;~4V(B) $B$K8x3+$@$=$&$G!#(Bin-the-wild $B$J7g4Y$N=$@5$b4^$^$l$k$=$&$G$9!#(B

$B"#(B $B$$$m$$$m(B (2011.09.21)
(various)


$B"#(B 2011.09.20

$B"#(B Skype$B$O(BiOS$B%"%W%j$N(BXSS($B%/%m%9%5%$%H%9%/%j%W%F%#%s%0(B)$B@H
(techcrunch, 2011.09.20)

$B"#(B $BDI5-(B

Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

Google $B$N0lIt%5%$%H$KBP$7$FH/9T$5$l$?IT@5$J(B SSL $B>ZL@=q$NLdBj(B

$B!!4XO"(B:

$B"#(B Google Chrome Stable Channel Update
(Google Chrome Release blog, 2011.09.16)

$B!!(BGoogle Chrome 14 $B7ONs$,(B stable $B$K!#(B14.0.835.163$B!#(B32 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B Flaw in OS X Lion allows unauthorized password changes
(Sophos, 2011.09.20)

$B!!(BMac OS X 10.7 Lion $B$K(B 2 $B$D$N7g4Y!#(B

  • $B%m%0%$%s:Q$N(B local user $B$,%Q%9%o!<%I$rJQ99$9$k$H$-$K!"8=:_$N%Q%9%o!<%I$,3NG'$5$l$J$$!#$$$-$J$j?7$7$$%Q%9%o!<%I$rF~NO$G$-$F$7$^$&!#(B

    testmac:~ TestUser$ dscl localhost -passwd /Search/Users/TestUser
    New Password:      
  • local user $B$,!"G$0U$NB>$N(B local user $B$N%Q%9%o!<%I%O%C%7%e$r

$B!!(Bpatch $B$O$^$@$J$$!#85$M$?(B: Cracking OS X Lion Passwords (defenceindepth.net, 2011.09.18)


$B"#(B 2011.09.19


$B"#(B 2011.09.16


$B"#(B 2011.09.15


$B"#(B 2011.09.14

$B"#(B $BDI5-(B

Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

$B!!(BAdvisory $B$N:G=*HG(B (UPDATE 3) $B=P$^$7$?(B: Apache HTTPD Security ADVISORY (UPDATE 3 - FINAL): Range header DoS vulnerability Apache HTTPD prior to 2.2.20 (apache.org, 2011.09.13)

$B"#(B $B$$$m$$$m(B (2011.09.14)
(various)

$B"#(B APSB11-24: Security updates available for Adobe Reader and Acrobat
(Adobe, 2011.09.13)

$B!!(BAdobe Reader / Acrobat 10.1.1 / 9.4.6 / 8.3.1 $BEP>l!#(B 13 $B7$/(B) $B$,=$@5$5$l$F$$$k!#(BCVE-2011-1353 CVE-2011-2431 CVE-2011-2432 CVE-2011-2433 CVE-2011-2434 CVE-2011-2435 CVE-2011-2436 CVE-2011-2437 CVE-2011-2438 CVE-2011-2439 CVE-2011-2440 CVE-2011-2441 CVE-2011-2442$B!#(B $B$?$@$7(B Adobe Reader 9.4.6 for UNIX $B$O(B 2011.11.07 $B$KEP>l$9$kM=Dj!#(B $B7g4Y$O(B UNIX $BHG$K$b$"$k$N$GCm0U!#(B

$B!!4XO"(B:

2011.09.15 $BDI5-(B:

$B!!4XO"(B:

2011.10.27 $BDI5-(B:

$B!!(BUnix $BHG$O0MA3$H$7$F(B 2011.11.07 $B$KEP>l$9$kM=Dj$H$J$C$F$$$k!#(B

$B!!(B2011.10.21 $BIU$G!"4|99?7$N8x3+F|$,(B 2011.12.13 $B$+$i(B 2012.01.10 $B$KJQ99$5$l$?!#(B

$B"#(B Microsoft 2011 $BG/(B 9 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2011.09.14)

$B!!M=Dj$I$*$j=P$^$7$?(B ($B$"$H$G=q$/(B)$B!#F|K\8lHG$b(B US $B$HF1MM$K(B URL $BJQ$o$j$^$7$?!#(B

$B!!4XO"(B:


$B"#(B 2011.09.13


$B"#(B 2011.09.12


$B"#(B 2011.09.11


$B"#(B 2011.09.10


$B"#(B 2011.09.09

$B"#(B $BDI5-(B

Google $B$N0lIt%5%$%H$KBP$7$FH/9T$5$l$?IT@5$J(B SSL $B>ZL@=q$NLdBj(B

$B!!4XO"(B:

$B"#(B $B$$$m$$$m(B (2011.09.09)
(various)

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2011 $BG/(B 9 $B7n(B
(Microsoft, 2011.09.09)

$B!!(B5 $B7o!#=EMW(B x 5$B!#(BOffice $B$"$j(B (Excel, SharePoint, Groove)

