$B%;%-%e%j%F%#%[!<%k(B memo

Last modified: Tue Sep 28 18:45:46 2010 +0900 (JST)


$B!!(BSecurity Watch $B$5$s$,E9$8$^$$$5$l$F$7$^$C$?$N$G!"(B $B8D?M$GDI$$$+$1$F$_$k%F%9%H$G$9!#(B $BHwK:O?$H$7$F=q$$$F$*$/$D$b$j$J$N$G!"(B Security Watch $B$5$s$N$h$&$J>\:Y$J$b$N$G$O$"$j$^$;$s!#(B $B4pK\E*$J%?!<%2%C%H$O(B UNIX$B!"(BWindows$B!"(BMac OS (priority $B=g(B) $B$H$7$^$9!#(B $B$^$?!"$3$N%Z!<%8$NFbMF$O$I$N%Z!<%8$K$bA}$7$FL5J]>Z$G$"$k$3$H$r@k8@$7$F$*$-$^$9!#A4$F$N>pJs$,=8$^$C$F$$$k$o$1$b$"$j$^$;$s!#(B

$B!!$3$3$K:\$;$k>pJs$K$D$$$F$O!"2DG=$J8B$j(B 1 $BpJs8;$X$N%j%s%/$r:n@.$7$F$*$-$^$9!#(B $B3F<+$G(B 1 $BpJs8;$NFbMF$r3NG'$7$F$/$@$5$$!#(B $B$3$N%Z!<%8$NFbMF$r$/$l$0$l$b1-0{$_$K$7$J$$$h$&$K!#(B $B4V0c$$$rH/8+$5$l$?J}!"5-:\$5$l$F$$$J$$>pJs$r$4B8CN$NJ}!"$<$R(B$B$*$7$($F$/$@$5$$(B$B!#$h$m$7$/$*4j$$$$$?$7$^$9!#(B

$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B!!(B[ $BDjHV>pJs8;(B ] $B!!2a5n$N5-;v(B: 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[SCAN Security Wire NP Prize 2001]

$B!V(BScan Security Wire$B!W(B $BSCAN Security Wire NP Prize 2001 $B$r^(B$B$7$^$7$?!#(B

$B!!(B

$B!V%M%C%H%i%s%J!o=,^$r!"%Y%9%H!&%*%V!&>o=,^$r^$7$^$7$?!#(B


www.iraqbodycount.org www.iraqbodycount.org

$BI|4)%j%/%(%9%H
$B%8%'%$%`%:(B.$B#F(B.$B%@%K%,%s!V(B $B?7!&@oAh$N%F%/%N%m%8!<(B$B!W(B($B8=:_(B44$BI<(B)
$BCf;3?.90!V(B$B%=%U%H%&%'%"$NK!E*J]8n(B$B!W(B ($B8=:_(B119$BI<(B) ($B%*%s%G%^%s%I9XF~2D(B)
$B%j%G%k!&%O!<%H!V(B$B@oN,O@!!4V@\E*%"%W%m!<%A(B$B!W(B ($B?7Lu=P$^$7$?(B: $B>e(B $B2<(B)
$BN&0f;0O:Lu!&JT!V(B$B%Y%H%J%`5"4TJ<$N>Z8@(B$B!W(B ($B8=:_(B108$BI<(B)
$BNS9nL@!V(B$B%+%U%+%9$N>.$5$J9q!!%A%'%A%'%sFHN)1?F0;OKv(B$B!W(B ($B8=:_(B176$BI<(B)

RSS $B$KBP1~$7$F$_$^$7$?!#(B $B>.%M%?$O4^$^$l$F$$$^$;$s!#!V@/<#$M$?%&%<%'!W$H$$$&?M$O(B RSS $B%Y!<%9$GFI$`$H9,$;$K$J$l$k$G$7$g$&(B ($B%&%6$/$J$$?M$O(B $B$3$C$A$N(B RSS $B$,$h$$$+$b$7$l$^$;$s(B)$B!#(B RSS 1.0 $B$G$9$N$G!"$"$/$^$G(B RDF Site Summary $B$G$9!#(B $B8=:_$O(B Really Simple Syndication $B$K$OBP1~$7$F$$$^$;$s!#(B
$B:#$9$0(B Really Simple Syndication $B$,$[$7$$?M$O!"$N$$$s$5$s$K$h$k(B Web $B%5%$%H$N(B RSS $B$r>! $B$r;2>H$7$F$/$@$5$$!#(B($B$N$$$s$5$s>pJs$"$j$,$H$&$4$6$$$^$9(B)

$B<BMQ(B SSH $BBh(B2$BHG(B: $B%;%-%e%
2 $B:~$,=P$^$7$?!#(B$B%*%i%$%j!<$GCmJ8$7(B$B!"Hw9MMw$K!VI,$:(B2$B:~$G$"$k$3$H!W$H=q$/$H(B 2 $B:~$r3N

$B"#(B 2010.09.28

$B"#(B $BDI5-(B

XSS$B%"%?%C%/$K$D$$$FG'<1$7!"%Q%C%A$K$h$k=$I|:n6H$r9T$$$^$7$?!#(B

$B!!4XO"(B:

$BJ@

$B!!4XO"JsF;!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!FIGd$NJsF;$K$h$k$H!"!VF1e$k!W$=$&$G$9$,!"(BMicroAd $B<+?H$OH]Dj$7$F$^$9!#KhF|$b(B 800 $BK|$H$$$&?t;z$r5s$2$F$^$9$,!"$I$3$+$iMh$??t;z$J$s$G$9$+$M!#(B

$B!!4XO"(B:

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2416728) ASP.NET $B$N@HpJsO3$($$$,5/$3$k(B

$B!!L@F|(B (2010.09.29)$B!"=$@5%W%m%0%i%`$,DjNc30$G8x3+$6$l$k$=$&$G$9(B: ASP.NET $B$N%;%-%e%j%F%#99?7$N;vA0DLCN(B ($BDjNc30(B) ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.09.27)

$B!!$^$?!"(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B 2416728 $B$,(B 2010.09.27 $BIU$G2~D{$5$l$F$$$^$9!#(B $B!V%+%9%?%`%(%i!<$r@_Dj$7!">o$KF1$8%a%C%;!<%8$rJV$9!W$h$&(B .NET Framework $B$r@_Dj$9$k$@$1$G$OBLL\$G!"(B URLScan $B$d(B IIS $BMW5a%U%#%k%?!<$r;H$C$F!"!V%/%(%jJ8;zNs$N%"%W%j%1!<%7%g%s(B $B%(%i!<(B $B%Q%9$r;XDj$9$k%j%/%(%9%H$r%V%m%C%/!W$9$kI,MW$b$"$k$=$&$G$9!#(B

