Announced November 8, 2011 Reporter Yosuke Hasegawa Impact High Products Firefox, SeaMonkey, Thunderbird Fixed in Firefox 3.6.24 Firefox 8 SeaMonkey 2.5 Thunderbird 3.1.16 Thunderbird 8 Description Yosuke Hasegawa reported that the Mozilla browser engine mishandled invalid sequences in the Shift-JIS encoding. When encountering an invalid pair Mozilla would turn the entire two-byte sequence into a
ï¼»ãããï¼½E4Xã§æ»æã§ããï¼ ã§ããªãï¼ï¼æç§æ¸ã«è¼ããªãWebã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ï¼6ï¼ï¼1/3 ãã¼ã¸ï¼ XSSã«CSRFã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ãã£ã¬ã¯ããªãã©ãã¼ãµã«â¦â¦Webã¢ããªã±ã¼ã·ã§ã³ã®ããã°ã©ããç¥ã£ã¦ããã¹ãèå¼±æ§ã¯ãã£ã±ãããã¾ããããã§æ¬é£è¼ã§ã¯ããã®ãããªã¡ã¸ã£ã¼ãªãã®â以å¤âãæãä¸ãã¦ããã¾ã ï¼ç·¨éé¨ï¼ ECMAScriptã§XMLãæ±ãâE4Xâ çããããã«ã¡ã¯ãã¯ãããããããã§ããä»åã¯ãMozilla Firefoxã§ã¯ãã¹ãã¡ã¤ã³å¶ç´ãåé¿ããæ¹æ³ã®ä¸ä¾ã¨ãã¦ãE4Xã¨ããæ©è½ãå©ç¨ããæ»ææ¹æ³ãç´¹ä»ãã¾ãã E4Xã¨ã¯ããECMAScript for XMLãã®ç¥ã§ãããJavaScriptãActionScriptãªã©ã®ECMAScriptå¦çç³»ã«ããã¦ãXMLããã¤ãã£ãæ©è½ã¨ãã¦æ±ãããã®ä»æ§ã§ãã ç¾å¨ãFirefoxã®Ja
2010/07/23ãã³ã¼ã¹ï¼å ç¥ãã£ã¦ã ãå ç¥ãã£ã¦ããè¨äºã¯ãããã¨ã¼ã¸ã§ã³ãæ§ããã°[netagent-blog.jp]ã«æ²è¼ããã¦ããè¨äºã§ãããç¾å¨ãããã¨ã¼ã¸ã§ã³ãã«å¨ç±ãã¦ããªãã©ã¤ã¿ã¼ã®è¨äºãå«ã¿ã¾ãã Firefoxã®Web Workersã«ãããèå¼±æ§ã«ã¤ã㦠ã¿ãªãããããã«ã¡ã¯ããããã¨ã¼ã¸ã§ã³ãæ ªå¼ä¼ç¤¾ ç ç©¶éçºé¨ã®é·è°·å·ã§ãã ä»é±ã®æ°´ææ¥ã« Mozilla Firefox 3.6.7 ããªãªã¼ã¹ããã¾ãããããã®ãã¼ã¸ã§ã³ã«ã¯ç§ãçºè¦ããèå¼±æ§(*1)ã®ä¿®æ£ãå«ã¾ãã¦ãã¾ãã仿¥ã¯ãã®å 容ã«ã¤ãã¦èª¬æãããã¨æãã¾ãã (*1) MFSA 2010-42: Web ã¯ã¼ã«ã¼ã® importScripts ãéããã¯ãã¹ãµã¤ããã¼ã¿æ¼ãã ----- â æ¦è¦ Mozilla Firefox 3.6.4 ããã³ 3.6.6 ã«ããã¦ãWeb Workers ã¨
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}