ãã£ã¨é»åã¯ç´ ç²åï¼æ§æãã¼ããä¸é¨æ§é ãæããªãæå°ã®åä½ï¼ã¨æããã¦ãã¾ãããããªãã¨ãµãã¤ã®ãã¼ãã«åããããã¨ãå®é¨ã§ç¢ºèªãããç©çå¦è ã®ç²åã®åºç¤èªèã«è¦ç´ããè¿«ããã¦ãã¾ãã§ããã å®é¨ã§ã¯é»åããµãã¤ã®å¥ã ã®ãã¼ãã«åãããããããé»åã®ç°ãªãç¹æ§ã帯ã³ã¦ãããã¨ãåããã¾ããã ã¾ã1åç®ã¯ï½¢ã¹ããã³ï¼spinonï¼ï½£ã§ãé»åãã³ã³ãã¹ã®è»¸ã¿ãããªæåã示ãåå ã¨ãªãã¹ãã³ã®å±æ§ãæã£ã¦ãã¾ãã ããã¦2åç®ã¯ï½¢ãªã¼ããã³ï¼orbitonï¼ï½£ãé»åãååæ ¸å¨è¾ºãåãç¶ããåå ã¨ãªãè»éã®ã¢ã¼ã¡ã³ãï¼è»éè§éåéï¼ã®å±æ§ãæã£ã¦ãã¾ãã å®é¨ãè¡ã£ãç 究å¡ã®ã²ã¨ããã¨ã«ã³ã»ã´ã¡ã³ãã³ã»ããªã³ã¯ï¼Jeroen van den Brinkï¼ããã¯ï½¢Natureï½£ä»é±å·æ²è¼ã®å®é¨å ±åã§ãã説æãã¦ãã¾ããã ããç¹å®ã®ãããªã¢ã«ï¼ç©è³ªï¼ã®ä¸ã§é»åã®åé¢ãçè«ä¸èµ·ããå¾ããã¨ã¯åãã
<<< JPCERT/CC WEEKLY REPORT 2012-04-25 >>> â 04/15(æ¥)ã04/21(å) ã®ã»ãã¥ãªãã£é¢é£æ å ± ç®ã次 ã1ã2012å¹´4æ Oracle Critical Patch Update ã«ã¤ã㦠ã2ãOpenSSL ã® DER ãã¼ã¿å¦çã«èå¼±æ§ ã3ãBugzilla ã«ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªã®èå¼±æ§ ã4ãTwitRocker2 (Android ç) ã«ããã WebView ã¯ã©ã¹ã«é¢ããèå¼±æ§ ãä»é±ã®ã²ã¨ãã¡ã¡ã¢ãã¹ãã¼ããã©ã³ã®ã¢ããªã«æ³¨æ â»ç´¹ä»ããã»ãã¥ãªãã£é¢é£æ å ±ã®é¸å®åºæºã¯ä»¥ä¸ã®ãã¼ã¸ãã覧ãã ããã https://www.jpcert.or.jp/wr/ â»PGPç½²åä»ãããã¹ãçããã³ XML çã¯ä»¥ä¸ã®ãã¼ã¸ãã覧ãã ããã https://www.jpcert.or.jp/wr/2012/wr
CVSS v2 ã«ããæ·±å»åº¦ åºæ¬å¤: 7.5 (å±éº) [NVDå¤] æ»æå åºå: ãããã¯ã¼ã¯ æ»ææ¡ä»¶ã®è¤éã: ä½ æ»æåã®èªè¨¼è¦å¦: ä¸è¦ æ©å¯æ§ã¸ã®å½±é¿(C): é¨åç å®å ¨æ§ã¸ã®å½±é¿(I): é¨åç å¯ç¨æ§ã¸ã®å½±é¿(A): é¨åç OpenSSL Project OpenSSL 0.9.8v æªæº OpenSSL 1.0.0i æªæºã®Â 1.0.0 OpenSSL 1.0.1a æªæºã®Â 1.0.1 VMware VMware ESX 3.5 VMware ESX 4.0 VMware ESX 4.1 VMware ESXi ã¢ããã« Apple Mac OS X 10.6.8 Apple Mac OS X v10.7 ãã v10.7.5 Apple Mac OS X v10.8 ãã v10.8.3 Apple Mac OS X Server 10.6.8 Apple Mac
