$B%;%-%e%j%F%#%[!<%k(B memo

Last modified: Wed Jan 16 20:06:55 2008 +0900 (JST)


$B!!(BSecurity Watch $B$5$s$,E9$8$^$$$5$l$F$7$^$C$?$N$G!"(B $B8D?M$GDI$$$+$1$F$_$k%F%9%H$G$9!#(B $BHwK:O?$H$7$F=q$$$F$*$/$D$b$j$J$N$G!"(B Security Watch $B$5$s$N$h$&$J>\:Y$J$b$N$G$O$"$j$^$;$s!#(B $B4pK\E*$J%?!<%2%C%H$O(B UNIX$B!"(BWindows$B!"(BMac OS (priority $B=g(B) $B$H$7$^$9!#(B $B$^$?!"$3$N%Z!<%8$NFbMF$O$I$N%Z!<%8$K$bA}$7$FL5J]>Z$G$"$k$3$H$r@k8@$7$F$*$-$^$9!#A4$F$N>pJs$,=8$^$C$F$$$k$o$1$b$"$j$^$;$s!#(B

$B!!$3$3$K:\$;$k>pJs$K$D$$$F$O!"(B $B2DG=$J8B$j(B 1 $BpJs8;$X$N%j%s%/$r:n@.$7$F$*$-$^$9!#(B $B3F<+$G(B 1 $BpJs8;$NFbMF$r3NG'$7$F$/$@$5$$!#(B $B$3$N%Z!<%8$NFbMF$r$/$l$0$l$b1-0{$_$K$7$J$$$h$&$K!#(B $B4V0c$$$rH/8+$5$l$?J}!"5-:\$5$l$F$$$J$$>pJs$r$4B8CN$NJ}!"$<$R(B$B$*$7$($F$/$@$5$$(B$B!#$h$m$7$/$*4j$$$$$?$7$^$9!#(B

$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B!!(B[ $BDjHV>pJs8;(B ] $B!!2a5n$N5-;v(B: 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[SCAN Security Wire NP Prize 2001]

Scan Security Wire $BSCAN Security Wire NP Prize 2001 $B$r^(B$B$7$^$7$?!#(B

$B!!(B

$B%M%C%H%i%s%J!<(B$B$N(B $B%Y%9%H!&%*%V!&>o=,^$r!"%Y%9%H!&%*%V!&>o=,^$r^$7$^$7$?!#(B


$B!!(B$BF|7P(B $B%M%C%H%o!<%/%;%-%e%j%F%#(B 2002 Vol.1 $B%5%]!<%H%Z!<%8(B$B$r$D$/$j$^$7$?!#(B (Vol.3 $B$N%5%]!<%H%Z!<%8$bI,MW$J$N$+$J$"!D!DFC$K=q$/$3$H$J$$$N$G$9$,(B)


www.iraqbodycount.org www.iraqbodycount.org

$BI|4)%j%/%(%9%H
$B%8%'%$%`%:(B.$B#F(B.$B%@%K%,%s!V(B $B?7!&@oAh$N%F%/%N%m%8!<(B$B!W(B($B8=:_(B27$BI<(B)
$BCf;3?.90!V(B$B%=%U%H%&%'%"$NK!E*J]8n(B$B!W(B ($B8=:_(B119$BI<(B) ($B%*%s%G%^%s%I9XF~2D(B)
$B%j%G%k!&%O!<%H!V(B$B@oN,O@!!4V@\E*%"%W%m!<%A(B$B!W(B ($BI|4)7hDj(B)
$BN&0f;0O:Lu!&JT!V(B$B%Y%H%J%`5"4TJ<$N>Z8@(B$B!W(B ($B8=:_(B103$BI<(B)
$BNS9nL@!V(B$B%+%U%+%9$N>.$5$J9q!!%A%'%A%'%sFHN)1?F0;OKv(B$B!W(B ($B8=:_(B166$BI<(B)

RSS $B$KBP1~$7$F$_$^$7$?!#(B $B>.%M%?$O4^$^$l$F$$$^$;$s!#!V@/<#$M$?%&%<%'!W$H$$$&?M$O(B RSS $B%Y!<%9$GFI$`$H9,$;$K$J$l$k$G$7$g$&(B ($B%&%6$/$J$$?M$O(B $B$3$C$A$N(B RSS $B$,$h$$$+$b$7$l$^$;$s(B)$B!#(B RSS 1.0 $B$G$9$N$G!"$"$/$^$G(B RDF Site Summary $B$G$9!#(B $B8=:_$O(B Really Simple Syndication $B$K$OBP1~$7$F$$$^$;$s!#(B
$B:#$9$0(B Really Simple Syndication $B$,$[$7$$?M$O!"$N$$$s$5$s$K$h$k(B Web $B%5%$%H$N(B RSS $B$r>! $B$r;2>H$7$F$/$@$5$$!#(B($B$N$$$s$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)