$B!!:#2s$+$i!"(BUS $BHG$O(B http://technet.microsoft.com/en-us/security/bulletin/ms11-sep $B$H$$$&(B URL $B$KJQ99$5$l$F$$$^$9$,!"F|K\8lHG$O$3$l$^$G$HF1MM$N$h$&$G!#(B

$B"#(B APSB11-24: Prenotification Security Advisory for Adobe Reader and Acrobat
(Adobe, 2011.09.08)

$B!!(BTuesday, September 13, 2011 (US $B;~4V(B) $B$K(B Adobe Reader / Acrobat $B$N99?7HG$,=P$kM=Dj$@$=$&$G$9!#(B $B>6LuHG(B: APSB11-24: Adobe Reader $B$*$h$S(B Acrobat $B$K4X$9$k%;%-%e%j%F%#>pJs$N;vA0DLCN(B (Adobe, 2011.09.09)

$B!!4XO"(B: Adobe Reader and Acrobat Version 8 End of Support (Adobe, 2011.09.08)$B!#(BAdobe Reader 8 / Acrobat 8 $B$O(B 2011.11.03 $B$G%5%]!<%H=*N;!#(B


$B"#(B 2011.09.08

$B"#(B $B$$$m$$$m(B (2011.09.08)
(various)

$B"#(B OpenSSL Security Advisory [6 September 2011] Two security flaws have been fixed in OpenSSL 1.0.0e
(OpenSSL, 2011.09.06)

$B!!(BOpenSSL 1.0.0e $B=P$^$7$?!#(B2 $B7o$N7g4Y$,=$@5$5$l$F$$$^$9!#;3ED$5$s!"(Biida $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

  • $BFCDj$N>u67$K$*$$$F!"(B nextUpdate $B%U%#!<%k%I$,2a5n$N$b$N$H$J$C$F$$$k(B CRL $B$rCVE-2011-3207

  • $B%5!<%PMQ$N(B ephemeral ECDH ($B80BP$,0l;~E*$JBJ1_6J@~(B Diffie-Hellman) $B0E9f72$N%3!<%I$,(B thread-safe $B$G$J$$$?$a!"%/%i%$%"%s%H$,4V0c$C$?=g=x$G%O%s%I%7%'%$%/%a%C%;!<%8$rAw?.$9$k$H(B crash $B$9$k!#(B OpenSSL 0.9.8$B!A(B0.9.8s$B!"(B1.0.0$B!A(B1.0.0d $B$N7g4Y!#(B $B$?$@$7(B 0.9.8 $B7ONs$G$O(B ECCdraft $B$OCVE-2011-3210

$B!!(BOpenSSL 0.9.8s $B$H$$$&$N$O$^$@%j%j!<%9$5$l$F$$$J$$$H;W$&$N$@$,!D!D!#(B http://www.openssl.org/source/ $B$K$b$J$$$7!#(B


$B"#(B 2011.09.07

$B"#(B $BDI5-(B

Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

$B!!=$@5HG$D$E$-(B:

Google $B$N0lIt%5%$%H$KBP$7$FH/9T$5$l$?IT@5$J(B SSL $B>ZL@=q$NLdBj(B

$B!!(BWindows / Firefox / Thunderbird / Seamonkey / Debian / FreeBSD $B=$@5=P$F$^$9!#(B

$B!!%O%/$C$??M$,(B GlobalSign $B$NL>A0$r=P$7$?$?$a!"BP1~$KDI$o$l$F$$$kLOMM!#(B

$B!!4XO"(B:


$B"#(B 2011.09.06

$B"#(B $BDI5-(B

Google $B$N0lIt%5%$%H$KBP$7$FH/9T$5$l$?IT@5$J(B SSL $B>ZL@=q$NLdBj(B

$B!!4XO"(B:


$B"#(B 2011.09.05

$B"#(B $BDI5-(B

Advisory: Range header DoS vulnerability Apache HTTPD 1.3/2.x (CVE-2011-3192)

$B!!(BAdvisory $B$N(B UPDATE 3 $B$N%I%i%U%HHG$H$$$&$N$,$"$k$h$&$G(B:

$B!!3F%G%#%9%H%j$+$i=$@5HG$,=P$F$$$k$,!"(BCentOS 5.6 / 6.0 $B$,$d$d$3$7$$$3$H$K$J$C$F$$$k(B (CentOS 5.7 / 6.1 $B$N%j%j!<%9$,CY$l$F$$$k$?$a(B)$B!#(B

Google $B$N0lIt%5%$%H$KBP$7$FH/9T$5$l$?IT@5$J(B SSL $B>ZL@=q$NLdBj(B

$B!!(BThunderbird 3.1.13 $B$O=P$F$^$9(B: Thunderbird 6.0.1 and 3.1.13 security updates now available (mozilla.org, 2011.08.31)$B!#(BFirefox 6.0.1 Android $BHG$O$^$@$_$?$$!#(B

$B!!$*$*$b$H$N(B Diginotar $BOC$O$5$i$KOC$,%d%P$/$J$C$F$$$k$h$&$G!#(BGoogle $B$I$3$m$8$c$J$$!#(B


$B"#(B 2011.09.04


$B"#(B 2011.09.02


$B"#(B 2011.09.01


[$B%;%-%e%j%F%#%[!<%k(B memo]