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2010 $BG/(B 9 $B7n(B ($BDjNc30(B)
(Microsoft, 2010.09.28)

$B!!DjNc30$N=$@5%W%m%0%i%`!"L@F|8x3+M=Dj$@$=$&$G$9!#(B ASP.NET $B$N7o(B$B$@$=$&$G$9!#(B ASP.NET $B$N%;%-%e%j%F%#99?7$N;vA0DLCN(B ($BDjNc30(B) ($BF|K\$N%;(B%-%e%j%F%#%A!<%`, 2010.09.27) $B$r;2>H!#(B


$B"#(B 2010.09.27

$B"#(B $BDI5-(B

Stuxnet worm 'targeted high-value Iranian assets'

$BJ@ ($BDI5-$=$N(B3)

$B!!%+%+%/%3%`$+$i(B 18:35 $B$K0FFb=P$^$7$?(B: $B!Z=EMW![30ItG[?.9-9p%5!<%P!<$N>c32$K$D$$$F(B ($B%+%+%/%3%`(B, 2010.09.27)$B!#(B cadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$BJ@ ($BDI5-$=$N(B2)

$B!!:#2s$N7o!"(BOpenX $B$N@H.$N(BWeb$B%a%G%#%"$G$"$l$P$[$\;H$&$@$m$&$H$$$&DjHV$N9-9p%5!<%P!<$J$N$@$=$&$G!"@H

$B$7$F$/$@$5$$!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$BJ@

$B!!:rF|=q$$$?J,",!"$7$?!#(B

$B!!4XO"(B:

$B"#(B $B$$$m$$$m(B (2010.09.27)
(various)


$B"#(B 2010.09.26

$B"#(B $BJ@
(MicroAd, 2010.09.25)

$B!!(BMicroAd $B$N(B$BL5NA9-9p%5!<%P(B VASCO $B$N!V0lIt!W$,967b$r

$B!!(Bslashdot.jp $B$G$O!"(BOpenX$B$N@H$B!"$H$$$&?dB,$,Ej9F$5$l$F$$$k!#(B OpenX Ad-Server Vulnerability (SANS ISC, 2010.09.16) $B$r8+$?$H$-$K$O!";d$K$O2?$N$3$H$J$N$+$5$C$Q$j$o$+$i$J$+$C$?$N$@$,!"$1$C$3$&;H$o$l$F$$$k$s$G$9$+$M!#(B

$B!!$"$H!"$3$l$OJL7o$J$N$+$I$&$J$N$+$h$/$o$+$i$J$$$N$@$,!"(B2010.09.26 23:45 $B8=:_!"(B japanese.joins.com ($BCf1{F|Js(B $BF|K\8lHG(B) $B$,(B Google Safe Browsing $B$G%"%&%HH=Dj$5$l$F$$$k(B$B!#(B

2010.09.27 $BDI5-(B:

$B!!:rF|=q$$$?J,",!"$7$?!#(B

$B!!4XO"(B:

2010.09.27 $BDI5-(B ($B$=$N(B2):

$B!!:#2s$N7o!"(BOpenX $B$N@H.$N(BWeb$B%a%G%#%"$G$"$l$P$[$\;H$&$@$m$&$H$$$&DjHV$N9-9p%5!<%P!<$J$N$@$=$&$G!"@H

$B$7$F$/$@$5$$!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2010.09.27 $BDI5-(B: ($B$=$N(B3)

$B!!%+%+%/%3%`$+$i(B 18:35 $B$K0FFb=P$^$7$?(B: $B!Z=EMW![30ItG[?.9-9p%5!<%P!<$N>c32$K$D$$$F(B ($B%+%+%/%3%`(B, 2010.09.27)$B!#(B cadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2010.09.28 $BDI5-(B:

$B!!4XO"JsF;!#F?L>4uK>$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!FIGdJsF;$K$h$k$H!"!VF1e$k!W$=$&$G$9$,!"(BMicroAd $B<+?H$OH]Dj$7$F$^$9!#KhF|$b(B 800 $BK|$H$$(B$&?t;z$r5s$2$F$^$9$,!"$I$3$+$iMh$??t;z$J$s$G$9$+$M!#

$B!!4XO"(B:


$B"#(B 2010.09.24

$B"#(B $B$$$m$$$m(B (2010.09.24)
(various)

$B"#(B Stuxnet worm 'targeted high-value Iranian assets'
(BBC, 2010.09.23)

$B!!(BStuxnet $B%o!<%`$O!"9q2H$,:n@.$7$?!"%$%i%s%$%s%U%i967bMQ$N%5%$%P!

2010.09.27 $BDI5-(B:

$B!!4XO"(B:

$B"#(B $BDI5-(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat


$B"#(B 2010.09.23

$B"#(B $BDI5-(B

XSS$B%"%?%C%/$K$D$$$FG'<1$7(B!"%Q%C%A$K$h$k=$I|:n6H$r9T$$$^$7$?!#

APSA10-03: Security Advisory for Flash Player

$B!!4XO"(B: Technical Analysis of the Recent Adobe Flash Zero-Day Vulnerability (trendmicro blog, 2010.09.22)

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2286198) Windows $B%7%'%k$N@H

$B!!(BSymantec $B$N(B Stuxnet $B4XO"5-;v(B:

$B$R$5$S$5$K!VBgNL%a!<%kAw?.7?%&%$%k%9!W$,N.9T$C$F$$$kLOMM(B (W32/VBMania@MM)

$B"#(B Cisco $BJ}LL(B
(Cisco, 2010.09.22)

$B!!(BCisco IOS $BJ}LL!"$$$m$$$m=P$F$^$9!#(B

$B!!$"$H(B 1 $B$D!#(B

$B"#(B Security Vulnerabilities and HIPER APARs fixed in DB2 for Linux, UNIX, and Windows Version 9.7 Fix Pack 3
(IBM, 2010.09.18)

$B!!(BCVE-2010-3474 CVE-2010-3475 $B$,=$@5$5$l$F$$$^$9!#(B

$B"#(B Flaw in Runas group matching
(sudo.ws, 2010.09.07)