$B%;%-%e%j%F%#%[!<%k(B memo BoF 2007 $B$r3+:E$7$^$7$?!#%W%l%<%s%F!<%7%g%s$7$FD:$$$?3'MM!"$*$h$S$4;22C$5$l$?3'MM!"$"$j$,$H$&$4$6$$$^$7$?!#(B

$B<BMQ(B SSH $BBh(B2$BHG(B: $B%;%-%e%
2 $B:~$,=P$^$7$?!#(B$B%*%i%$%j!<$GCmJ8$7(B$B!"Hw9MMw$K!VI,$:(B2$B:~$G$"$k$3$H!W$H=q$/$H(B 2 $B:~$r3N

$B"#(B 2008.01.16

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B(947563) Microsoft Excel $B$N@H
(Microsoft, 2008.01.16)

$B!!(BExcel 2003 SP2 $B0JA0(B / 2002 / 2000 / 2004 for Mac, Excel Viewer 2003 $B$K7g4Y!#(B Excel $B%U%!%$%k$N=hM}$N7g4Y$N$?$a$K%a%b%jGK2u$,H/@8!"96N,(B Excel $B%U%!%$%k$K$h$C$FG$0U$N%3!<%I$rCVE-2008-0081

$B!!=$@5%W%m%0%i%`$O$^$@$J$$!#(BExcel 2003 SP3 / 2007 / 2008 for Mac $B$K%"%C%W%0%l!<%I$9$k$3$H$GBP1~$G$-$k!#$^$?!"(BExcel 2003 $B$G$O(B MOICE (Microsoft Office Isolated Conversion Environment) $B$r;H$&$3$H$G$b2sHr$G$-$k$=$&$@(B (info from: Excel$B$N@H ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog))

$B"#(B $B$$$m$$$m(B (2008.01.16)
(various)

$B"#(B Drupal $B$KJ#?t$N7g4Y(B
(Drupal.org, 2008.01.10)

$B!!(BDrupal $B$KJ#?t$N7g4Y!#(B

$B!!?@8M$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $BDI5-(B

JVN#80057925$B!!(B Apache HTTP Server $B$N(B mod_imap $B$*$h$S(B mod_imagemap $B$K$*$1$k%/%m%9%5%$%H%9%/%j%W%F%#%s%0$N@H

$B!!(BApache 1.3.40 / 2.0.62 / 2.2.7 $B$O%j%j!<%9$5$l$:!"(B Apache 1.3.41 / 2.0.63 / 2.2.8 $B$G=$@5$5$l$kLOMM!#(B

$B"#(B Apache $B$KJ#?t$N7g4Y(B
(various)

$B!!(BApache $B$KJ#?t$N7g4Y$,H/8+$5$l$F$$$^$9!#(B

$B!!(BApache 1.3.41 / 2.0.63 / 2.2.8 $B$G=$@5$5$l$k!#4{$K3F%P!<%8%g%s$N3+H/HG$G$O=$@5$5$l$F$$$k!#(Btakezou $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B About the security content of iPhone v1.1.3 and iPod touch v1.1.3
(Apple, 2008.01.16)

$B!!(BiPhone / iPod touch v1.1.3 $BEP>l!#(B3 $B$D$N7g4Y$,=$@5$5$l$F$$$k(B:

$B"#(B About the security content of QuickTime 7.4
(Apple, 2008.01.16)

$B!!(BQuickTime 7.4 $BEP>l!#(B4 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B!!!D!D$"$l!"(BJVNVU#112179$B!!(B Apple QuickTime RTSP $B$N(B Response message $B$K4^$^$l$k(B Reason-Phrase $B=hM}$K%P%C%U%!%*!<%P!<%U%m!<$N@H $B$OD>$C$F$J$$$h$&$G$9!D!D!#(B


