2024 2023 2022 2021 2020 2019 2018 2017 2016 2015 2014 2013 2012 2011 2010 2009 2008 2007 2006 2005 2004年以å JPCERT/CCãéå»ã«è¬æ¼ãªã©ã§ä½¿ç¨ããè³æã®ä¸ã§ä¸è¬ã«å ¬éã§ãããã®ãç¨æãã¦ãã¾ãã <注æ> 以ä¸ã®åææ¸ã§ç´¹ä»ãã¦ããã½ããã¦ã§ã¢ããã¼ã¸ã§ã³ãURLçã¯ãåææ¸ã®çºè¡æç¹ã®ãã®ã§ãããå¤æ´ããã¦ããå¯è½æ§ãããã¾ãã â»ããã¸ã¿ã«ç½²åä»ãã¨è¡¨ç¤ºããã¦ãã PDF ææ¸ã¯ GlobalSign CA for Adobe ããçºè¡ããããã¸ã¿ã«è¨¼ææ¸ã«ããçæ£æ§ã証æããã¦ããã¾ãã Adobe Reader ãã¼ã¸ã§ã³ 9.0 以éãã使ç¨ããã ããã¨ã§ãPDF ææ¸ã®çæ£æ§ãæ¤è¨¼ãããã¨ãã§ãã¾ãã 2024
èå¼±æ§ãèå¥ããCVEçªå·ã®æ°ä½ç³»ã«ããæ¡çªã®ãç¥ãã ç±³å½MITRE社*1ã管çéå¶ããèå¼±æ§ã®èå¥åCVE (Common Vulnerabilities and Exposures)*2çªå·ã®ä½ç³»ãã2014å¹´ããå¹´é1ä¸ä»¶ãè¶ ããèå¼±æ§ã«ã対å¿ã§ããããæ¡å¼µããã¾ããã CVEãåç §ãã¦ããçµç¹çã«ããã¦ããåºå®é·ã®CVEçªå·ãåæã¨ããæ©æ¢°å¦çããã¦ããå ´åã«ã¯ã誤åä½ããå¯è½æ§ããããããç±³å½MITRE社ã¯ã2014å¹´1æ15æ¥ãCVEã®Webãµã¤ãä¸ã§æ°çªå·ä½ç³»ã«ããéç¨ãéå§ãã¦ããæ¨ã®Notificationãå ¬è¡¨ã7æ15æ¥ã«ã¯ãCVEçªå·ä½ç³»å¤æ´ã®Reminder Notificationãå ¬è¡¨ãã¾ãããããã¦ã2014å¹´9æ17æ¥ãCNAãã¯ããã¨ããCVEå©ç¨è ãèå¼±æ§æ å ±ãåç §ããã¨ã³ãã¦ã¼ã¶ã«è³ãã¾ã§ããã®CVEçªå·ã®æ°ä½ç³»ãåºãå¨ç¥ãã¹ããæ¹ãã¦ãã¬ã¹ãªãªã¼
åä½ JPCERT-AT-2014-0013 JPCERT/CC 2014-04-08(æ°è¦) 2014-04-11(æ´æ°) <<< JPCERT/CC Alert 2014-04-08 >>> OpenSSL ã®èå¼±æ§ã«é¢ãã注æåèµ· https://www.jpcert.or.jp/at/2014/at140013.html I. æ¦è¦ OpenSSL Project ãæä¾ãã OpenSSL ã® heartbeat æ¡å¼µã«ã¯æ å ±æ¼ããã® èå¼±æ§ãããã¾ããçµæã¨ãã¦ãé éã®ç¬¬ä¸è ã¯ãç´°å·¥ãããã±ãããéä»ã ããã¨ã§ã·ã¹ãã ã®ã¡ã¢ãªå ã®æ å ±ãé²è¦§ããç§å¯éµãªã©ã®éè¦ãªæ å ±ãåå¾ ããå¯è½æ§ãããã¾ãã 管çããã·ã¹ãã ã«ããã¦è©²å½ãããã¼ã¸ã§ã³ã® OpenSSL ã使ç¨ãã¦ããå ´å ã¯ãOpenSSL Project ãæä¾ããä¿®æ£æ¸ã¿ãã¼ã¸ã§ã³ã¸ã¢ãããã¼ãããã㨠ããå§ããã¾