$B!!(Bsudo 1.7.0 $B!A(B 1.7.4p3 $B$K7g4Y!#(B-g $B%*%W%7%g%s(B (sudo 1.7.0 $B$G?7@_$5$l$?(B) $B$H(B -u $B%*%W%7%g%s$H$rAH$_$"$o$;>l9g$N=hM}$K7g4Y$,$"$j!"5v2D$5$l$F$$$J$$>l9g$G$b(B -u root $B$r;XDj!&CVE-2010-2956

$B!!(Bsudo 1.7.4p4 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B PMASA-2010-7: XSS attack on setup script
(phpMyAdmin, 2010.09.08)

$B!!(BphpMyAdmin 3.x $B$N(B setup script $B$K(B XSS $B7g4Y!"(BphpMyAdmin 3.3.7 $B$G=$@5$5$l$F$$$k!#(B CVE-2010-3263


$B"#(B 2010.09.22

$B"#(B CVE-2010-3301: $B$b$&(B 1 $B$D$N!V(BLinux 64bit $BHG%+!<%M%k$K(B root $B8"8B$rC%$o$l$k@H
(various)

$B!!(BLinux 2.6.27-rc1 $B!A(B 2.6.36-rc4 $B$K7g4Y!#(BIA32 $B%7%9%F%`%3!<%k%(%_%e%l!<%7%g%s$K7g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rC%CVE-2007-4573 $B$K4X$9$k=$@5$,IT==J,$@$C$?LOMM!#(B CVE-2010-3301

$B"#(B Linux 64bit $BHG%+!<%M%k$K(B root $B8"8B$rC%$o$l$k@H
(slashdot.jp, 2010.09.21)

$B!!(BLinux 2.6.26-rc1 $B!A(B 2.6.36-rc4 $B$K7g4Y!#(B64bit $BHG%+!<%M%k$N(B 32bit $B8_49%l%$%d!<$K7g4Y$,$"$j!"(Blocal user $B$,(B root $B8"8B$rC%CVE-2010-3081$B!#(B

$B"#(B $BDI5-(B

APSA10-03: Security Advisory for Flash Player

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B"#(B XSS$B%"%?%C%/$K$D$$$FG'<1$7!"%Q%C%A$K$h$k=$I|:n6H$r9T$$$^$7$?!#(B
(twitter.jp, 2010.09.21)

$B!!$3$N7o(B:

$B!!4{$K=$@5$5$l$F$$$k!#(B

2010.09.23 $BDI5-(B:

$B!!(BThe names and faces behind the 'onMouseOver' Twitter worm attack (Sophos, 2010.09.22)

2010.09.28 $BDI5-(B:

$B!!4XO"(B:


$B"#(B 2010.09.21

$B"#(B Google Chrome Stable, Beta Channel Updates
(Google Chrome Releases blog, 2010.09.17)

$B!!=54)(B Google Chrome 6.0.472.62 $BEP>l!#(B2 $B7o$N7g4Y$,=$@5$5$l$F$$$kB>!"(B APSB10-22: Security update available for Adobe Flash Player (Adobe, 2010.09.20) $B$X$NBP1~$b4^$^$l$F$$$k!#(B

$B"#(B $BDI5-(B

APSA10-03: Security Advisory for Flash Player

$B!!(BFlash Player 10.1.85.3 / 9.0.283$B!"(BFlash Player for Android 10.1.95.1 $B$,A0E]$78x3+$5$l$^$7$?!#(BIlion $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BFlash Player $B$O(B Google Chrome $B$K$b4^$^$l$F$^$9$,!"(BGoogle Chrome 6.0.472.62 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

$B"#(B About Security Update 2010-006
(apple, 2010.09.21)

$B!!(BMac OS X 10.6 $BMQ$N%;%-%e%j%F%#99?7!#=$@52U=j$O(B AFP (CVE-2010-1820) $B$N$_!#(B remote $B$+$i%Q%9%o!<%IG'>Z$r2sHr$7$F(B AFP $B%U%!%$%k6&M-$K@\B3$G$-$k7g4Y!#(B $B%f!<%6L>$9$iCN$kI,MW$,$J$$!#(B Mac OS X 10.5 $B0JA0$K$O$3$N7g4Y$O$J$$!#(B

$B"#(B $B$$$m$$$m(B (2010.09.21)
(various)


$B"#(B 2010.09.20

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2416728) ASP.NET $B$N@HpJsO3$($$$,5/$3$k(B
(Microsoft, 2010.09.18)

$B!!(B.NET Framework 1.x $B!A(B 4.x $B$K7g4Y!#0E9f2=$5$l$?%G!<%?$NI|9f=hM}$K$*$$$F!"%(%i!<%a%C%;!<%8(B ($B=hM}$N@.8y!&<:GT(B) $B$rJV$7$F$7$^$&7g4Y$,$"$j!"7k2L$H$7$F!"(B $B0E9f2=$5$l$?(B ViewState $B%*%V%8%'%/%H$NI|9f$d!"(Bweb.config $B$NFI$_CVE-2010-3332

$B!!=$@5%W%m%0%i%`$O$^$@$J$$!#%+%9%?%`%(%i!<$r@_Dj$7!">o$KF1$8%a%C%;!<%8$rJV$9$3$H$G2sHr$G$-$k!#%+%9%?%`%(%i!<$N@_DjJ}K!$O!"(B SA 2416728 $B$K5-:\$5$l$F$$$k!#(B

$B!!4XO"(B:

2010.09.28 $BDI5-(B:

$B!!L@F|(B (2010.09.29)$B!"=$@5%W%m%0%i%`$,DjNc30$G8x3+$6$l$k$=$&$G$9(B: ASP.NET $B$N%;%-%e%j%F%#99?7$N;vA0DLCN(B ($BDjNc30(B) ($BF|K\$N%;%-%e%j%F%#%A!<%`(B, 2010.09.27)

$B!!$^$?!"(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B 2416728 $B$,(B 2010.09.27 $BIU$G2~D{$5$l$F$$$^$9!#(B $B!V%+%9%?%`%(%i!<$r@_Dj$7!">o$KF1$8%a%C%;!<%8$rJV$9!W$h$&(B .NET Framework $B$r@_Dj$9$k$@$1$G$OBLL\$G!"(B URLScan $B$d(B IIS $BMW5a%U%#%k%?!<$r;H$C$F!"!V%/%(%jJ8;zNs$N%"%W%j%1!<%7%g%s(B $B%(%i!<(B $B%Q%9$r;XDj$9$k%j%/%(%9%H$r%V%m%C%/!W$9$kI,MW$b$"$k$=$&$G$9!#(B