$B"#(B 2008.01.15

$B"#(B $BDI5-(B

$B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H

$B!!(B2008.01.08, 2008.01.15 $B$K2~D{$5$l$F$$$k!#(B

$B"#(B InterScan Messaging Security Suite 7.0 / InterScan Messaging Security Appliance 7.0 $B$N(B $B!H(BKeep Alive$B!I@_Dj$K4X$9$k=EBg$JLdBj$K$D$$$F(B
($B%H%l%s%I%^%$%/%m(B, 2008.01.15)

$B!!(BIMSS 7.0 / IMSA 5000 7.0 $B$K7g4Y!#(BKeep Alive $B$rM-8z$K$7$?>l9g$K(B ($B%G%U%)%k%H(B: $BL58z(B) $B!"!VFCDj$N%a!<%k!W$r

$B!!(BIMSS 7.0 Linux $BHG(B Service Pack 1 $B$G=$@5$5$l$F$$$kB>!"(B IMSS 7.0 Windows $BHG(B / Solaris $BHG!"(BIMSA 5000 7.0 $BMQ$K$O(B Critical Patch $B$,8x3+$5$l$F$$$k!#(B


$B"#(B 2008.01.14


$B"#(B 2008.01.12


$B"#(B 2008.01.11

$B"#(B UTF-7$B$G(BXSS$B$rH/@8$5$;$k(B10$B$NJ}K!(B
($BMU$C$QF|5-(B, 2008.01.10)

$B!!$?$@$$$^A}?#Cf!#(BJavaScript $B$rM-8z$K$7$J$$$HFI$a$J$$$h$&$G$9!#(B

$B"#(B Web$B7PM3$G%W%j%s%?$rA`:n$9$k967b
(computerworld, 2008.01.10)

$B!!85$M$?(B: Cross Site Printing (Aaron Weaver)$B!#%$%s%H%i%M%C%HFb$N%M%C%H%o!<%/%W%j%s%?$N(B HP JetDirect $B%]!<%H(B (9100/tcp) $B$r(B Form $B$NAw$j@h$K@_Dj$7$F$*$/$H!"!D!D(B

$B"#(B JVNVU#112179$B!!(B Apple QuickTime RTSP $B$N(B Response message $B$K4^$^$l$k(B Reason-Phrase $B=hM}$K%P%C%U%!%*!<%P!<%U%m!<$N@H
(JVN, 2008.01.11)

$B!!(BQuickTime 7.3.1 $B0JA0$K$*$1$k(B RTSP $B%l%9%]%s%9%a%C%;!<%8$N=hM}$K7g4Y!#(B $BFCDj$N(B RTSP $B%9%F!<%?%9%3!<%I$r$B4{$K(B exploit $B$,8x3+$5$l$F$$$k(B$B!#(B

$B!!=$@5HG$O$^$@$J$$!#8=;~E@$K$*$1$k3NVulnerability Note VU#112179: Apple QuickTime RTSP Response message Reason-Phrase buffer overflow vulnerability (US-CERT) $B$K$O$3$NB>$K$bJ#?t$NJ}K!$,5-:\$5$l$F$$$k$,!"$$$:$l$b3N

2008.01.16 $BDI5-(B:


$B"#(B 2008.01.10

$B"#(B [SA28247] SSH Tectia Client/Server ssh-signer Unspecified Privilege Escalation
(Secunia, 2008.01.10)

$B!!(BSSH Tectia 5.x $B$K7g4Y!#(Bssh-signer $B$K8"8B>e>:$r5v$97g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rC%

$B!!(BSSH Tectia 5.2.4 / 5.3.6 $B$G=$@5$5$l$F$$$k!#$^$?!"(Bssh-signer $B%3%^%s%I$r:o=|$9$k$3$H$G2sHr$G$-$k!#$?$@$7!"$3$l$rZ$,$G$-$J$/$J$k!#(B


$B"#(B 2008.01.09

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (943411) Windows $B%5%$%I%P!<$NJ]8n$r6/2=$9$k99?7%W%m%0%i%`(B
(Microsoft, 2008.01.09)

$B!!(BWindows Sidebar Protection update for Windows Vista (Microsoft KB941411) $B$K$h$k$H!"$3$l$rE,MQ$9$k$3$H$G!"(BWindows $B%5%$%I%P!<$K$O

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B 2008 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!:#7n$O(B 2 $B7o$G$9!#(B

$B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B!!4XO"(B: 2008$BG/(B1$B7n$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog, 2008.01.04)