JPCERT/CCã¯ãHTML5ãå©ç¨ããWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£åé¡ã«é¢ãã調æ»å ±åæ¸ã(PDF))ã以ä¸ã®URLããå ¬éãã¦ãã¾ãã http://www.jpcert.or.jp/research/html5.html ãHTML5ãå©ç¨ããWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£åé¡ã«é¢ãã調æ»å ±åæ¸ãã¯ãå§ãã§ãããã¨ããã¨ã³ããªãæ¸ãããã¨æããä¹ ãã¶ãã«JPCERT/CCã®ããããã¼ã¸ã確èªããã¨æ¹å®ããã¦ãã¾ããã å¤ãJPCERT/CCã®ããããã¼ã¸ã¯å³è©ã®ãç¥ããæ¬ã§ãHTML5(ä¸ç¥)調æ»å ±åæ¸ãããªã³ã¯ãã¦ãã¾ãããå½å æ å ±ã»ãã¥ãªãã£ã®åä¸ãç®æãã¦ããã®ãJPCERT/CCã§ãããå¤æ°ã®ãç¥ããã«æµãã¦ãHTML5(以ä¸ç¥)ããæ¶ãã¦ãã¾ãã¾ãããã¯ã£ããè¨ãã¨å½ç¶ã§ããã ããããä»ããHTML5ãå©ç¨ããWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£åé¡ã«é¢ã
JPCERT/CCã§ã¯ããªã¼ãã³ãªã¾ã«ãã¼(å¤é¨ã®ä¸ç¹å®ã®IPã¢ãã¬ã¹ããã®å帰çãªåãåããã許å¯ãã¦ããDNSãµã¼ãã¼)ã¨ãªã£ã¦ããDNSãµã¼ãã¼ãæ¥æ¬å½å ã«å¤ãåå¨ãã¦ãããã¨ã確èªãã¦ãã¾ãã ãªã¼ãã³ãªã¾ã«ãã¼ã¯å½å å¤ã«å¤æ°åå¨ãã大è¦æ¨¡ãªDDoSæ»æã®è¸ã¿å°ã¨ãã¦æªç¨ããã¦ããã¨ã®å ±åãããã¾ãã ã¾ããDNSãµã¼ãã¼ã¨ãã¦éç¨ãã¦ãããã¹ãã ãã§ã¯ãªããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ãæå³ãããªã¼ãã³ãªã¾ã«ãã¼ã«ãªã£ã¦ããäºä¾ããããã¨ã確èªãã¦ãã¾ãã æ¬ç¢ºèªãµã¤ãã§ã¯ãã使ãã®PCã«è¨å®ããã¦ããDNSãµã¼ãã¼ã¨ãæ¬ç¢ºèªãµã¤ãã¸ã®æ¥ç¶å ã¨ãªã£ã¦ããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ããªã¼ãã³ãªã¾ã«ãã¼ã¨ãªã£ã¦ããªããã確èªãããã¨ãå¯è½ã§ãã æ¬ãµã¤ãã®è©³ç´°ã«ã¤ãã¦ã¯ãã¡ãããåç §ãã ããã ãã ãã¾å¦çä¸ã§ãããã°ãããå¾ ã¡ãã ããã â»å¤å®å¦ç