$B"#(B CVE-2010-3069: Buffer Overrun Vulnerability (Samba 3.0.x - 3.5.x)
(Samba.org, 2010.09.14)

$B!!(BSamba 3.0.x $B!A(B 3.5.x $B$K7g4Y!#(Bsid_parse() $B$K$*$$$FF~NOD9$r@5$7$/3NG'$7$J$$$?$a!"96N,(B SID $B$K$h$C$F(B buffer overflow $B$,H/@8!#(BCVE-2010-3069

$B!!(BSamba 3.5.5 $B$G=$@5$5$l$F$$$k!#$^$?(B Samba 3.3.13 / 3.4.8 / 3.5.4 $BMQ$N(B patch $B$,MQ0U$5$l$F$$$k!#(B

$B"#(B Squid Proxy Cache Security Update Advisory SQUID-2010:3 - Denial of service in request processing
(squid-cache.org, 2010.09.03)

$B!!(BSquid 3.x $B$K7g4Y!#J8;zNs=hM}$K7g4Y$,$"$j!"96N,%j%/%(%9%H$K$h$C$F(B DoS $B967b$rCVE-2010-3072

$B!!(BSquid 3.1.8 / 3.2.0.2 $B$G=$@5$5$l$F$$$k!#$^$?(B Squid 3.0 / 3.1 $BMQ$N(B patch $B$,MQ0U$5$l$F$$$k!#(B


$B"#(B 2010.09.19


$B"#(B 2010.09.17

$B"#(B $BDI5-(B

Firefox 3.6.9/3.5.12$B!"(BThunderbird 3.1.3/3.0.7 $BEP>l(B

$B!!(BFirefox 3.5 $B7O$d(B Thunderbird $B$b99?7$5$l$F$$$?$s$G$9$M!#(B


$B"#(B 2010.09.16

$B"#(B About the security content of QuickTime 7.6.8
(Apple, 2010.09.15)

$B!!(BQuickTime 7.6.8 $BEP>l!#(BWindows $BHG(B QuickTime $B$K$N$_B8:_$9$k!"(B2 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B QuickTime$B$KL$=$@0$N?<9o$J@H $B$N7o(B (CVE-2010-1818 ) $B$H!"(BQuickTime Picture Viewer $B$KB8:_$7$?(B DLL Hijacking $BLdBj(B (CVE-2010-1819) $B$KBP1~!#(B

$B"#(B $BDI5-(B

Firefox 3.6.9/3.5.12$B!"(BThunderbird 3.1.3/3.0.7 $BEP>l(B

$B!!(BFirefox 3.6.10 $B=P$^$7$?!#LdBj$H$J$C$F$$$?!V%/%i%C%7%e%P%0!W$,2r7h$5$l$?$h$&$G$9!#(B

$B!!(BSeaMonkey $B$b(B 2.0.8 $B$,=P$F$$$^$9!#(Btvb19131 $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2010.09.15

$B"#(B $B$$$m$$$m(B (2010.09.15)
(various)

$B"#(B Google Chrome Stable, Beta Channel Updates
(Google Chrome Releases blog, 2010.09.14)

$B!!3V=5(B Google Chrome 6.0.472.59 $BEP>l!#(B10 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B Microsoft 2010 $BG/(B 9 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2010.09.15)

$B!!M=Dj$I$*$j=P$^$7$?!#(B

$B!!(B($B$"$H$GA4LLE*$K=q$-$J$*$9M=Dj!D!D$C$F2?;~$@(B > $B26(B)

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B(973811) $BG'>Z$KBP$9$kJ]8n$N6/2=(B

$B!!(B2010.09.15 $BIU$G!"(BOutlook Express $B$*$h$S(B Windows $B%a!<%k$X$NBP1~$,DI2C$5$l$F$$$^$9!#(B

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2401593) Outlook Web Access $B$N@H:3J$5$l$k(B
(Microsoft, 2010.09.15)

$B!!(BExchange Server 2003 (SP2) / 2007 (SP1, SP2) $B$K7g4Y!#(B Outlook Web Access $B$K(B CSRF $B@H\:Y(B: Pwning corporate webmails (Tentacolo Viola, 2010.07.08)$B!#(B CVE-2010-3213

$B!!(BExchange 2000 SP3 / 2007 SP3 / 2010 $B$K$O$3$N7g4Y$O$J$$!#(B Exchange 2007 $BMxMQ

$B!!2sHr:v(B:

$B"#(B PDF$B$+$i$N>pJsO3$l$K$4MQ?4!AAmL3>J!"8D?ML>$,1\Mw$G$-$k%U%!%$%k$r8m7G:\(B
(so-net $B%;%-%e%j%F%#DL?.(B, 2010.09.14)

$B!!!V$7$*$j!W$K8D?M>pJs!#(B

$B!!(BPDF$B%U%!%$%k$r:n@.$9$k:]$K$O!"J#?t$N%U%!%$%k$r7k9g$7$F0l$D$N%U%!%$%k$K$9$k$3$H$,$G$-$k!#(BPDF$B:n@.%D!<%k$NCf$K$O!"$=$N%U%!%$%k7k9g;~$K!"<+F0E*$K85$N%U%!%$%k$NL>A0$r$7$*$j$K$7$FIU2C$9$k$b$N$,$"$k!#$3$N$3$H$rCN$i$J$$$H!">pJsN.=P;v8N$r0z$-5/$3$7$+$M$J$$!#$?$H$($P!"%U%!%$%kL>!a8D?ML>$H$J$C$F$$$k%U%!%$%k$r7k9g$9$k$H!"8D?ML>$r4^$`$7$*$j$,>!

