���J���F2010/09/12 12:51�@�ŏI�X�V���F2011/03/14 0:53

JVNTR-2010-23
Microsoft Windows �ɂ����� DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (TA10-238A)

Tv


Microsoft Windows ���񋟂��� DLL �����p�X�A���S���Y���̎����ɋN�����A�N�����ɁA�{���ǂݍ��ނׂ��łȂ��׍H���ꂽ DLL ��ǂݍ��މ”\���̂���v���O���������݂��܂��B

�e�����󂯂�V�X�e��
�@Windows �v���b�g�t�H�[����� DLL ���g�p���ē��삷��v���O�������e�����󂯂�”\��������܂��B
�@�Ȃ��A�v���O�����ɐƎ㐫�����݂��邩�ۂ��́A�v���O�������ǂ̂悤�� DLL ��ǂݍ��ނ��ɂ��܂��B

nCxg


���� (JST)���e
2011-03-09 07:39 �}�C�N���\�t�g
ms11-mar: �}�C�N���\�t�g �Z�L�����e�B��� 2011 �N 3 ���̃Z�L�����e�B���
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS11-015, CVE-2011-0032) �΍��Ń����[�X�FDirectShow
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS11-016, CVE-2010-3146) �΍��Ń����[�X�FGroove
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS11-017, CVE-2011-0029) �΍��Ń����[�X�F�����[�g�f�X�N�g�b�v
2011-02-09 07:45 �}�C�N���\�t�g
ms11-feb: �}�C�N���\�t�g �Z�L�����e�B��� 2011 �N 2 ���̃Z�L�����e�B���
DLL Preloading ��� (MS11-003, CVE-2011-0038) �΍��Ń����[�X�FInternet Explorer
2011-01-12 07:44 �}�C�N���\�t�g
ms11-jan: �}�C�N���\�t�g �Z�L�����e�B��� 2011 �N 1 ���̃Z�L�����e�B���
DLL Preloading ��� (MS11-001, CVE-2010-3145) �΍��Ń����[�X�FBackup Manager
2010-12-15 07:51 �}�C�N���\�t�g
ms10-dec: �}�C�N���\�t�g �Z�L�����e�B��� 2010 �N 12 ���̃Z�L�����e�B���
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS10-093, CVE-2010-3967) �΍��Ń����[�X�F���[�r�[ ���[�J�[
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS10-094, CVE-2010-3965) �΍��Ń����[�X�FMedia �G���R�[�_�[
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS10-095, CVE-2010-3966) �΍��Ń����[�X�FBranchCache
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS10-096, CVE-2010-3147) �΍��Ń����[�X�F�A�h���X��
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (MS10-097, CVE-2010-3144) �΍��Ń����[�X�F�C���^�[�l�b�g�ڑ��̃T�C���A�b�v �E�B�U�[�h
2010-11-04 �A�h�r
APSB10-26: Adobe Flash Player�p�Z�L�����e�B�A�b�v�f�[�g���J
�Z�L�����e�B�X�V�v���O���� (CVE-2010-3976) �̃����[�X: Flash Player 10.1.102.64/9.0.289.0
2010-10-20 Mozilla Japan
MFSA 2010-71: ���S�łȂ����C�u�����̓ǂݍ��݂Ɋւ�����
�Z�L�����e�B�X�V�v���O���� (CVE-2010-3181,CVE-2010-3182) �̃����[�X: Firefox 3.6.11/3.5.14, Thunderbird 3.1.5/3.0.9
Windows �ɂ����� DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (CVE-2010-3181)�ALinux �ɂ����郉�C�u�����ǂݍ��ݖ�� (CVE-2010-3182)
2010-10-18 �A�h�r
APSB10-24: InDesign�̃Z�L�����e�B�A�b�v�f�[�g���J
�Z�L�����e�B�X�V�v���O���� (CVE-2010-3153) �̃����[�X: InDesign CS5 7.0.3/CS4 6.0.6, InDesign Server CS5 7.0.3, InCopy CS5 7.0.3/CS4 6.0.6
2010-10-14 Lhaplus
�����p�X�̖��ɋN������Ǝ㐫
���s�t�@�C���ǂݍ��݂Ɋւ���Ǝ㐫 (CVE-2010-3158) �΍��Ń����[�X�FLhaplus 1.59
2010-10-11 Lhaplus
�����p�X�̖��ɋN������Ǝ㐫
DLL �ǂݍ��݂Ɋւ���Ǝ㐫 (CVE-2010-2368) �΍��Ń����[�X�FLhaplus 1.58
2010-09-15 �A�b�v��
HT4339: QuickTime 7.6.8 �̃Z�L�����e�B�R���e���c�ɂ‚���
�Z�L�����e�B�X�V�v���O���� (CVE-2010-1819) �̃����[�X: QuickTime 7.6.8
2010-09-07 Mozilla Japan
MFSA 2010-52: Windows XP �ɂ����� DLL �ǂݍ��ݐƎ㐫
�Z�L�����e�B�X�V�v���O���� (CVE-2010-3131) �̃����[�X: Firefox 3.6.9/3.5.12, Thunderbird 3.1.3/3.0.7
2010-09-01 23:27 US-CERT
Insecure Loading of Dynamic Link Libraries in Windows Applications
US-CERT Current Activity
����� (Fix it 50522) �̃����[�X���A�i�E���X
2010-09-01 13:42 �}�C�N���\�t�g
�}�C�N���\�t�g �Z�L�����e�B �A�h�o�C�U�� (2269637): ���S�łȂ����C�u�����̃��[�h�ɂ��A�����[�g�ŃR�[�h�����s�����
Fix it (WebDAV ����у����[�g�̃l�b�g���[�N���L����̃��C�u�����̃��[�h������) �̒�
2010-08-27 05:40 US-CERT
TA10-238A: Microsoft Windows Insecurely Loads Dynamic Libraries
US-CERT ���[�����O���X�g�o�R�� Technical Cyber Security Alert ���M
���S�łȂ����C�u�����[�̃��[�h (DLL�̃v�����[�h) �����A�i�E���X
2010-08-26 01:01 US-CERT
Insecure Loading of Dynamic Link Libraries in Windows Applications
US-CERT Current Activity
�Z�L�����e�B �A�h�o�C�U�� (VU#707943) �̌��J���A�i�E���X
2010-08-25 15:44 Metasploit Project
Better, Faster, Stronger: DLLHijackAuditKit v2
DLLHijackAuditKit V2 �����[�X
2010-08-25 Exploit-Database
DLL Hijacking - Vulnerable Applications
���S�łȂ����C�u�����[�̃��[�h (DLL�̃v�����[�h) �����A�i�E���X
2010-08-24 10:07 �}�C�N���\�t�g
�}�C�N���\�t�g �Z�L�����e�B �A�h�o�C�U�� (2269637): ���S�łȂ����C�u�����̃��[�h�ɂ��A�����[�g�ŃR�[�h�����s�����
�Z�L�����e�B �A�h�o�C�U�� (2269637) �̌��J
2010-08-23 14:48 Metasploit Project
Exploiting DLL Hijacking Flaws
DLLHijackAuditKit �����[�X
2010-08-23 SANS Internet Storm Center
DLL hijacking vulnerabilities
�Ǝ㐫���A���؃c�[���̗��ʂ��
2010-08-19 00:05 ACROS
ASPR #2010-08-18-1-PUB: Remote Binary Planting in Apple iTunes for Windows
�Z�L�����e�B �A�h�o�C�U�� (CVE-2010-1795) �̌��J
2010-08-12 �A�b�v��
HT4105: iTunes 9.1 �̃Z�L�����e�B�R���e���c�ɂ‚���
�Z�L�����e�B�X�V�v���O���� (CVE-2010-1795) �̃����[�X: iTunes 9.1
2010-04-13 01:51 ACROS
ASPR #2010-04-12-1-PUB: Remote Binary Planting in VMware Tools for Windows
�Z�L�����e�B �A�h�o�C�U�� (CVE-2010-1141) �̌��J
2010-03-30 VMware
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
�Z�L�����e�B�X�V�v���O���� (CVE-2010-1141) �̃����[�X
2010-01-31 �J���t�H���j�A��w
CSE-2010-2.pdf: Automatic Detection of Vulnerable Dynamic Component Loadings
�Z�p���|�[�g�̌��J (Web�T�C�g�Ɍf��)
2004-09-02 �}�C�N���\�t�g
Dynamic-Link Library Search Order
Windows XP SP2 SafeDllSearchMode (�f�t�H���g�L��) �̓���
2003-07-03 �}�C�N���\�t�g
Dynamic-Link Library Search Order
Windows 2000 SP4 SafeDllSearchMode (�f�t�H���g����) �̓���
2001-11-16 �}�C�N���\�t�g
Dynamic-Link Library Search Order
Windows XP SafeDllSearchMode (�f�t�H���g����) �̓���
2000-09-18 Georgi Guninski
Georgi Guninski security advisory #21, 2000 : Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases
�Ǝ㐫�ƌ��؃R�[�h�̌��J (Web�T�C�g�Ɍf��)


