ç§ã¯ããã«ãã¦æ§ã ãªãã©ã¦ã¶ã®èå¼±æ§ãçºè¦ããã
JVN#89344424: è¤æ°ã®ã¡ã¼ã«ã¯ã©ã¤ã¢ã³ãã½ããã«ããããæ·»ä»ãã¡ã¤ã«ã«ããã¡ã¼ã«ã¯ã©ã¤ã¢ã³ãã½ããã使ç¨ä¸è½ã«ãªãèå¼±æ§
ããã¯ãæ·»ä»ãã¡ã¤ã«åã«Unicodeã®åè¨å·ãå«ãã¦ããã¨ãã¡ã¼ã©å´ã§Shift_JISã«å¤æããéã«ããã¯ã¹ã©ãã·ã¥ã«å¤æããã¦ãã¾ã£ã¦æ³å®å¤ã®ãã£ã¬ã¯ããªã«æ·»ä»ãã¡ã¤ã«ãå±éããã¦ãã¾ã£ããããããã¯ã©onãã®ãããªååã®ãã¡ã¤ã«ãæ·»ä»ãã¦ãããã¨ã§Shift_JISã«å¤æãã¦CONã¨ãããã¡ã¤ã«ãéããã¨ãã¦ã¡ã¼ã©ãåºã¾ã£ã¦ãã¾ãã¨ããåé¡ã§ããããã¯ãç§èªèº«ãæåã³ã¼ãã®åé¡ã«ã¤ãã¦èª¿ã¹å§ããåæ段éã§ãUnicodeããã®å¤æã§åé¡ãèµ·ããããªã±ã¼ã¹ã¨ãã¦ã§ããã ãããããããã¢ãã«ã±ã¼ã¹ãèããã«ããããæå ã®ã¡ã¼ã©ã§è©¦ãããã¾ãã«æ³å®éãã®èå¼±æ§ããã£ãããIPAã«å±ãããã®ã§ãããã ãç§ãå±ãããã®ã¡ã¼ã©ã«ã¤ãã¦ã¯éçºè ã¨é£çµ¡ãã¤ããªãã¨ãããã¨ã§ä¿®æ£ã«ã¯è³ãããIPAãä»ã®ãã³ãã®ã¡ã¼ã©ã§ã®æåãåãã¾ã¨ããããã§JVNã¨ãã¦å ¬è¡¨ãããã¨ããçµç·¯ã®ãã®ã§ãã
MFSA 2008-13: æåã¨ã³ã³ã¼ãã£ã³ã°ã«èµ·å ããè¤æ°ã® XSS èå¼±æ§
Firefoxã«ããã¦Shift_JISã®ã¨ãã«0x80ã¨ãããã¤ãå¤ãç¡è¦ãããããã"<(0x80)sc(0x80)ript>"ã¨ãã£ãæååããã©ãã¯ãªã¹ãã§å¦çãã¦ããå ´åã«æ¼ããçããã¨ããåé¡ã§ããããã¯ããã¾ãã¾ãªã¨ã³ã³ã¼ãã£ã³ã°ã§HTMLã®ãã¼ã¹ã«ããããªã¨ããããªããããã¡ã¸ã³ã°ã®ãããªå½¢å¼ã§ååèªåãååæåã§ãã¹ããã¦ãã¦è¦ã¤ããåé¡ã§ããæè¿ã ã¨ãããã«ãã¼ãµããããªãã°ã¯æ¯ãã¦ãã¾ãè¦å½ãããªã(ã¨æããã)ã§ãããããã¾ã§è©¦ãæ°åãããªãã§ããâ¦ã
MFSA 2010-42: Web ã¯ã¼ã«ã¼ã® importScripts ãéããã¯ãã¹ãµã¤ããã¼ã¿æ¼ãã
1å¹´ã»ã©åã«è¦ã¤ããWeb Workersã®åé¡ã¯ã次ã®ãããªè¦³ç¹ã§è¦ã¤ãã¾ãã(ãã®èå¼±æ§ã®è©³ç´°ã«ã¤ãã¦ã¯ãNetAgent Official Blog : Firefoxã®Web Workersã«ãããèå¼±æ§ã«ã¤ãã¦ãåç §)ã