$B"#(B APSA10-03: Security Advisory for Flash Player
(Adobe, 2010.09.13)

$B!!(BFlash Player 10.1.82.76 $B0JA0(B (Windows, Mac, Unix $BMQ(B) / 10.1.92.10 $B0JA0(B (Android $BMQ(B) $B$K!"G$0U$N%3!<%I$NCVE-2010-2884$B!#(B $B4{$K96N,%3!<%I$,B8:_$9$k!#(B $B$3$N7g4Y$O(B Acrobat / Adobe Reader 9.3.4 $B0JA0$K$b1F6A$9$k!#(B

$B!!(BFlash Player $B$N=$@5HG$O(B 2010.09.27 (US $B;~4V(B) $B$K8x3+$5$l$kM=Dj!#(B $B$^$?(B Acrobat / Adobe Reader $B$N=$@5HG$O(B 2010.10.04 (US $B;~4V(B) $B$K8x3+$5$l$kM=Dj!#(B

$B!!4XO"(B:

2010.09.21 $BDI5-(B:

$B!!(BFlash Player 10.1.85.3 / 9.0.283$B!"(BFlash Player for Android 10.1.95.1 $B$,A0E]$78x3+$5$l$^$7$?!#(BIlion $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BFlash Player $B$O(B Google Chrome $B$K$b4^$^$l$F$^$9$,!"(BGoogle Chrome 6.0.472.62 $B$G=$@5$5$l$F$$$k$=$&$G$9!#(B

2010.09.22 $BDI5-(B:

$B!!4XO"(B: Flash Player$B$K?7$?$J@H ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.09.21)

2010.09.23 $BDI5-(B:

$B!!4XO"(B: Technical Analysis of the Recent Adobe Flash Zero-Day Vulnerability (trendmicro blog, 2010.09.22)


$B"#(B 2010.09.14

$B"#(B $BDI5-(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B!!(BAPSA10-02: Security Advisory for Adobe Reader and Acrobat (Adobe, 2010.09.13 $B2~D{(B)$B!#(B

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

$B!!(B2010.10.04 (US $B;~4V(B) $B$K?7HG$r8x3+M=Dj$@$=$&$G!#(B3 $B=54V$b@h$NOC!#(B

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

$B!!$O$$$O$$!#(B

$B!!4XO"(B:

$B$R$5$S$5$K!VBgNL%a!<%kAw?.7?%&%$%k%9!W$,N.9T$C$F$$$kLOMM(B (W32/VBMania@MM)

$B!!4XO"!#(B

Firefox 3.6.9/3.5.12$B!"(BThunderbird 3.1.3/3.0.7 $BEP>l(B

$B!!>e5-$N$h$&$K!"<+F099?7$O$G$-$J$$$h$&$G$9$,!"(Bmozilla.jp $B$G$N(B Firefox 3.6.9 $B$N8x3+$,Cf;_$5$l$?$o$1$G$O$J$$$N$G!"(B $B$B$7%$%s%9%H!<%k$G$-$^$9!#(B

$B!!$"$H!"(BFirefox 3.6.9 $B$G$O(B X-Frame-Options $B%l%9%]%s%9%X%C%@$K(B ($B$h$&$d$/(B) $BBP1~$7$F$$$^$9!#(B clickjacking $B967b$NGS=|$KMxMQ$G$-$^$9!#(B


$B"#(B 2010.09.13

$B"#(B $BDI5-(B

APSA10-02: Security Advisory for Adobe Reader and Acrobat

$B!!(BEnhanced Mitigation Experience Toolkit 2.0 $B$r;H$($P2sHr$G$-$k$=$&$G$9!#(B


$B"#(B 2010.09.10

$B"#(B iOS 4.1$B$N(BJailbreak$B
($B$D$d$F$6%K%e!<%9(B, 2010.09.09)

$B"#(B $BDI5-(B

8 $B7n(B 4 $BF|0J9_!"(BMicrosoft Update $B$,7c=E$K(B?

$B!!$h$&$d$/!"(BMicrosoft $BB&$G2?$i$+$NBP1~$,$J$5$l$?LOMM$G$9!#(B [XP] wuauclt.exe$B$H(Bsvchost.exe$B$,=E$$!&!&!&!&(B (Microsoft answers) $B$N(B harusora $B$5$s$NEj9F(B:

$B:rF|(BMS$B$NM-=~%5%]!<%H$+$iO"Mm$,M-$j!"8=:_$O(BMicrosoftUpdate$B$G99?7$N8!:w$r$+$1$k$@$1$G>I>u$O2r>C$9$k$H$N;v$G$9!#(B
$BFCJL2?$+$r%$%s%9%H!<%k$9$kI,MW$O$"$j$^$;$s!#(B
$BJ@$j$^$7$?!#(B

$B!!(BWindows$B!&(BMicrosoft Update$B$,CY$$!&=E$$(B (2ch.net) $B$G$b!"(B732 $B0J9_(B$B$KF1MM$N=q$-9~$_$,8+$i$l$k!#(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2269637) $B0BA4$G$J$$%i%$%V%i%j$N%m!<%I$K$h$j!"%j%b!<%H$G%3!<%I$,

$B"#(B Opera 10.62 released
(Opera, 2010.09.09)

$B"#(B $B$R$5$S$5$K!VBgNL%a!<%kAw?.7?%&%$%k%9!W$,N.9T$C$F$$$kLOMM(B (W32/VBMania@MM)
(various, 2010.09.10)

$B!!8+;v$KL>A0$,0c$&$J!D!D!#(B

2010.09.14 $BDI5-(B:

$B!!4XO"!#(B

2010.09.23 $BDI5-(B:

$B!!4XO"(B:

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2010 $BG/(B 9 $B7n(B
(Microsoft, 2010.09.10)

$B!!$b$&$=$s$J5(@a!#6[5^(B x 4$B!"=EMW(B x 5$B!#(BOffice $B$b$"$k$h!#(BMac $BHG(B Office $B$K$O1F6A$7$J$$$_$?$$!#(B


$B"#(B 2010.09.09

$B"#(B QuickTime$B$KL$=$@0$N?<9o$J@H
(so-net $B%;%-%e%j%F%#DL?.(B, 2010.09.02)

$B!!(BQuickTime 7.6.7 $B0JA0$K(B 0-day $B7g4Y!#(BQTPlugin.ocx $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$rCVE-2010-1818

$B!!(Bpatch $B$O$J$$!#(BCLSID {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} $B$K(B kill bit $B$r@_Dj$9$k$3$H$G2sHr$G$-$k!#(B

2010.09.24 $BDI5-(B:

$B!!(BQuickTime 7.6.8 $B$G=$@5$5$l$F$$$^$9!#(B

$B"#(B $B%&%$%k%9%P%9%?!<%3!<%]%l!<%H%(%G%#%7%g%s!&(BTrend Micro$B%S%8%M%9%;%-%e%j%F%#$K$*$1$k=$@5%W%m%0%i%`8x3+$N$*CN$i$;(B
($B%H%l%s%I%^%$%/%m(B, 2010.09.07)