$B"#(B 2008.01.08

$B"#(B $B$$$m$$$m(B (2008.01.08)
(various)

$B"#(B 2008-01-07 Cumulative Security Update Release
(PostgreSQL.org, 2007.01.07)

$B!!(BPostgreSQL $BA4%P!<%8%g%s$KJ#?t$N7g4Y!#(B

$B!!(BPostgreSQL 8.2.6, 8.1.11, 8.0.15, 7.4.19, 7.3.21 $B$G=$@5$5$l$F$$$k!#(B 7.3 $B7ONs$O(B 7.3.21 $B$G=*N;$@$=$&$@!#(B $B$^$?(B 8.0 / 8.1 $B7ONs$N(B Windows $BHG%P%$%J%j%Q%C%1!<%8$NDs6!$b(B 8.0.15 / 8.1.11 $B$G=*N;$@$=$&$@!#B>$N%W%i%C%H%[!<%`$d%=!<%9$G$N(B 8.0 / 8.1 $B7ONs$NDs6!$O0];}$5$l$k$=$&$G!#(B

$B!!(BFreeBSD ports $B$b99?7$5$l$F$^$9(B: Adobe Acroread 8$BEP>l!$(BPostgreSQL$B%;%-%e%j%F%#99?7!$(BPostgreSQL$B8~$1A4J88!:w5!G=(Bludia$BDI2C!$(Blibgpod$B$G?7(BiPod Classic/Nano Video$BBP1~!$(BLinux Flash 7/9$B99?7(B (FreeBSD Daily Topics, 2008.01.08)

$B!!4XO"(B: PostgreSQL$B$K4m81$J%;%-%e%j%F%#!&%[!<%k!$4IM} ($BF|7P(B IT Pro, 2008.01.08)

$B"#(B $BDI5-(B

[APSB07-20] Flash Player update available to address security vulnerabilities

$B!!(BFreeBSD ports $B$G(B Flash Player 7r73 $B$H(B Flash Player 9.0r115 $B$,MQ0U$5$l$?(B: Adobe Acroread 8$BEP>l!$(BPostgreSQL$B%;%-%e%j%F%#99?7!$(BPostgreSQL$B8~$1A4J88!:w5!G=(Bludia$BDI2C!$(Blibgpod$B$G?7(BiPod Classic/Nano Video$BBP1~!$(BLinux Flash 7/9$B99?7(B (FreeBSD Daily Topics, 2008.01.08)

$B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H

$B!!(B[FFRRA-20080107] $B%8%c%9%H%7%9%F%`4pK\%/%i%9%i%$%V%i%j$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<@H ($B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B) $B$,8x3+$5$l$F$$$k!#(B

$B:Y9)$5$l$?J8=q%U%!%$%k(B(jtd$B%U%!%$%k$J$I(B)$B$r3+$/$3$H$G!"$"$k$$$O!":Y9)$5$l$?J8=q%U%!%$%k$,CV$+$l$?(Bweb$B%5%$%H$r(BInternet Explorer$B$d(BFirefox$BEy$N(Bweb$B%V%i%&%6$G1\Mw$9$k$3$H$G!"J8=q%U%!%$%kCf$K5-=R$5$l$?G$0U$N%3!<%I$r

$B!!1F6AHO0O$O(B jtd $B%U%!%$%k$K$H$I$^$i$J$$LOMM!#:rF|=q$$$?!V(Bjtd $B%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k$?$a!W$H$$$&J8>O$O!"(B JVN#08237857$B!!(B $BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H (JVN) $B$N(B

$BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$O!":Y9)$5$l$?(B jtd $B%U%!%$%k$r=hM}$9$k:]$K%P%C%U%!%*!<%P!<%U%m!<$N@H

$B$r:,5r$K$7$?$N$@$,!"$I$&$d$i4V0c$C$F$$$k$h$&$J$N$G=$@5$7$?!#(B


$B"#(B 2008.01.07

$B"#(B $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H
($B%8%c%9%H%7%9%F%`(B, 2008.01.07)

$B!!%8%c%9%H%7%9%F%`@=IJ6&DL%i%$%V%i%j(B jsfc.dll $B$K7g4Y!#(Bjtd $B%U%!%$%k(B jtd $B%U%!%$%k$J$I$NJ8=q%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k$?$a!"96N,(B jtd $B%U%!%$%k(B$BJ8=q%U%!%$%k$r;H$C$FG$0U$N%3!<%I$r