- ãã¨ãã¨ãFirefoxã¯E4Xã¨ããæ©è½ãå©ç¨ãããã¨ã§ãHTMLæçãJavaScriptã¨ãã¦<script>ã®ã½ã¼ã¹ã¨ãã¦èªã¿è¾¼ããã¨ãå¯è½ã§ãã£ã
- Firefoxã§ã¯ããã«å¯¾ããä¿®æ£ã¨ãã¦ã<script>ã½ã¼ã¹ã¨ãã¦èªã¿è¾¼ãã JavaScriptãåä¸ã®XMLãªãã¸ã§ã¯ãã§ãã£ãå ´åã«ã¯ã»ãã¥ãªãã£ä¾å¤ãçºçããã¦ãã
- ã¨ãã以ä¸ã®ãã¨ãåæç¥èã¨ãã¦ç¥ã£ã¦ããä¸ã§ãWeb Workers ã«ã¯ importScripts ã¨ãããªã¢ã¼ãã®JavaScriptãèªã¿è¾¼ãæ©è½ã追å ããããã¨ãç¥ã£ã
- ãããããã¨importScriptsã§ã¯<script>ã§ãªããã¦ããE4Xã®ãã§ãã¯ãããã¦ããªãã®ã§ã¯ãªããã¨ããæ¨æ¸¬ãç«ã¦ã
- å®éã«è©¦ãã¦ã¿ãã¨ãããæ¨æ¸¬éããªã¢ã¼ãã®HTMLãJavaScriptã¨ãã¦èªã¿è¾¼ããã¨ãã§ãããããèå¼±æ§ã¨å¤æ
ãã®ããã«ãæ°ãã追å ãããæ©è½ã«å¯¾ãã¦éå»ã®ç¥è¦ãé©ç¨ãããã¨ã§èå¼±æ§ãè¦ã¤ãããã¨ãã§ããã®ã§ããã
ãã¤ã¯ãã½ãã ã»ãã¥ãªãã£æ å ± MS07-034 - ç·æ¥ : Outlook Express ããã³ Windows ã¡ã¼ã« ç¨ã®ç´¯ç©çãªã»ãã¥ãªãã£æ´æ°ããã°ã©ã (929123)
MS07-034ã«ã¯è¤æ°ã®èå¼±æ§ã®ä¿®æ£ãå«ã¾ãã¦ãããã¿ã¤ãã«ã¯ãOutlook Express ããã³ Windows ã¡ã¼ã«ãã¨ãªã£ã¦ãã¾ããããã®ãã¡ã®ããã¤ãã¯OEã³ã³ãã¼ãã³ãçãéãã¦Internet Explorerã«å®³ãåã¼ããã®ã§ãããå«ã¾ããä¿®æ£ã®ãã¡ãCVE-2007-2225ã¯IEã«ããã¦mhtmlãããã³ã«ãã³ãã©ãéããã¨ã§base64ã¨ã³ã³ã¼ããããç¶æ
ã§æ¿å
¥ãããJavaScriptãå®è¡å¯è½ãªããã«åºãç¯å²ã§XSSãçºçããã¨ãããã®ã§ãããããèªä½ã¯èå¼±æ§ã®åå¨èªä½ãåºãå
¬éããã¦ãããã®ã®ããã¤ã¾ã§ãä¿®æ£ãããªããã¨ã«æ¥ãç
®ããã hoshikuzu ããã®ååã«ããMicrosoftã«å ±åãããã®ã§ããã¨ããããMicrosoft ããå½åè¿ã£ã¦ããè¿äºã¯ãInternet Explorerã®ä»æ§ã«åºã¥ãåä½ã§ãããã¨ããé©ãã®è¿äºã ã£ãã®ã§ãããmhtml ãã³ãã©ãå©ç¨ããã°ãã¾ãã«ãåºãç¯å²ã§XSSãçºçããããã¨ãã§ããããããããã«ä»æ§ã¯ãªãããã¨ãããã¨ã§ãmhtml ãã³ãã©ãå©ç¨ã㦠microsoft.com ã live.com ãªã©ã§ã®XSSãå¤æ°å ±åãããã¨ã§æ¹å転æããããã¨ã«ãã¾ããã