$B!!(BTrend Micro $B%S%8%M%9%;%-%e%j%F%#(B 5.0 / 5.1 / 6.0$B!"%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 10.0 $B$K7g4Y!#!V5sF04F;k%b%8%e!<%k$N4F;k5!G=(B $B$,L58z$K$J$k!W@H$B%"%i!<%H(B/$B%"%I%P%$%6%j!'(B $B5sF04F;k%b%8%e!<%k$N4F;k5!G=(B $B$,L58z$K$J$kLdBj(B ($B%H%l%s%I%^%$%/%m(B, 2010.09.08 $B99?7(B) $B$K$h$k$H!"(B

$B5sF04F;k%b%8%e!<%k$N4F;k5!G=$NFbIt=hM}Cf$NFCDj>r7o2<$K$F!"=hM}$,L58z2=$5$l$kLdBj$,3NG'$5$l$^$7$?!#$3$NLdBj$r0-MQ$9$k$3$H$K$h$j!"967b

$B!!=$@5%W%m%0%i%`$,8x3+$5$l$F$$$^$9!#(B

$B"#(B About the security content of iOS 4.1 for iPhone and iPod touch
(apple, 2010.09.08)

$B!!(BiOS 4.1 $BEP>l!#(B24 $B7o$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B About the security content of Safari 5.0.2 and Safari 4.1.2
(Apple, 2010.09.07)

$B!!(BSafari 5.0.2 / 4.1.2 $BEP>l!#(B3 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#Fb(B 1 $B$D$O(B Windows $BHGFCM-!#(B

$B"#(B $B8xA3DDNs!'%&%#%K!<;H$$;yF8%]%k%N!D#3#3:PMF5?
($BKhF|(B, 2010.09.09)

$B!!7Y;!!"$h$&$d$/!V%-%c%C%7%e!W$rBP>]$K!#(B

$B!!BaJaMF5?$O!"#77n#1#5F|!"%&%#%K!<$rMxMQ$7!"%U%!%$%k>pJs$r0E9f2=$9$k!V%-%c%C%7%e%U%)%k%@!uBV$K$7$?$H$7$F$$$k!#

$B!!4XO"(B: $B;yF8%]%k%N$r(Bwinny$B$G8xA3DDNs:a(B ($B1|B

$B!!!V%9%+%$%i%$%s$K$h$k$R$-F($2;v7o$OA49q=i!W!V%W%j%&%9$K$h$k$R$-F($2;v7o$OA49q=i!W$J$s$F8@$o$J$$$G$7$g!#(B

$B!!%1!<%5%D$O$d$?$i=i$b$N$,9%$-$J$o$1$G$9$,!"$=$l$O$H$b$+$/!"!V(B$B%3%s%3%k%I=i$N;`K4;v8N(B$B!W$H$+8@$$$^$9$h!#(B

$B"#(B APSA10-02: Security Advisory for Adobe Reader and Acrobat
(Adobe, 2010.09.08)

$B!!(BAdobe Reader / Acrobat 9.3.4 ($B:G?7HG(B) $B0JA0$K(B 0-day $B7g4Y!#(B $B96N,(B PDF $B$r3+$/$HG$0U$N%3!<%I$,CVE-2010-2883$B!#(B $B4{$K$3$N7g4Y$rMxMQ$7$?96N,(B PDF $B%U%!%$%k$,=P2s$C$F$$$kLOMM!#(B

2010.09.13 $BDI5-(B:

$B!!(BEnhanced Mitigation Experience Toolkit 2.0 $B$r;H$($P2sHr$G$-$k$=$&$G$9!#(B

2010.09.14 $BDI5-(B:

$B!!(BAPSA10-02: Security Advisory for Adobe Reader and Acrobat (Adobe, 2010.09.13 $B2~D{(B)$B!#(B

We are in the process of finalizing a fix for the issue and expect to provide updates for Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 for Windows and Macintosh during the week of October 4, 2010.

$B!!(B2010.10.04 (US $B;~4V(B) $B$K?7HG$r8x3+M=Dj$@$=$&$G!#(B3 $B=54V$b@h$NOC!#(B

Please note that these Adobe Reader and Acrobat updates represent an accelerated release of the next quarterly security update originally scheduled for October 12, 2010. With this accelerated schedule, we do not plan to release any new updates for Adobe Reader and Acrobat on October 12, 2010.

$B!!$O$$$O$$!#(B

$B!!4XO"(B:

2010.09.22 $BDI5-(B:

$B!!4XO"(B: Adobe PDF$B4XO"@=IJ$K%<%m%G%$@H ($B%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#(B blog, 2010.09.21)

2010.09.24 $BDI5-(B:

$B!!;vNc(B: Adobe Reader$B$N%<%m%G%$@H (IBM ISS, 2010.09.22)


$B"#(B 2010.09.08

$B"#(B Firefox 3.6.9/3.5.12$B!"(BThunderbird 3.1.3/3.0.7 $BEP>l(B
(Mozilla.org, 2010.09.08)

$B!!=P$F$^$9!#(B

2010.09.13 $BDI5-(B:

$B!!(BFirefox $B$N%;%-%e%j%F%#%"%C%W%G!<%H(B (3.6.9/3.5.12) $B$r8x3+$7$^$7$?(B (Mozilla Japan $B%V%m%0(B, 2010.09.08) $B$,(B 2010.09.11 $BIU$G99?7$5$l$F$$$^$9!#(B $B8=:_!"(BFirefox 3.6.9 $B$X$N<+F099?7$OL58z$H$J$C$F$$$kLOMM$G$9!#(B cadz $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2010/09/11 $B99?7(B: $B8=:_%/%i%C%7%e%P%0$ND4::$N$?$a!"99?75!G=$OL58z$K$J$C$F$$$^$9!#(B

2010.09.14 $BDI5-(B:

$B!!>e5-$N$h$&$K!"<+F099?7$O$G$-$J$$$h$&$G$9$,!"(Bmozilla.jp $B$G$N(B Firefox 3.6.9 $B$N8x3+$,Cf;_$5$l$?$o$1$G$O$J$$$N$G!"(B $B$B$7%$%s%9%H!<%k$G$-$^$9!#(B

$B!!$"$H!"(BFirefox 3.6.9 $B$G$O(B X-Frame-Options $B%l%9%]%s%9%X%C%@$K(B ($B$h$&$d$/(B) $BBP1~$7$F$$$^$9!#(B clickjacking $B967b$NGS=|$KMxMQ$G$-$^$9!#(B

2010.09.16 $BDI5-(B:

$B!!(BFirefox 3.6.10 $B=P$^$7$?!#LdBj$H$J$C$F$$$?!V%/%i%C%7%e%P%0!W$,2r7h$5$l$?$h$&$G$9!#(B