HTML5 ã¯ãWHATWG ããã³ W3C ã HTML4 ã«ä»£ãã次ä¸ä»£ã® HTML ã¨ãã¦çå®ãé²ãã¦ããä»æ§ã§ãããHTML5 ããã³ãã®å¨è¾ºæè¡ã®å©ç¨ã«ãããWeb ãµã¤ãé²è¦§è (以ä¸ãã¦ã¼ã¶) ã®ãã©ã¦ã¶å ã§ã®ãã¼ã¿æ ¼ç´ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãéã§ã®åæ¹åéä¿¡ãä½ç½®æ å ±ã®åå¾ãªã©ãå¾æ¥ã® HTML4 ãããæè»ãã¤å©ä¾¿æ§ã®é«ã Web ãµã¤ãã®æ§ç¯ãå¯è½ã¨ãªã£ã¦ãã¾ããå©ä¾¿æ§ãåä¸ããä¸æ¹ã§ããããã®æ°æè¡ãæ»æè ã«æªç¨ãããéã«ã¦ã¼ã¶ãåããå½±é¿ã«é¢ãã¦ãååã«æ¤è¨¼ãå¨ç¥ãããã¦ããã¨ã¯è¨ãããã»ãã¥ãªãã£å¯¾çããããªãã¾ã¾æ®åãé²ããã¨ãå±æ§ããã¦ãã¾ãã JPCERT/CCã§ã¯ãHTML5 ãå©ç¨ããå®å ¨ãª Web ã¢ããªã±ã¼ã·ã§ã³éçºã®ããã®æè¡æ¸ãã¬ã¤ãã©ã¤ã³ã®ãã¼ã¹ã¨ãªãä½ç³»çãªè³æã®æä¾ãç®çã¨ãã¦ãæ¸å¿µãããã»ãã¥ãªãã£åé¡ãæ½åºããä¸ã§æ¤è¨ãå ãããããã®åé¡
第2åãã«ã¦ã§ã¢è§£æåå¼·ä¼ ã¾ã¨ãã¾ããã 1.ãRecon 2011 å ±åã JPCERT/CC é 山央ãã 2.ããã«ã¦ã§ã¢è§£æã許ãããã®ã¯20ä¸ç´ã¾ã§ã ããï¼ã 丹ç°è³¢ãã 3.ãå»å¹´è¦ãæ¯è² â Black Hat 2010 & DEF CON 18 ã JPCERT/CC ä¸æ´¥çåãã ç¶ããèªã
JPCERT/CC ã2003å¹´ããéç¨ãã¦ã¾ããã¾ãããå®ç¹è¦³æ¸¬ã·ã¹ãã ãISDAS(Internet Scan Data Acquisition System) ãã¯ãéç¨ãçµäºãããã¾ããããå©ç¨èª ã«ãããã¨ããããã¾ããã ISDASã¯ãæ°ã¤ã³ã¿ã¼ãããå®ç¹è¦³æ¸¬ã·ã¹ãã ãTSUBAMEãã«ç§»è¡ãã¾ããã ãTSUBAMEããã¼ã¸ã¯ãã¡ã Topã¸
åä½ JPCERT-AT-2011-0023 JPCERT/CC 2011-08-31(åç) 2011-09-15(æ´æ°) <<< JPCERT/CC Alert 2011-08-31 >> Apache HTTP Server ã®ãµã¼ãã¹éç¨å¦¨å®³ã®èå¼±æ§ã«é¢ãã注æåèµ· Apache HTTP Server DoS Vulnerability https://www.jpcert.or.jp/at/2011/at110023.txt I. æ¦è¦ Apache HTTP Server ã«ã¯ããµã¼ãã¹éç¨å¦¨å®³ (DoS) ã®èå¼±æ§ãããã¾ãã é éã®ç¬¬ä¸è ãç´°å·¥ãã HTTP ãªã¯ã¨ã¹ãã Apache HTTP Server ã«éãã㨠ã§ã·ã¹ãã ãªã½ã¼ã¹ã大éã«ä½¿ç¨ãããçµæã¨ãã¦ãµã¼ãã¹ä¸è½ç¶æ ã«é¥ãå¯ è½æ§ãããã¾ãã Range header DoS vulnerability