Ql



  1. Technical Cyber Security Alert TA10-238A
    Microsoft Windows Insecurely Loads Dynamic Libraries
  2. Japan Vulnerability Note JVNTA10-238A
    Microsoft Windows �ɂ����� DLL �ǂݍ��݂Ɋւ���Ǝ㐫
  3. DLL �ǂݍ��݂Ɋւ���Ǝ㐫
    1. CVE-2010-1141 : VMware Tools
    2. CVE-2010-1795 : Apple iTunes
    3. CVE-2010-1819 : Apple QuickTime
    4. CVE-2010-1911 : SdcWebSecureBase
    5. CVE-2010-2368 : Lhaplus
    6. CVE-2010-2600 : BlackBerry Desktop Software
    7. CVE-2010-3124 : VLC Media Player
    8. CVE-2010-3125 : TeamMate Audit Management Software Suite
    9. CVE-2010-3126 : avast!
    10. CVE-2010-3127 : Adobe PhotoShop
    11. CVE-2010-3128 : TeamViewer
    12. CVE-2010-3129 : uTorrent
    13. CVE-2010-3130 : TechSmith Snagit
    14. CVE-2010-3131 : Mozilla Firefox Thunderbird
    15. CVE-2010-3132 : Adobe Dreamweaver
    16. CVE-2010-3133 : Wireshark
    17. CVE-2010-3134 : Google Earth
    18. CVE-2010-3135 : Cisco Packet Tracer
    19. CVE-2010-3136 : Skype
    20. CVE-2010-3137 : Nullsoft Winamp
    21. CVE-2010-3138 : Microsoft Indeo filter
    22. CVE-2010-3139 : Microsoft Windows Progman Group Converter
    23. CVE-2010-3140 : Microsoft Windows Internet Communication Settings
    24. CVE-2010-3141 : Microsoft PowerPoint
    25. CVE-2010-3142 : Microsoft Office PowerPoint
    26. CVE-2010-3143 : Microsoft Windows Contacts
    27. CVE-2010-3144 : Microsoft Internet Connection Signup Wizard
    28. CVE-2010-3145 : Microsoft Vista BitLocker Drive Encryption API
    29. CVE-2010-3146 : Microsoft Office Groove
    30. CVE-2010-3147 : Microsoft Address Book
    31. CVE-2010-3148 : Microsoft Visio
    32. CVE-2010-3149 : Adobe Device Central
    33. CVE-2010-3150 : Adobe Premier Pro
    34. CVE-2010-3151 : Adobe On Location
    35. CVE-2010-3152 : Adobe Illustrator
    36. CVE-2010-3153 : Adobe InDesign , Adobe InDesign Server, Adobe InCopy
    37. CVE-2010-3154 : Adobe Extension Manager
    38. CVE-2010-3155 : Adobe ExtendScript Toolkit
    39. CVE-2010-3161 : TeraPad
    40. CVE-2010-3163 : Fenrir Sleipnir
    41. CVE-2010-3181 : Mozilla Firefox, Thunderbird, SeaMonkey
    42. CVE-2010-3190 : ATL MFC Trace Tool
    43. CVE-2010-3191 : Adobe Captivate
    44. CVE-2010-3199 : TortoiseSVN
    45. CVE-2010-3337 : Microsoft Office
    46. CVE-2010-3397 : PGP Desktop
    47. CVE-2010-3402 : UltraEdit
    48. CVE-2010-3403 : Qualcomm eXtensible Diagnostic Monitor
    49. CVE-2010-3914 : GVim
    50. CVE-2010-3965 : Microsoft Windows Media