$B!!(BSeaMonkey $B$b(B 2.0.8 $B$,=P$F$$$^$9!#(Btvb19131 $B$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

2010.09.17 $BDI5-(B:

$B!!(BFirefox 3.5 $B7O$d(B Thunderbird $B$b99?7$5$l$F$$$?$s$G$9$M!#(B

$B"#(B Google Chrome Stable and Beta Channel Update
(Google Chrome Release blog, 2010.09.02)

$B!!(BGoogle Chrome 6.0.472.53 $BEP>l!#5!G=8~>e(B + $B%;%-%e%j%F%#=$@5!#(B14 $B7o$N7g4Y$,=$@5$5$l$F$$$k!#(BHigh x 7$B!"(BMedium x 4$B!"(BLow x 3$B!#(B $B$^$?!"(B5.0.375.127 $B$G$N(B

Credit and $1337 to Marc Schoenefeld for enabling us to work around another Windows kernel bug [51070].

$B$,IT==J,$@$C$?$=$&$G!"$3$l$b=$@5$5$l$F$$$k!#(B

2010.09.08 $BDI5-(B:

$B!!!D!D$H8@$C$F$$$k4V$K!"(BGoogle Chrome 6.0.472.55 $BEP>l!#%;%-%e%j%F%#=$@5$O$J$$$h$&$G$9!#(B


$B"#(B 2010.09.07


$B"#(B 2010.09.06


$B"#(B 2010.09.05

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 8 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!$$$^$4$mDI5-!#(B

MS10-047 - $B=EMW(B: Windows $B%+!<%M%k$N@H:3J$5$l$k(B (981852)

$B!!(BWindows XP 32bit / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B Windows $B%+!<%M%k$K(B 3 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$d(B DoS $B967b$,2DG=!#(B Windows XP 64bit / Server 2003 $B$K$O$3$N7g4Y$O$J$$!#(B

  • Windows $B%+!<%M%k$N%G!<%?=i4|2=$N@HCVE-2010-1888

    Windows XP 32bit $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Exploitability Index: 1

  • $B%+!<%M%k$N%@%V%k(B $B%U%j!<$N@HCVE-2010-1889

    Windows Vista / Server 2008 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Exploitability Index: 2

  • Windows $B%+!<%M%k(B $B$NITE,@Z$J8!>Z$N@HCVE-2010-1890

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(B local user $B$K$h$k(B DoS $B967b$,2DG=!#(B Exploitability Index: N/A

MS10-048 - $B=EMW(B: Windows $B%+!<%M%k%b!<%I(B $B%I%i%$%P!<$N@H:3J$5$l$k(B (2160329)

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B%+!<%M%k%b!<%I%I%i%$%P$K(B 5 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$d(B DoS $B967b$,2DG=!#(B

  • Win32k $B$N6-3&%A%'%C%/$N@HCVE-2010-1887

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k(B DoS $B967b$,2DG=!#(B Exploitability Index: N/A

  • Win32k $B$NNc30=hM}$N@HCVE-2010-1894

    Windows XP / Server 2003 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%W!<%k(B $B%*!<%P!<%U%m!<$N@HCVE-2010-1895

    Windows XP / Server 2003 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%f!<%6!Z$N@HCVE-2010-1896

    Windows XP / Server 2003 / Vista / Server 2008 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

  • Win32k $B$N%&%#%s%I%&:n@.$N@HCVE-2010-1897

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(BExploitability Index: 1

$B!!4XO"(B: MS10-048 an explanation of the Defense in Depth fixes (Microsoft Security Research & Defense, 2010.08.10)

MS10-049 - $B6[5^(B: SChannel $B$N@H

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BWindows $B$N(B Secure Channel (SChannel) $B$K(B 2 $B$D$N7g4Y$,$"$j!"$J$j$9$^$7$dG$0U$N%3!<%I$N7$/!#(B

MS10-050 - $B=EMW(B: Windows $B%`!<%S!<(B $B%a!<%+!<$N@H

MS10-051 - $B6[5^(B: Microsoft XML $B%3%"(B $B%5!<%S%9$N@H

MS10-052 - $B6[5^(B: Microsoft MPEG Layer-3 $B%3!<%G%C%/$N@H

MS10-053 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (2183461)

$B!!(BIE 6 / 7 / 8 $B$K(B 6 $B$D$N7g4Y$,$"$j!">pJsO31L$dG$0U$N%3!<%I$N7$/!#(B

  • $B%$$Y%s%H(B $B%O%s%I%i!<$N%/%m%9(B $B%I%a%$%s$N@HCVE-2010-1258

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$7!"$+$D!V%^%&%9$r;HMQ$7$F%V%i%&%6!<%&%#%s%I%&$HBPOC$9$k!W$H>pJsO31L$,H/@8!#(B Exploitability Index: 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2556

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2557

    IE 6 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B6%9g>uBV$N%a%b%jGKB;$N@HCVE-2010-2558

    IE 6 / 7 / 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • $B=i4|2=$5$l$F$$$J$$%a%b%jGKB;$N@HCVE-2010-2559

    IE 8 $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • HTML $B%l%$%"%&%H$N%a%b%jGKB;$N@HCVE-2010-2560

    IE 6 / 7 / $B$K7g4Y$,$"$j!"96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

MS10-054 - $B6[5^(B: SMB $B%5!<%P!<$N@H

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BSMB $B%W%m%H%3%k

  • SMB $B$N%W!<%k(B $B%*!<%P!<%U%m!<$N@HCVE-2010-2550

    Windows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(BSMB $B%W%m%H%3%kl9g$OG'>Z$OITMW!#(B Windows Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$G$O!"!V%Q%9%o!<%I%Y!<%9$N6&M-$,L58z!W$G$"$l$PG'>Z$OITMW!"$=$&$G$J$1$l$PG'>Z$,I,MW!#(B Exploitability Index: 2

    $B4XO"(B: MS10-054: Exploitability Details for the SMB Server Update (Microsoft Security Research & Defense, 2010.08.10)

  • SMB $B$NJQ?t$N8!>Z$N@HCVE-2010-2551

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B SMB $B%W%m%H%3%k

  • SMB $B$N%9%?%C%/>CHq$N@HCVE-2010-2552

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B SMB $B%W%m%H%3%k

MS10-055 - $B6[5^(B: Cinepak Codec $B$N@H

MS10-056 - $B6[5^(B: Microsoft Office Word $B$N@H

$B!!(BMicrosoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWorks 9 $B$K(B 4 $B$D$N7g4Y!#(B