ã¾ããä»®ã«ãmhtmlã«ããXSSã¯ä»æ§ã§ãããã¨ããç¶æ³ãè¦ããªãã¨ãã¦ããå°ãã§ãmhtmlã®æåãæ¹åãããããã«ã¨mhtmlã®å¼ãèµ·ããåé¡ãå¾¹åºãã¦èª¿ã¹ããã¨æãããã®ãããªä¸ã§è¦ã¤ããã®ãMS07-034ã«å«ã¾ããCVE-2007-2227ã§ãããããã¯ãmhtml ãããã³ã«ãã³ãã©ãçµç±ãã¦IEã§ã³ã³ãã³ããéãã¨ãWebã¢ããªã±ã¼ã·ã§ã³å´ã§ãã¦ã³ãã¼ãããããã¨ãæå³ãã¦ä»ä¸ããã "Content-Disposition: attachment" ã¬ã¹ãã³ã¹ããããç¡è¦ãããIEå
ã§ãããªããã®ã³ã³ãã³ããéãããã¨ãããã®ã§ããã
ãã®ããã«ãCVE-2007-2227ã«ã¤ãã¦ã¯ãèå¼±æ§ã¨èªããããªãä»æ§ã§ãã£ã¦ããæªç¨ãããã¨ãã®å½±é¿ã大ããã®ã§ããã°ä»æ§ã®æ¹åãè¿«ããã¨ãã§ãããã¨ããå·å¿µããçºè¦ã«è³ã£ããã®ã§ãã
ãã¤ã¯ãã½ãã ã»ãã¥ãªãã£æ å ± MS08-056 - è¦å : Microsoft Office ã®èå¼±æ§ã«ãããæ å ±ã®æ¼ãããèµ·ãã (957699)
MS08-056ãã¿ã¤ãã«ã¯ Microsoft Office ã¨ãªã£ã¦ãã¾ãããOfficeã³ã³ãã¼ãã³ããå©ç¨ãããã¨ã§IEã«å®³ãåã¼ããã®ã§ãããMS08-056ã§ä¿®æ£ãããCVE-2008-4020ããåè¿°ã®mhtmlã®åé¡ã«é¢é£ãã¦ãã¾ããmhtmlã«ããContent-Dispositionç¡è¦(CVE-2007-2227)ãè¦ã¤ããã¨ãã«ãmhtml以å¤ã®ãããã³ã«ãã³ãã©ã§ãåæ§ã®åé¡ãããã®ã§ã¯ãªããã¨æ¨æ¸¬ããã¬ã¸ã¹ããªã®HKCR\PROTOCOLS\Handlerã«ç»é²ããã¦ããæ§ã ãªãããã³ã«ãã³ãã©ã«å¯¾ãã¦ãContent-Dispositionãä»ä¸ãããã³ã³ãã³ããIEã§éããã¨ãã«åé¡ãçºçããªãã試ããªããçºè¦ãããã®ã§ãã
çµå±ã®ã¨ããããã§ã«åå¨ããæ§ã ãªèå¼±æ§ã«ã¤ãã¦åçãæ»æææ³ãããããéãã¦ãããå¥ã®ã½ããã¦ã§ã¢ã«å¯¾ãã¦ããããçµã¿åããããã¨ã§ä½ãåé¡ãçºçããããã¨ãã§ããªãããã¾ãä»æ§ã§ããã«ãã¦ãæ大éæªç¨ãããã¨ã§åé¡ãçºçããããã¨ãã§ããªããã¨ãã£ãæèããèå¼±æ§ãçºè¦ãã¦ããæ°ããã¾ãã