å ¨ã¦ã®NSD 3ã®ãã¼ã¸ã§ã³ã¨éçºãã©ã³ãã®NSD 4ã«ãªã¢ã¼ãããã®æ»æå¯è½ãªãµã¼ãã¹ä¸è½ã®èå¼±æ§ãè¦ã¤ããã¾ããã ãªã¢ã¼ãããã®ä¸æ£ãªãã±ãããåãåããã¨ã§NSDã®åããã»ã¹ãã¯ã©ãã·ã¥ãã¾ãã親ããã»ã¹ã®NSDã¯åããã»ã¹ã®NSDãèªåçã«åèµ·åããã¾ãããæ»æè ãé£ç¶ãã¦æ»æãããã¨ã§å®è³ªçã«ãµã¼ãã¹ä¸è½ã«ãªãã¾ãã 詳ããã¯CVE-2012-2978ãã覧ãã ããã 対ç 対çæ¹æ³ã¯ä»¥ä¸ã®ã©ã¡ããã§ããè¨å®ã§ã¯åé¿ã¯ã§ãã¾ããã ä¿®æ£æ¸ã¿ã®NSD 3.2.12ã«ã¢ãããã¼ãããã㨠ãããpatch.diffãé©å¿ãã¦ãã«ããç´ãã¦ã¤ã³ã¹ãã¼ã«ãããã¨
ä»åã¯ãã£ãã·ã¥ãã¼ã ãµã¼ãã®UnboundãDNSã©ã¦ã³ãããã³ã«å¯¾å¿ããã®ã§ãUnboundã¨DNSã©ã¦ã³ãããã³ã«ã¤ãã¦ç´¹ä»ãã¾ãã å§å¦¹ç·¨ãNSDã¨DNSã©ã¦ã³ãããã³ããã覧ãã ããã Unboundã¨ã¯ DNSãµã¼ãã®ã½ããã¦ã§ã¢ã¨ãã¦ã¯BINDãããã¡ã¯ãã¹ã¿ã³ãã¼ãã®ãããªä½ç½®ã¥ãã«ãªã£ã¦ãã¾ãããBIND以å¤ã«ãæ§ã ãªDNSãµã¼ãã®ã½ããã¦ã§ã¢ãããã¾ãããã®ä¸ã®ä¸ã¤ã¨ãã¦Unboundãããã¾ãã Unboundã¯ãªã©ã³ãã®NLnet Labsã®W.C.A. Wijngaardsæ°ãä¸å¿ã¨ãªã£ã¦éçºãè¡ããã¦ãã¾ãã2008å¹´5æ20æ¥ã®æ£å¼ãªãªã¼ã¹ãã4å¹´è¿ãçµã¡ãä»ã§ã¯ä»£è¡¨çãªãã£ãã·ã¥ãã¼ã ãµã¼ãã®ã½ããã¦ã§ã¢ã®ä¸ã¤ã¨ãªã£ã¦ãã¾ã Unboundã«ã¤ãã¦ã®è©³ç´°ã¯ä»¥ä¸ã®ãµã¤ããã覧ãã ããã Unbound | æ¥æ¬Unboundã¦ã¼ã¶ã¼ä¼ Unboundã®ç´¹ä» D
1æ29æ¥ã¾ã§ã«æããã«ãªã£ãèå¼±æ§æ å ±ã®ãã¡ãæ°ã«ãªããã®ãç´¹ä»ãã¾ããããããããã³ãã¼ãæä¾ããæ å ±ãªã©ãåèã«å¯¾å¦ãã¦ãã ããã Struts 2.3.1.2ãªãªã¼ã¹ï¼2012/01/22ï¼ Webã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯Strutsã®ãã¼ã¸ã§ã³2.3.1.2ããªãªã¼ã¹ããã¾ããããã®ãã¼ã¸ã§ã³ã§ã¯ãParametersInterceptorã«çµã¿è¾¼ã¾ãã¦ããé²è·æ©è½ãè¿åãã¦ãOGNLï¼Object Graph Navigation Languageï¼ã使ã£ãä»»æã®ã³ã¼ãå®è¡ã許ãã¦ãã¾ãèå¼±æ§ï¼CVE-2011-3923ï¼ã解決ãã¦ãã¾ããStruts 2.0.0ï½2.3.1.1ã«å½±é¿ãããã¾ãã Apache Strutsï¼ParameterInterceptor vulnerability allows remote command execution Apache
--------------------------------------------------------------------- â ï¼ç·æ¥ï¼Unbound 1.xã®èå¼±æ§ãå©ç¨ãããµã¼ãã¹ä¸è½ï¼DoSï¼æ»æã«ã¤ã㦠- ãã¼ã¸ã§ã³ã¢ããï¼ç·æ¥ãããã®é©ç¨ãå¼·ãæ¨å¥¨ - æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ 2011/12/20ï¼Tueï¼ --------------------------------------------------------------------- â¼æ¦è¦ ãã£ãã·ã¥DNSãµã¼ãã¼ã®Unboundã«ã¯å®è£ ä¸ã®ä¸å ·åããããéæ¨æºã®å¿ç ã®å¦çä¸ã«åä½ä¸ã®Unboundãã¯ã©ãã·ã¥ããèå¼±æ§ãäºã¤åå¨ãããã¨ãã éçºå ã®NLnet Labsããçºè¡¨ããã¾ããããããã®èå¼±æ§ãå©ç¨ãããã¨ã« ãããå¤é¨ããã®ãµã¼ãã¹ä¸è½ï¼DoSï¼æ»æãå¯è½ã¨ãªãã¾ã
3. 3 2011-06-18 æ¥æ¬Unboundã¦ã¼ã¶ä¼ #dnstudy 01 çºè¡¨è³æ æ¥æ¬Unboundã¦ã¼ã¶ä¼ ⢠ä½ã¨ãªãããªã§ä½ã£ã ⢠ãªããå ¬å¼ï¼NLnet Labsï¼å ¬èª ⢠ã¦ã¼ã¶ä¼ã¨åä¹ã£ã¦ããå²ã«ã¯ã³ãã¥ãããã¼ ã¨ãã¦ä½ããªãã¦ããªã ⢠ã¨ãã©ãååãã¦ãã ããæ¹ãããã®ã§å©ã㣠ã¦ãã ⢠Googleã°ã«ã¼ãã«è°è«ãé£çµ¡ã®å ´æãä½ã£ãã â« http://groups.google.com/group/unbound-jp 4. 4 2011-06-18 æ¥æ¬Unboundã¦ã¼ã¶ä¼ #dnstudy 01 çºè¡¨è³æ ã¦ã¼ã¶ä¼ã®ä¸»ãªæ´»å ⢠ã¦ã§ããµããã®å ¬é â« http://unbound.jp/ ⢠ããã¥ãã«çã®ç¿»è¨³ ⢠Unboundã ãã§ãªããldnsã¨NSDã«ã¤ãã¦ãã ãã¥ãã«ã翻訳ãã¦å ¬éãã¦ãã ⢠æè¡æ¤è¨¼ã¯ã»ã¨ãã©ã§ãã¦ããªã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}