  • Word $B$N%l%3!<%I$N2r@O$N@HCVE-2010-1900

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BWorks 9 $B$K7g4Y!#(B Word $B%U%!%$%k$N=hM}$K7g4Y$,$"$j!"(B $B96N,(B Word $B%U%!%$%k$r3+$/$HG$0U$N%3!<%I$,

  • Word $B$N(B RTF $B7A<0$N2r@O%(%s%8%s$N%a%b%jGKB;$N@HCVE-2010-1901

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(B RTF $B7A<0%G!<%?$N2r@O$K7g4Y$,$"$j!"96N,(B RTF $B7A<0%G!<%?$K$h$C$FG$0U$N%3!<%I$,

  • Word $B$N(B RTF $B7A<0$N2r@O$N%P%C%U%!!<(B $B%*!<%P!<%U%m!<$N@HCVE-2010-1902

    Microsoft Word 2002 (XP) / 2003 / 2007$B!"(BOffice 2004 / 2008 for Mac$B!"(B Open XML File Format Converter for Mac$B!"(BWord Viewer$B!"(B Word/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/$K7g4Y!#(B RTF $B7A<0%G!<%?$N2r@O$K7g4Y$,$"$j!"96N,(B RTF $B7A<0%G!<%?$K$h$C$FG$0U$N%3!<%I$,

  • Word HTML $B%j%s%/%*%V%8%'%/%H$N%a%b%jGKB;$N@HCVE-2010-1903

    Microsoft Word 2002 (XP) / 2003$B!"(BWord Viewer $B$K7g4Y!#(B Word $B%U%!%$%k$N=hM}$K7g4Y$,$"$j!"96N,(B Word $B%U%!%$%k$r3+$/$HG$0U$N%3!<%I$,

MS10-057 - $B=EMW(B: Microsoft Office Excel $B$N@H

MS10-058 - $B=EMW(B: TCP/IP $B$N@H:3J$5$l$k(B (978886)

$B!!(BWindows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B TCP/IP $Be>:$,2DG=!#(B

  • IPv6 $B$N%a%b%jGKB;$N@HCVE-2010-1892

    Windows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B IPv6 $B

  • Windows $B%M%C%H%o!<%-%s%0$N@0?t$N%*!<%P!<%U%m!<$N@HCVE-2010-1893

    Windows Vista SP1 / Server 2008 gold / 7 / Server 2008 $B$K7g4Y!#(B $BF~NO%P%C%U%!!<$N=hM}$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$,2DG=!#(B Vista SP2 / Server SP2 $B$K$O$3$N7g4Y$O$J$$!#(B Exploitability Index: 1

MS10-059 - $B=EMW(B: $B%5!<%S%9$N%H%l!<%95!G=$N@H:3J$5$l$k(B (982799)

$B!!(BWindows Vista / Server 2008 / 7 / Server 2008 R2 $B$K7g4Y!#(B $B%5!<%S%9$N%H%l!<%95!G=$K(B 2 $B$D$N7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B

  • $B%l%8%9%H%j(B $B%-!<$N(B ACL $B$N%H%l!<%9$N@HCVE-2010-2554

    $B%f!<%6$,!V%5!<%S%9$N%H%l!<%95!G=$N%l%8%9%H%j(B $B%-!<$KIT@53N$J%"%/%;%9@)8f%j%9%H(B (ACL) $B$rG[CV$7$?>l9g!W$K!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B Exploitability Index: N/A

  • $B%H%l!<%9$N%a%b%jGKB;$N@HCVE-2010-2555

    $B%l%8%9%H%j$N=hM}$K7g4Y$,$"$j!"D9Bg$J%l%8%9%H(B%j$K$h$C$F8"8B>e>:$,2DG=!# Exploitability Index: 1

MS10-060 - $B6[5^(B: Microsoft .NET $B6&DL8@8l%i%s%?%$%`$*$h$S(B Microsoft Silverlight $B$N@H

$B!!(B.NET Framework 2.0 / 3.5$B!"(BSilverlight 2 / 3 $B$K(B 2 $B$D$N7g4Y!#(B

  • Microsoft Silverlight $B$N%a%b%jGKB;$N@HCVE-2010-0019

    Silverlight 3 $B$K7g4Y!#%]%$%s%?$N=hM}$K7g4Y$,$"$j!"(B $B96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

  • Microsoft Silverlight $B$*$h$S(B Microsoft .NET Framework CLR $B$N2>A[%a%=%C%I$N0QG$$N@HCVE-2010-1898

    .NET Framework 2.0 / 3.5$B!"(BSilverlight 2 / 3 $B$K7g4Y$,$"$j!"(B $B96N,(B Web $B%Z!<%8$r1\Mw$9$k$HG$0U$N%3!<%I$,

Renegotiating TLS

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 / 7 / Server 2008 R2 $B$O!"(B MS10-049 - $B6[5^(B: SChannel $B$N@H $B$rE,MQ$9$k$3$H$G!"(BRFC5746 $B$KBP1~$9$k!#(B


$B"#(B 2010.09.03

$B"#(B $BDI5-(B

Microsoft 2010 $BG/(B 6 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(B$B%^%$%/%m%=%U%H&IJ$X$N1F6A$K$D$$$F(B ($BIY;N%<%m%C%/%9(B, 2010.09.01 $B99?7(B)$B!#(BApeosWare $BB&$G$NBP1~$,$h$&$d$/40N;!#(B


$B"#(B 2010.09.02

$B"#(B About the security content of iTunes 10
(Apple, 2010.09.02)

$B!!(BWindows $BHG$N(B iTunes 10 $B$K$O!"(BSafari 5.0.1 $B$G=$@5$5$l$?(B WebKit $B$N=$@5$,4^$^$l$F$$$k$=$&$G$9!#(B


$B"#(B 2010.09.01

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (2269637) $B0BA4$G$J$$%i%$%V%i%j$N%m!<%I$K$h$j!"%j%b!<%H$G%3!<%I$,

$B!!4XO"(B:

$B"#(B $B$$$m$$$m(B (2010.09.01)
(various)


$B2a5n$N5-;v(B: 2010 | 2009 | 2008 | 2007 | 2006 | 2005 | 2004 | 2003 | 2002 | 2001 | 2000 | 1999 | 1998


[$B%;%-%e%j%F%#%[!<%k(B memo]