    51. CVE-2010-3966 : Microsoft BranchCache
    52. CVE-2010-3967 : Microsoft Windows Movie Maker
    53. CVE-2010-3975 : Adobe Flash Player
    54. CVE-2010-3976 : Adobe Flash Player
    55. CVE-2010-4182 : Data Access Objects
    56. CVE-2011-0029 : Microsoft Remote Desktop
    57. CVE-2011-0032 : Microsoft DirectShow
    58. CVE-2011-0403 : ImgBurn
  4. ���s�t�@�C���ǂݍ��݂Ɋւ���Ǝ㐫
    1. CVE-2010-2369 : Lhasa
    2. CVE-2010-3156 : K2Editor
    3. CVE-2010-3157 : XacRett
    4. CVE-2010-3158 : Lhaplus
    5. CVE-2010-3159 : Explzh
    6. CVE-2010-3160 : Archive Decoder
    7. CVE-2010-3162 : Apsaly
    8. CVE-2010-3164 : Fenrir Sleipnir, Grani
    9. CVE-2010-3165 : Yokka NoEditor, Yokka OuiEditor, Yokka UnEditor, Yokka DeuxEditor, Yokka SQLEditorXP, Yokka SQLEditorTE, Yokka SQLEditor, Yokka SQLEditorClassic
    10. CVE-2011-0452 : Lunascape
  5. Linux �‹��ɂ����郉�C�u�����ǂݍ��ݖ��
    1. CVE-2010-3182 : Mozilla Firefox, Thunderbird, SeaMonkey
    2. CVE-2010-3349 : Ardour
    3. CVE-2010-3350 : bareFTP
    4. CVE-2010-3351 : Bristol
    5. CVE-2010-3353 : Cowbell
    6. CVE-2010-3354 : Dropbox
    7. CVE-2010-3355 : Ember
    8. CVE-2010-3357 : gnome-subtitles
    9. CVE-2010-3358 : HenPlus JDBC SQL-Shell
    10. CVE-2010-3360 : Hipo
    11. CVE-2010-3361 : Shrew Soft IKE
    12. CVE-2010-3362 : lastfm
    13. CVE-2010-3363 : roaraudio
    14. CVE-2010-3364 : VIPS
    15. CVE-2010-3365 : Mistelix
    16. CVE-2010-3366 : Mn_Fit
    17. CVE-2010-3369 : mono-debugger
    18. CVE-2010-3374 : Qt Creator
    19. CVE-2010-3376 : ROOT
    20. CVE-2010-3377 : SALOME
    21. CVE-2010-3378 : Scilab
    22. CVE-2010-3380 : SLURM
    23. CVE-2010-3381 : Tangerine
    24. CVE-2010-3382 : Tuning and Analysis Utilities (TAU)
    25. CVE-2010-3383 : TeamSpeak
    26. CVE-2010-3384 : TORCS
    27. CVE-2010-3385 : TuxGuitar
    28. CVE-2010-3386 : LTTng Userspace Tracer
    29. CVE-2010-3389 : SAPDatabase, SAPInstance, OCF Resource Agents
    30. CVE-2010-3393 : Magics++
    31. CVE-2010-3394 : TeXmacs
    32. CVE-2010-3689 : OpenOffice
    33. CVE-2010-3996 : Centre for Speech Technology Research (CSTR) Festival
    34. CVE-2010-3998 : Banshee
    35. CVE-2010-3999 : GnuCash
    36. CVE-2010-4000 : GNOME Shell
    37. CVE-2010-4001 : Gromacs
    38. CVE-2010-4005 : GNOME Tomboy
    39. CVE-2010-4450 : Java Runtime Environment
    40. CVE-2011-0532 : Red Hat Directory Server
    41. CVE-2011-0902 : SunScreen Firewall