$B!!1F6A$rHo$k%=%U%H%&%'%"$O!"(BJSGCI.DLL $B$N$H$-(B$B$HF1MM!"B?4t$K$o$?$k!#(B

  • $B0lB@O:(B 2007 / 2006 / 2005 / 2004 / 13 / 12 / 11 / 10 / 9
  • $B0lB@O:(B Lite2
  • XML $B%F%s%W%l!<%H%/%j%(!<%?!<(B 1 / 2 / 3
  • FormLiner for XML/SGML
  • $B0lB@O:(B 9 SGML $B%(%/%9%F%s%7%g%s(B
  • Netnote
  • $B%8%c%9%H%[!<%`(B/i/2/3/4/EX/EX2
  • $B2V;R(B 2007 / 2006 / 2005 / 2004 / 13 / 12 / 11 / 10 / 9
  • $B;0;MO:(B 2007 / 2005 / 9 / SE / Home
  • $B%i%Y%k%^%$%F%#(B 1 / 2 / 3 / 4 / 5 / 6 / 7 / 8
  • $B%i%Y%k%^%$%F%#(B POP in Shop 1 / 2 / 3 / 4 / 5
  • $B3Z!9$O$,$-(B 2008 / 2007 / 2006 / 2005 / 2004 / 2003 / 2002 / 2001 / 2000
  • $B%^%$%Z%s%7%k(B
  • $B%(%W%m%s(B/2
  • $B%U%)%H%Z%?!*(B
  • $B%8%c%9%H%/%l%h%s(B
  • $B%[!<%`%Z!<%8%_%C%/%9(B
  • $B%I%/%?!<%^%&%9(B [$B1QOB!?OB1Q!?9q8l<-E5(B]
  • $B%;!<%k%9%^%$%F%#(B
  • $B?^2r%^%9%?!<(B
  • $B%8%c%9%H%9%^%$%k(B 2 / 3 @$B%U%l%s%I(B
  • $B%8%c%9%H%9%^%$%k(B 1 / 2 / 3
  • $B0lB@O:%9%^%$%k(B 1 / 2 / 3
  • $B%8%c%9%H%8%c%s%W(B 2 / 3 @$B%U%l%s%I(B
  • $B%8%c%9%H%8%c%s%W(B 1 / 2 / 3
  • $B0lB@O:%8%c%s%W(B 1 / 2 / 3
  • $B$D$?$o$k$M$C$H(B 1 / 3 @$B%U%l%s%I(B
  • $B$O$C$T$g$&L>?M(B 1 / 2 / 3
  • $B$R$i$a$-%i%$%?!<(B 1 / 2 / 3
  • $B$+$$$1$DI=%0%i%U(B 1 / 2 / 3
  • $BCO?^%9%?%8%*(B
  • $BJ8;z%9%?%8%*(B 1 / 2
  • $B8&=$%G%6%$%J!<(B
  • ConceptSearch
  • ExpandFinder
  • $B0lB@O:(B for Linux
  • $B0lB@O:%S%e!<%"(B (5.0.7.0 $B0JA0(B)
  • $B2V;R%S%e!<%"(B (2.0.2.0 $B0JA0(B)
  • $B$O$C$T$g$&L>?M%S%e!<%"(B
  • ConceptBase

$B!!=$@5%W%m%0%i%`$^$?$O99?7HG$,8x3+$5$l$F$$$k$N$G!"E,MQ$9$l$P$h$$!#(B

$B!!(B$B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B$B$N1-;t$5$s$K$h$kH/8+$@$=$&$@!#(B $B%8%c%9%H%7%9%F%`@=IJ6&DL$N%P%C%U%!%*!<%P!<%U%m!<@H ($B%8%c%9%H%7%9%F%`(B) $B$K$O!V(B2007$BG/(B12$B7n(B19$BF|!"Ev[FFRUA-20071216] $BJ8=q:n@.%=%U%H%&%(%"$N@H ($B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B) $B$,$=$l$@$m$&$+!#(B

$B!!4XO"(B:

2008.01.08 $BDI5-(B:

$B!!(B[FFRRA-20080107] $B%8%c%9%H%7%9%F%`4pK\%/%i%9%i%$%V%i%j$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<@H ($B%U%)%F%#!<%s%U%)%F%#5;=Q8&5f=j(B) $B$,8x3+$5$l$F$$$k!#(B

