Trend Micro Virtual Patch for Endpoint 2.0 Service Pack 2 Patch 7 ãä¸è¨æ¥ç¨ã«ã¦å ¬éãããã¾ãã
â å ¬ééå§æ¥
2019å¹´08æ27æ¥(ç«)
â å ¥ææ¹æ³
æ¬è£½åã¯ãææ°çãã¦ã³ãã¼ããã¼ã¸ãã®
Trend Micro Virtual Patch for Endpoint (æ§ï¼èå¼±æ§å¯¾çãªãã·ã§ã³) ãããã¦ã³ãã¼ãã§ãã¾ããâ 主ãªè¿½å æ©è½/ä¿®æ£å 容
1. Vulnerability Protection Agentããã³Vulnerability Protection Relayã§ä½¿ç¨ããã
ã OpenSSLã®ãã¼ã¸ã§ã³ãopenssl-1.0.2oã«ã¢ãããã¼ãããã¾ãã2. ç¡å¹ãªIPv6ããããåå ã§Vulnerability Protection Agentã®ãããã¯ã¼ã¯
ã ãã©ã¤ã (tbimdsa) ãã¯ã©ãã·ã¥ããåé¡ãä¿®æ£ããã¾ãããâ»Readmeãªã©ã®ããã¥ã¡ã³ãã«ã¯Vulnerability Protectionã¨è¨è¼ããã¦ãã¾ããã
Vulnerability Protection 㯠Trend Micro Virtual Patch for Endpointãæå³ãã¾ãã詳細ã«ã¤ãã¦ã¯ææ°çãã¦ã³ãã¼ããã¼ã¸ããä»å±ã®Readmeãã確èªãã ããã
サポート情報 : トレンドマイクロ
Manager
2. ä¿®æ£ãããå 容 ================= 注æ: æ¬Patchãã¤ã³ã¹ãã¼ã«å¾ã«ãæ¬ã»ã¯ã·ã§ã³ã«ãæé ããå«ã¾ããå ´åã«ã¯ãæ é ããå®è¡ãã¦ãã ããã 2.1 æ°æ©è½ ========== æ¬Patchã§ã¯ã次ã®æ°æ©è½ãæä¾ããã¾ãã æ¬Patchã§æä¾ãããå 容ã«ã¤ãã¦ã次ã®å½¢å¼ã§è¨è¼ãã¾ãã ------------------------------------------------ æ©è½: [社å 管çç¨çªå·] æ©è½ã®å 容 æé : æé ã®å 容 ------------------------------------------------ æ©è½1: [DSSEG-2785] Vulnerability Protection Managerã§ä½¿ç¨ããã¦ããApache Tomcatãã¢ãã ã°ã¬ã¼ãããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ æ©è½2: [DSSEG-3202/VP-667] Oracle JRE 8u181ãAzul Zulu OpenJDK 8u192ã«ç½®ãæãããã¾ãã 2.2 æ¬Patchã§ä¿®æ£ãããæ¢ç¥ã®åé¡ ================================= æ¬Patchã§ã¯ã次ã®åé¡ãä¿®æ£ããã¾ãã æ¬Patchã§ä¿®æ£ãããå 容ã«ã¤ãã¦ã次ã®å½¢å¼ã§è¨è¼ãã¾ãã ------------------------------------------------ åé¡: [社å 管çç¨çªå·] åé¡ã®å 容 ä¿®æ£: ä¿®æ£ã®å 容 ------------------------------------------------ åé¡1: [DSSEG-2814] JDK 8u181以éãJVMã§ã¯LDAPSæ¥ç¶ã«ã¨ã³ããã¤ã³ãèå¥ãåæè¨å®ã§é©ç¨ããã¾ ãããã®JVMã¯ãActive Directoryã³ãã¯ã¿ã®ãµã¼ãã¢ãã¬ã¹ãããµã¼ã証ææ¸ã® ä¸è¬å (åå¨ããå ´åã¯subjectAltName) ã«å¯¾ãã¦æ¤è¨¼ãã¾ãããã®çµæãæ¢åã® Active Directoryã³ãã¯ã¿ã証ææ¸ã®ä¸è¬å (ã¾ãã¯subjectAltName) ã«ä¸è´ã㪠ããµã¼ãã¢ãã¬ã¹ã使ç¨ãã¦ããå ´åãã³ãã¯ã¿ã§åæã§ããªãåé¡ãããã¾ã ãã ä¿®æ£1: æ¬Patchã®é©ç¨å¾ã¯ãæ°è¦ã¤ã³ã¹ãã¼ã«ãå®è¡ããå ´åãã¨ã³ããã¤ã³ãèå¥ã¯æ å¹ã«ãªãã¾ããã¢ããã°ã¬ã¼ããå®è¡ããå ´åã§ãLDAPSã使ç¨ãã¦æ¥ç¶ããæ¢å ã®Active Directoryã³ãã¯ã¿ (ã³ã³ãã¥ã¼ã¿ã¾ãã¯ã¦ã¼ã¶ã®ããããã«å¯¾ãã¦) ã ããã³ãã«ããå ´åãã¨ã³ããã¤ã³ãèå¥ã¯ç¡å¹ã«ãªãã¾ããActive Directory ã³ãã¯ã¿ãè¦ã¤ãããªãå ´åãã¨ã³ããã¤ã³ãèå¥ã¯åæè¨å®ã§æå¹ã«ãªãã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡2: [VP-675/SEG-53377] æ°ããã¦ã¼ã¶ãVulnerability Protection Managerã®Webã³ã³ã½ã¼ã«ã«ãã°ãªã³ ããã¨ãããã·ã¥ãã¼ããé©åã«ãã¼ãã§ããªããã¨ãããåé¡ãããã¾ããã ä¿®æ£2: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã
Agent
2. ä¿®æ£ãããå 容 ================= 注æ: æ¬Patchãã¤ã³ã¹ãã¼ã«å¾ã«ãæ¬ã»ã¯ã·ã§ã³ã«ãæé ããå«ã¾ããå ´åã«ã¯ãæ é ããå®è¡ãã¦ãã ããã 2.1 æ°æ©è½ ========== æ¬Patchã§ã¯ã次ã®æ°æ©è½ãæä¾ããã¾ãã æ¬Patchã§æä¾ãããå 容ã«ã¤ãã¦ã次ã®å½¢å¼ã§è¨è¼ãã¾ãã ------------------------------------------------ æ©è½: [社å 管çç¨çªå·] æ©è½ã®å 容 æé : æé ã®å 容 ------------------------------------------------ æ©è½1: [DSSEG-2770] ã¢ã¸ã¥ã¼ã«ã®ãã©ã°ã¤ã³ãã¡ã¤ã«ãVulnerability Protection Agentã®ã¤ã³ã¹ãã¼ ã©ã¨åããã©ã«ãã«åå¨ããå ´åããã¹ã¦ã®æ©è½ã¢ã¸ã¥ã¼ã«ãã¤ã³ã¹ãã¼ã«ãã㪠ããªãã¾ããä¿è·å¯¾è±¡ã³ã³ãã¥ã¼ã¿ã§ããªã·ã¼ãé©ç¨ããã¦ããå ´åãå¿ è¦ãªãã© ã°ã¤ã³ãã¡ã¤ã«ã¯ãVulnerability Protection Relayãããã¦ã³ãã¼ãããããã« ãªãã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ æ©è½2: [DSSEG-773] Vulnerability Protection Agentããã³Vulnerability Protection Relayã§ä½¿ç¨ ãããOpenSSLã®ãã¼ã¸ã§ã³ãopenssl-1.0.2oã«ã¢ãããã¼ãããã¾ãã 2.2 æ¬Patchã§ä¿®æ£ãããæ¢ç¥ã®åé¡ ================================= æ¬Patchã§ã¯ã次ã®åé¡ãä¿®æ£ããã¾ãã æ¬Patchã§ä¿®æ£ãããå 