ãJava ã»ãã¥ã¢ã³ã¼ãã£ã³ã° 並è¡å¦çç·¨ã ãJava ã»ãã¥ã¢ã³ã¼ãã£ã³ã° 並è¡å¦çç·¨ãï¼åè CERT/CCãJava Concurrency Guidelinesãï¼ã¯ãã«ã¼ãã®ã¼ã¡ãã³å¤§å¦ã½ããã¦ã¨ã¢å·¥å¦ç 究æã® CERTããã°ã©ã 㨠Oracle ã®å ±åä½æ¥ã®ææã§ãããCERT Oracle Secure Coding Standard for Javaãã®ä¸ããã次ã®ã«ãã´ãªã«å«ã¾ãã並è¡å¦çããã°ã©ãã³ã°ã«é¢é£ããã¬ã¤ãã©ã¤ã³ãã¾ã¨ããè³æã§ãã å¯è¦æ§ã¨ã¢ãããã¯æ§(VNA) ããã¯(LCK) ã¹ã¬ããAPI(THI) ã¹ã¬ãããã¼ã«(TPS) ã¹ã¬ããã®å®å ¨æ§ã«é¢ããéå(TSM) ã»ãã¥ã¢ãª Java ãã«ãã¹ã¬ããããã°ã©ãã³ã°ã«åãçµãéã®æå¼ãã¨ãã¦ãæ´»ç¨ãã ããã æ¬è³æã«è¨è¿°ãããã¬ã¤ãã©ã¤ã³ãå«ããCERT Oracle Secure Coding S
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼è¤æ± ä¸æ£ï¼ã¯ãã½ããã¦ã§ã¢è£½åã«ãããèå¼±ï¼ãããããï¼æ§ã®æ¸å°ãç®æããèå¼±æ§æ¤åºã®æ®åæ´»åããã2011å¹´8æããéå§ãã¾ãã è¿å¹´ã½ããã¦ã§ã¢è£½åã«ããã¦éçºè ãèªç¥ãã¦ããªãèå¼±æ§ï¼æªç¥ã®èå¼±æ§ï¼ãæªç¨ããæ»æãäºä»¶ãå¾ã絶ã¡ã¾ããããããã®æ»æãäºä»¶ã§ã¯ãä¸çä¸ã§åºã使ç¨ããã¦ããã½ããã¦ã§ã¢è£½åã ãã§ãªãã主ã«æ¥æ¬å½å ã®ã¿ã§åºã使ç¨ããã¦ããã½ããã¦ã§ã¢ï¼*1ï¼ããç£æ¥ç¨å¶å¾¡ã·ã¹ãã ï¼*2ï¼ãªã©ãæ¨çã¨ããã¦ãã¾ãã IPAã¨JPCERT/CCï¼*3ï¼ã¯2004å¹´7æãããçµæ¸ç£æ¥çã®å示ã®ä¸ã§ãæ å ±ã»ãã¥ãªãã£æ©æè¦æãã¼ããã¼ã·ããï¼*4ï¼ããéå¶ãã¦ãããã½ããã¦ã§ã¢è£½åã®èå¼±æ§é¢é£æ å ±ã®åä»ã¨ã製åéçºè ã«å¯¾ãããã®ä¿®æ£ã®ä¾é ¼ãå®æ½ãã¦ãã¾ãããã®ãã¼ããã¼ã·ããéå¶éå§ãã7å¹´ãçµéãã2011å¹´6ææ«æç¹ã§ãç´¯è¨1,2