$B:Y9)$5$l$?J8=q%U%!%$%k(B(jtd$B%U%!%$%k$J$I(B)$B$r3+$/$3$H$G!"$"$k$$$O!":Y9)$5$l$?J8=q%U%!%$%k$,CV$+$l$?(Bweb$B%5%$%H$r(BInternet Explorer$B$d(BFirefox$BEy$N(Bweb$B%V%i%&%6$G1\Mw$9$k$3$H$G!"J8=q%U%!%$%kCf$K5-=R$5$l$?G$0U$N%3!<%I$r

$B!!1F6AHO0O$O(B jtd $B%U%!%$%k$K$H$I$^$i$J$$LOMM!#:rF|=q$$$?!V(Bjtd $B%U%!%$%k$N=hM}$K$*$$$F(B buffer overflow $B$9$k$?$a!W$H$$$&J8>O$O!"(B JVN#08237857$B!!(B $BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H (JVN) $B$N(B

$BJ#?t$N%8%c%9%H%7%9%F%`@=IJ$K$O!":Y9)$5$l$?(B jtd $B%U%!%$%k$r=hM}$9$k:]$K%P%C%U%!%*!<%P!<%U%m!<$N@H

$B$r:,5r$K$7$?$N$@$,!"$I$&$d$i4V0c$C$F$$$k$h$&$J$N$G=$@5$7$?!#(B

2008.01.15 $BDI5-(B:

$B!!(B2008.01.08, 2008.01.15 $B$K2~D{$5$l$F$$$k!#(B

$B"#(B $BJFO"K.9R6u6I!"%\!<%$%s%0(B787$B$NFbIt%M%C%H%o!<%/$K$O?<9o$J@H
(technobahn, 2008.01.07)

$B!!%O%C%-%s%0$G%O%$%8%c%C%/;~BeE~Mh(B?


$B"#(B 2008.01.06

$B"#(B [SA28264] XOOPS "b_system_comments_show()" Security Bypass
(secunia, 2008.01.05)

$B!!(BXOOPS 2.0.18 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

$B"#(B [SA28228] Qt QSslSocket Certificate Verification Vulnerability
(secunia, 2008.01.04)

$B!!(BQt 4.3.0$B!A(B4.3.2 $B$N(B QSslSocket $B$K(B SSL $B$N>ZL@=qG'>Z$K4X$9$k7g4Y$,$"$k$=$&$G!#(B Qt 4.3.3 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(Bpatch $B$b$"$j$^$9(B$B!#(B CVE-2007-5965

$B"#(B [SA28318] PHP Multiple Vulnerabilities
(secunia, 2008.01.04)

$B!!(BPHP 4.4.8 $B$G=$@5$5$l$?(B 5 $B$D$N7g4Y$NOC!#(B

$B"#(B securityvulns.com russian vulnerabilities digest
(3APA3A, 2008.01.04)

$B!!(Bhttp://securityvulns.com/ $B$GJs9p$5$l$?%;%-%e%j%F%#7g4Y$N$&$A!"1Q8l$G$NJs9p$,$J$5$l$F$$$J$$$b$N$K4X$9$k%@%$%8%'%9%H!#(BWordPress $B$N(B XSS $B$M$?$J$I!#(B

$B"#(B multiple CAPTCHA automation test bypass digest
(3APA3A, 2008.01.04)

$B!!(BMonth of Bugs in Captchas $B$H$$$&%W%m%8%'%/%H$,(B 2007.11 $B$K3+:E$5$l$?$=$&$G!"$=$N7k2L$N%@%$%8%'%9%H!#(B $BJs9p$5$l$?(B 75 $B8D$N7g4Y$N$&$A!"=$@5$5$l$?$b$N$O(B 5 $B$D$@$1$@$=$&$G!#(B

$B"#(B $BDI5-(B

$B"#(B $B$$$m$$$m(B (2008.01.06)
(various)


$B"#(B 2008.01.05

$B"#(B [SA28276] RealPlayer Unspecified Buffer Overflow Vulnerability
(secunia, 2008.01.03)

$B!!>/$J$/$H$b(B RealPlayer 11 $B$KL$=$@5$N7g4Y$,B8:_$9$kLOMM!#(B $BH/8+[Dailydave] 0day RealPlayer exploit demo

$B!!(Bpatch $B$O$^$@$J$$!#(BSANS ISC $B$O(B uc8010.com $B$X$N%"%/%;%9$r5qH]$9$k$h$&?d>)$7$F$$$k!#(B $B;2>H(B: Realplayer Vulnerability (SANS ISC, 2008.01.04)