容ã«ã¤ãã¦ã次ã®å½¢å¼ã§è¨è¼ãã¾ãã ------------------------------------------------ åé¡: [社å 管çç¨çªå·] åé¡ã®å 容 ä¿®æ£: ä¿®æ£ã®å 容 ------------------------------------------------ åé¡1: [DSSEG-3337] ã¡ã¢ãªã®å²ãå½ã¦ã«å¤±æããã¨ããããã¯ã¼ã¯ãã£ã«ã¿ãã©ã¤ãã«ããã¨ã©ã¼ãã³ ããªã³ã°ãè¡ãããªããã¨ãããã¾ããããã®ãã¨ã«èµ·å ãã¦ãç¹ã«ã·ã¹ãã ã¡ã¢ ãªãæ¯æ¸ãã¦ããéã«ãã·ã¹ãã ãã¯ã©ãã·ã¥ããåé¡ãããã¾ããã ä¿®æ£1: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡2: [DSSEG-3332/VP-669/SEG-41367] 以åã®ä¿®æ£ã«ä¼´ãããããã¯ã¼ã¯ãã£ã«ã¿ãã©ã¤ããããã¼ããã³ãã¯ã¤ã¤ã¬ã¹ ã¤ã³ã¿ãã§ã¼ã¹ãä»ãã¦ãã±ããã渡ãåé¡ãããã¾ããã ä¿®æ£2: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡3: [DSSEG-2737/SEG-34502] 以å追跡ããæ¥ç¶ã¨åãçµã¿åããã§TCPæ¥ç¶ã確ç«ãããå ´åããããã¯ã¼ã¯ ã¨ã³ã¸ã³ãæ¥ç¶è¿½è·¡ãæ£ãããªãã¹ãã¼ã¿ã¹ã«è¨å®ããåé¡ãããã¾ããã ãã®åé¡ã¯ãæ¥ç¶åæå¾ãçæéã§æ¥ç¶ãåå©ç¨ãããã¸ã¼ç¶æ ã®ãµã¼ãã§çºçã ããã¨ãããã¾ããããããã¯ã¼ã¯ã¨ã³ã¸ã³ã¯ããããã»ãã·ã§ã³æ å ±ãªããã® ã¨ã©ã¼ã¨ãã¦æ±ãããã±ãããç ´æ£ãã¦ãã¾ããã ä¿®æ£3: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡4: [DSSEG-2861/SEG-36443/00131713/SEG-36443] Vulnerability Protection AgentãSSL/TLSãããã³ã«ã®renegotiation (åãã´ã· ã¨ã¼ã·ã§ã³) ã«é¢é£ããèå¼±æ§ã®å½±é¿ãåããåé¡ãããã¾ããã ä¿®æ£4: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡5: [DSSEG-3478/VP-670/SEG-44652] Windowsã¬ã¸ã¹ããªãã¼ãå¦çããå ´åãVulnerability Protection Agentã®CPU 使ç¨çãé«ããªããã¨ãããåé¡ãããã¾ããã ä¿®æ£5: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡6: [DSSEG-3510/SEG-39711/SF01397109] Vulnerability Protection Agentã®ä¾µå ¥é²å¾¡ã¢ã¸ã¥ã¼ã«ãã¼ããã¤ãã¼ãã® UDPãã±ãããç ´æ£ããåé¡ãããã¾ããã ä¿®æ£6: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ åé¡7: [DSSEG-3582/VP-672/SEG-47257] ç¡å¹ãªIPv6ããããåå ã§Vulnerability Protection Agentã®ãããã¯ã¼ã¯ ãã©ã¤ã (tbimdsa) ãã¯ã©ãã·ã¥ããåé¡ãããã¾ããã ä¿®æ£7: æ¬Patchã®é©ç¨å¾ã¯ããã®åé¡ãä¿®æ£ããã¾ãã