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼è¤æ± ä¸æ£ï¼ã¯ãã¯ã©ã¦ãã³ã³ãã¥ã¼ãã£ã³ã°(*1)ï¼ä»¥ä¸ãã¯ã©ã¦ããï¼ãåºã社ä¼çµæ¸ã«æµ¸éãã¤ã¤ããç¾æ³ãè¸ã¾ãããã®ã»ãã¥ãªãã£é¢ã§ã®èª²é¡ãèæ ®äºé ã«é¢ãã¦æ´çãè¡ããIPAã«ãããåé¡æèã¨ããã«é¢ããåãçµã¿ãæè¡ã¬ãã¼ãããã¯ãã«ã«ã¦ã©ãããã¨ãã¦ã¨ãã¾ã¨ããå ¬éãã¾ããã ã¯ã©ã¦ããã社ä¼ã®æ§ã ãªã¨ããã§ä½¿ãããããã«ãªã£ã¦ãã¦ãã¾ããä¸è¬å©ç¨è ã¸ã®ãµã¼ãã¹æä¾ã®åºç¤ã¨ãã¦ãã¾ãä¼æ¥éã®æ¥åé£æºã®åºç¤ã¨ãã¦ã®å©ç¨ãåºã¾ãã¤ã¤ããã¾ããã¯ã©ã¦ããµã¼ãã¹(*2)ã¯ãæ±æ¥æ¬å¤§éç½ã«éãã¦ãã被ç½è ã¸ã®ææ¸ã»æ¯æ´æ´»åãè¡æ¿æ å ±ã®çºä¿¡ãªã©ã«å¤ãã®ãµã¼ãã¹ãç¡åæä¾ãããç·æ¥æã«å½¹ç«ã¤ãã¨ã確èª(*3)ããã¾ãããç·æ¥æã®æ´»åãæ¯ããããã®æ å ±ã®ä¼éã¨å¦çã®ããã«ãä»å¾ãå¿ è¦æ§ãå¢ããã®ã¨äºæ¸¬ããã¾ãã ä¸æ¹ã§ãã¯ã©ã¦ãã®ã»ãã¥ãªãã£ã«é¢ããæ¸å¿µ
é»æ°èªåè»ï¼EVï¼ã«ã³ãã¯ãããï¼ã¤ãªããï¼ãèªåé転ââãæ°æè¡ãæè¼ããã¯ã«ããç¶ã ã¨ç»å ´ãã¦ãããã大ããããè¨é²ãã¦ãããã®ã¯å°ãªããã©ãããã°æ®åæã«çªå ¥ã§ããã®ãã ãâ¦ç¶ã ã¨ã³ã«ã¼ã«ãç¡é¢å¿ã®å£ããç±³èªåè»å¸å ´ã®ç¾å® ï¼»ææä¼å¡éå®ï¼½ EVæ代ã¯ã¾ã æ¥ãªããç¾å®è§£ã¯ããã¤ã«ãHVã
é»æ°èªåè»ï¼EVï¼ã«ã³ãã¯ãããï¼ã¤ãªããï¼ãèªåé転ââãæ°æè¡ãæè¼ããã¯ã«ããç¶ã ã¨ç»å ´ãã¦ãããã大ããããè¨é²ãã¦ãããã®ã¯å°ãªããã©ãããã°æ®åæã«çªå ¥ã§ããã®ãã ãâ¦ç¶ã ã¨ã³ã«ã¼ã«ãç¡é¢å¿ã®å£ããç±³èªåè»å¸å ´ã®ç¾å® ï¼»ææä¼å¡éå®ï¼½ EVæ代ã¯ã¾ã æ¥ãªããç¾å®è§£ã¯ããã¤ã«ãHVã
AI æè¼ã®ã¯ã©ã¦ã ã¹ãã¬ã¼ã¸ã§ãã·ã¼ã ã¬ã¹ã«ãã¡ã¤ã«ãå ±æããã³ã©ãã¬ã¼ã·ã§ã³ãã³ã©ãã¬ã¼ã·ã§ã³ãå¼·åãã¾ãããã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}