$B"#(B $B%^%$%/%m%=%U%H(B 2008 $BG/(B 1 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2008.01.04)

$B!!:#7n$O(B 2 $B7o$G$9!#(B

$B!!=$@5%W%m%0%i%`$,$"$k$N$GE,MQ$9$l$P$h$$!#(B

$B!!4XO"(B: 2008$BG/(B1$B7n$N%;%-%e%j%F%#%j%j!<%9M=Dj(B ($BF|K\$N%;%-%e%j%F%#%A!<%`$N(B Blog, 2008.01.04)

2008.01.09 $BDI5-(B:

$B!!(BBulletin $B8x3+$K$"$o$;$FA4LLE*$K=q$-$J$*$7!#(B


$B"#(B 2008.01.02


$B"#(B 2008.01.01

$B"#(B TK53 Advisory #2: Multiple vulnerabilities in ClamAV
(Lolek of TK53, 2007.12.30)

$B!!(BClamAV 0.92 ($B:G?7HG(B) $B$K(B 3 $B$D$N7g4Y$,$"$k!"$H$$$&;XE&!#(B

  • $B0l;~%U%!%$%k$N:n@.$K$*$$$F6%9g>uBV$,H/@8!#(B CVE-2007-6595

  • BASE64 $B7A<0$N(B UUENCODE $B%U%!%$%k(B (GNU sharutils $B$J$I$,BP1~!"(Buuencode -m ) $B$r$&$^$/07$($J$$$?$a!"4{CN$N%^%k%&%'%"$rDL2a$5$;$F$7$^$&!#(B CVE-2007-6596

  • sigtool $B$K$*$1$k(B utf16-decode $B;~$N%U%!%$%k$N07$$$,%;%-%e%"$G$J$$!#(B CVE-2007-6337

$B"#(B HDD$B$r%U%)!<%^%C%H$9$k%V%i%/%i(B $B$^$H$a(Bwiki
(@wiki, 2007.12.31)

$B!!$J$s$@$+$=$&$$$&$b$N$,N.9T$C$F$$$k$h$&$G$9!#;38}$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

  1. IE $BA@$$$N%V%i%&%6%/%i%C%7%c!<%Z!<%8$K%"%/%;%9$5$;$k(B ($B3HD%;R$r56Au$7$F$$$k>l9g$"$j(B)
  2. $B%V%i%&%6%/%i%C%7%c!<$O!"967b(B .bat $B%U%!%$%k$r%9%?!<%H%"%C%W$KEPO?$5$;$?>e$G:F5/F0$rB%$7$?$j$9$kLOMM(B
  3. $B:F5/F0$7$F$7$^$&$H%I%+%s(B

$B!!%"%/%;%9$7$F$7$^$C$?>l9g$NMM;R(B: http://www.geocities.jp/hdd_matome/

$B!!(BIE 6 SP2 / IE 7 $B$N>l9g!"!V3HD%;R$G$O$J$/!"FbMF$K$h$C$F%U%!%$%k$r3+$/!W$rL58z$K@_Dj$9$k$H!"3HD%;R56Au$K$D$$$F$O2sHr$G$-$^$9!#(B $B$7$+$7(B IE $B%3%s%]!<%M%s%H$r;HMQ$9$k%V%i%&%6$N>l9g!"$3$N@_Dj$,8z$+$J$$>l9g$,$"$k$h$&$G$9!#(BSleipnir $B$N>l9g$O(B 2.5.14 $B$GBP1~$5$l$F$$$k$=$&$G$9!#(B$B%j%j!<%9%N!<%H(B

$B!!%V%i%&%6%/%i%C%7%c!<<+BN$O(B JavaScript $B$rL58z$K$7$J$$$H2sHr$G$-$J$$LOMM!#(B $B$"$k$$$O(B Firefox $B$d(B Opera $B$J$I(B IE $B$G$O$J$$%V%i%&%6$r;HMQ$9$k!#(B

$B!!4XO"(B: $B2hA|%U%!%$%k$K56Au$7$?!$(BHDD$B$r%U%)!<%^%C%H$7$h$&$H$9$k%H%m%$$NLZGO$,%M%C%H$GOCBj$K(B ($BF|7P(B IT Pro, 2007.12.31)


$B2a5n$N5-;v(B: 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B