IPAï¼æ å ±å¦çæ¨é²æ©æ§ï¼ã®ã»ãã¥ãªãã£ã»ã³ã¿ã¼ã¨JPCERT/CCï¼JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼ã¯2011å¹´7æ29æ¥ãAndroid OSã®ä¸é¨ã«SSLï¼Secure Sockets Layerï¼è¨¼ææ¸ã®è¡¨ç¤ºã«é¢ããå±éºåº¦ãé«ãèå¼±æ§ãè¦ã¤ãã£ããã¨ãå ¬è¡¨ãããSSL証ææ¸ã¯ãWebã¢ã¯ã»ã¹æã«æ¥ç¶å ãµã¼ãã¼ã®èº«å ï¼æ£è¦ã®ãã¡ã¤ã³åã§ãããã©ãããªã©ï¼ã確ãããããã«ä½¿ãæ å ±ã§ããã 対象ã¨ãªãã®ã¯ãAndroid OSã®2.2ããåã®ãã¼ã¸ã§ã³ï¼å ¨ç«¯æ«ãé¢ä¿ãããã©ããã¯ç¾æç¹ã§ã¯å®ãã§ã¯ãªãï¼ã該å½ããAndroid端æ«ã®Webãã©ã¦ã¶ã¼ã§ãå¤é¨ãµã¤ãã®ã³ã³ãã³ããèªã¿è¾¼ãã¿ã¤ãã®Webãµã¤ããã«ã¢ã¯ã»ã¹ãã身å ã確èªããããã«SSL証ææ¸ã表示ãããã¨ãæ¬æ¥ã®æ¥ç¶å Webãµã¤ãï¼ãã¡ã¤ã³åï¼ã«å¯¾ãã証ææ¸ã§ã¯ãªããå¤é¨ãµã¤ãã®è¨¼ææ¸ã表示ãã¦ãã¾ããèå¼±æ§ãçºè¦ããI
2011/06/30 ãæ¨çåã¡ã¼ã«ãè¦ç ´ãã«ã¯ãã¡ã¼ã«ãå¦çãã人ã®ãç¼åããå¿ è¦ã ãââã©ã㯠ãµã¤ãã¼ãªã¹ã¯ç·åç 究æ éçºã»ã³ã¿ã¼ CBCããã¸ã§ã¯ãæ å½é¨é·ã®å·å´åºå¤«æ°ã¯ã6æ14æ¥ã«çºè¡¨ããæ°ãµã¼ãã¹ãITã»ãã¥ãªãã£äºé²æ¥ç¨®ãã®ç®çã«ã¤ãã¦ããã®ããã«èªã£ãã ITã»ãã¥ãªãã£äºé²æ¥ç¨®ã¨ã¯ãæ¨çåã¡ã¼ã«æ»æã«å¯¾ããé²ç½è¨ç·´ã®ãããªãµã¼ãã¹ã ã2åã«ããã£ã¦æ¬ä¼¼çãªæ»æã¡ã¼ã«ã社å ã«é ä¿¡ãããã®è å¨ã身ããã£ã¦ä½é¨ãããã¨ã«ãããæ¨çåã¡ã¼ã«æ»æã«å¯¾ãããå ç«ããä»ãããã¨ãçã£ã¦ãããæéã¯ã100åã¾ã§ã®å ´åã¯100ä¸åã500åã¾ã§ã§250ä¸åã ã åãµã¼ãã¹ã§ã¯ã顧客ã«åããã¦ã«ã¹ã¿ãã¤ãºããæé¢ãæ·»ä»ãã¡ã¤ã«ã®å½è£ ã¡ã¼ã«ãå é¨ã«é ä¿¡ããéå°çã調æ»ãããããã¦è¨ç·´ã®ç¨®æãããè¡ã£ãå¾ãæ°ã«æã®éãç½®ãã¦2åç®ã®å½è£ ã¡ã¼ã«æ»æãå®æ½ããããã¡ãããã ã¾ãè¨ã¡ãã«ãªããªã
æ å ±ã»ãã¥ãªãã£æ©æè¦æãã¼ããã¼ã·ããã¬ã¤ãã©ã¤ã³ã¨ã¯ ãæ å ±ã»ãã¥ãªãã£æ©æè¦æãã¼ããã¼ã·ãããã¯ããã½ããã¦ã¨ã¢è£½åçã®èå¼±æ§é¢é£æ å ±ã«é¢ããåæ±è¦ç¨ãï¼å¹³æ29å¹´çµæ¸ç£æ¥çå示第19å·ãæçµæ¹æ£ä»¤å6å¹´çµæ¸ç£æ¥çå示第93å·ï¼ã®å示ãè¸ã¾ããå½å ã«ãããã½ããã¦ã§ã¢çã®èå¼±æ§é¢é£æ å ±ãé©åã«æµéãããããã«ä½ããã¦ããæ çµã¿ã§ãã IPAãä¸è¬ç¤¾å£æ³äººJPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼ç¥ç§°ï¼JPCERT/CCï¼ãä¸è¬ç¤¾å£æ³äºº é»åæ å ±æè¡ç£æ¥åä¼(ç¥ç§°ï¼JEITA)ãä¸è¬ç¤¾å£æ³äºº ã½ããã¦ã§ã¢åä¼(ç¥ç§°ï¼SAJ)ãä¸è¬ç¤¾å£æ³äºº æ å ±ãµã¼ãã¹ç£æ¥åä¼(ç¥ç§°ï¼JISA)åã³ç¹å®éå¶å©æ´»åæ³äºº æ¥æ¬ãããã¯ã¼ã¯ã»ãã¥ãªãã£åä¼(ç¥ç§°ï¼JNSA)ã¯ãèå¼±æ§é¢é£æ å ±ã®é©åãªæµéã«ãããã³ã³ãã¥ã¼ã¿ã¦ã¤ã«ã¹ãä¸æ£ã¢ã¯ã»ã¹ãªã©ã«ãã被害çºçãæå¶ããããã«ãé¢ä¿è åã³é¢ä¿æ¥çã¨å調ãã¦å½
ã¯ããã« ã¤ã³ã¿ã¼ããããä¸è¬ã«æ®åããç¾å¨ãé»åã¡ã¼ã«ã¯ã¤ã³ã¿ã¼ãããå©ç¨è ã®å¤§åã使ãã³ãã¥ãã±ã¼ã·ã§ã³ãã¼ã«ã¨ãªãã¾ããã ããã«ä¼´ãè¿·æã¡ã¼ã«ãå¢å ããæ´ã«ã¦ã¤ã«ã¹ãé å¸ãããããªæ»æã«ããã°ãã°å©ç¨ãããããã«ãªã£ã¦ãã¾ããã å ãã¦è¿å¹´ã§ã¯ãä»ã¾ã§ã®è¿·æã¡ã¼ã«ã®ãããªç¡å·®å¥ãªé å¸ã§ã¯ãªããç¹å®å°æ°ãæ¨çã¨ããæ¨çåã¡ã¼ã«æ»æã¨å¼ã°ããæ»æãæ£è¦ãããããã«ãªã£ã¦ãã¦ãã¾ãã æ¨çåã¡ã¼ã«æ»æã«ããã¦æ»æè ã¯ãä¼æ¥æ å ±ãå人㮠Web ãã¼ã¸ã ããã°ãã¡ã¼ãªã³ã°ãªã¹ãçããç¹å®ã®å人æ å ±çãå ¥æããç¥ãå¾ ãæ å ±ããã¨ã«æ¨çã¨ãããç¹å®ã®çµç¹åãã«ã¡ã¼ã«æé¢ãªã©ãã«ã¹ã¿ãã¤ãºãããã®ä¼ç¤¾ã®å¹¹é¨ç¤¾å¡ãªã©ããã®ç¤¾å ææ¸ããçµç¹ãé¢é£ãã¦ããåéã®è³æãè£ ã£ãã¡ã¼ã«ãä½æãã¾ãã æ»æè ã¯ãæ¨çã¨ãªã£ãã¦ã¼ã¶ãã¤ãéãã¦ãã¾ããããªé»åã¡ã¼ã«ãéä»ãããã¨ã«ãã£ã¦ãã¦ã¼ã¶ã«ã¡ã¼ã«ã«æ·»
ãã¡ãã¯ãæè¦ã»ãææ³ç¨ã®ãã©ã¼ã ã§ããå社製åã«ã¤ãã¦ã¯ãå社ã¸ãåãåãããã ããã â»æ¬ãã©ã¼ã ã«ããã ããã³ã¡ã³ãã¸ã®è¿ä¿¡ã¯ã§ãã¾ããã è¿ä¿¡ããå¸æã®æ¹ã¯ããååãã ããå©ç¨ãã ããã
ãç¥ãã
é害
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}