2008-01-01ãã1å¹´éã®è¨äºä¸è¦§
ã¾ã£ã¡ã445åå¼·ä¼ã¡ã¼ãªã³ã°ãªã¹ã ãéè¨ããã¾ããã ä»å¾ã®åå¼·ä¼ã®åéåç¥ãè¡ãã ãã§ã¯ãªãã åå¼·ä¼ã®å¸æãã¼ããæ稿ãããããè¬å¸«ããããï¼ãã¨ãã声ãããããã åå¼·ä¼åå¾ã®ãã£ã¹ã«ãã·ã§ã³ã®å ´ã¨ãã¦ãå©ç¨é ããã°ã¨æãã¾ãã ã¡ãªã¿â¦
ã¾ããã¾ã«ã¯æ´æ°ããªãã¨ãã£ã¦ãã¨ã§(;^_^A ã¢ã»ã¢ã»â¦
ãçµ±åID管çã½ãªã¥ã¼ã·ã§ã³ããæ¡å -2008å¹´9æ24æ¥- æ¥æ¬ã¦ãã·ã¹ æ¥æ¬ã¦ãã·ã¹ãNovelIDMã«å ãã¦MS ILMãçµ±åID管çSolution*1ã®ã©ã¤ã³ãããã«å ããããããã§ãããã æµ·å¤ã¨ãã®IDMå¸å ´ãè¦ã¦ãã¨ãRoleManegementã«ã·ãããã¦ãã¦ããã®ã ããããâ¦
http://www.bbsec.co.jp/aboutus/press/080917.html ã«ããã¨ã Javaã¨.NETã§çµã¾ããã¢ããªã対象ãªã®ã§ãJavaEEãµã¼ããIISã対象ã£ã¦äºãªã®ããªï¼ ServletFilterã¨ISAPI Filter使ã£ã¦å®è£ ããå ´åã¯ãAPãµã¼ãã¨RDBMSéã®éä¿¡ã¯ã¸ã£ãã¯åºæ¥ãªããããã©â¦
http://www.webappsec.org/lists/websecurity/archive/2008-09/msg00034.html ã®ã¡ã¼ã«ã§Robert Augeræ°ã ãHey!誰ããã£ã¼ãããã¯ããYO!ã ã£ã¦äºãªã®ã§ãèå³ããã£ã¦æéãåããæ¹ã¯æ¯éï¼ï½
Threatï¼è å¨ï¼ Severityï¼éå¤§åº¦ï¼ ã«é¢ããè¦è§£ãè¨è¼ãããªããªããå 容ãé常ã«ç解ãè¾ããªã£ãæ°ãããã
Oracle Fusion Middleware ãªããåºã¦ããâ Impact and CVSS Ratings CVSSè©ä¾¡å¤ : 10.0 (High) æ»æå åºå (AV) : Network æ»ææ¡ä»¶ã®è¤éã (AC) : ä½ æ»æåã®èªè¨¼è¦å¦ (Au) : ä¸è¦ å½±é¿ : æ©å¯æ§ãå®å ¨æ§ãå¯ç¨æ§ã®å ¨ã¦ãå½±é¿ãåãã èå¼±æ§ã®ã¿ã¤ã : â¦
第01åã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ ã¨ããããã§ã é¢è¥¿ã§ã¾ã£ã¡ãï¼ï¼ï¼ã®ä»£è¡¨ãåããid:ripjyrãããé¢è¥¿ã¨ã¯å¥ã«ãé¢æ±ã§ãåå¼·ä¼ãå§ããæ§ã§ã⪠大ããªç¹å¾´ã¨ãã¦ã¯ã æ±äº¬ã§æã«ï¼ååææ¥ã«åå¼·ä¼ãéå¬ æ±äº¬ã§æã«ï¼åå¹³æ¥å¤ã«åå¼·ä¼ãéå¬ï¼å¤§éªã¨ãä»æ â¦
http://dev2dev.bea.com/advisoriesnotifications/ ã§ã¢ããã¤ã¶ãªã¼ã7ä»¶å ¬éããã¦ããã®ã§ããã ãã³ããªã³ã°ãCVE-2008-XXXXã¨ãªã£ã¦ãããã CVSS Ratingããè¨è¼ãããªããªã£ã¦ãããã¨å BEAã®Engineeréã¯ããæ°ãªããã¦ãã®ããªãï¼ã¨æã£ã¦ã¿ããâ¦
ã¾ãããä¹ ãã¶ãã®æ´æ°ã§ããã
Oracleã«è²·åããã¡ãã£ãæ社ããæ社ã¸ç§»ã£ãã®ããã æ¬äººã¯è¨æ¶ã«ãªãã ãããã©ããã®ç¯ã¯å¤§å¤ãä¸è©±ã«ãªãã¾ããã # ãããå æ°ã ã£ãããã¯ãªã³ã¯å¼µããã¡ãã£ã¦ãããããã¾ãããï½ãã©ãããã°ã寺åå±ãèç¡å§ãæ®ã©å©ç¨ãã¦ãã¾ãããï¼ãã ä¾â¦
Windows Server 2008ç»å ´ | Think ITï¼ã·ã³ã¯ã¤ããï¼ Windows Server 2008ããã¨æã£ã¦ãéãã¦ã¿ããé«æ·»ããã ã£ãï½
http://java.sun.com/javase/ja/6/download.html å質åä¸ã®çºã«Sunã¸æ å ±ãéãä»çµã¿ãçµã¿è¾¼ã¾ãããããã ã¾ããéè¦ãªä¿®æ£ãªã©ã¯ãªãã®ã§ãä¸ããªãã¦ãããã£ã½ãããè²ã è¦éãã¦ã¾ãããããorz DoSé£ããã¨ããã¼ã«ã«ãã¡ã¤ã«å¼ããã¨ãããããã¡â¦
http://java.sun.com/javase/ja/6/download.html 1.4.2ã§ä¿®æ£ããããã®ã«è¿½å 㧠Hard hangs in concurrent code on Solaris and Linux ã¨ãã ãããè ¹ãã£ã±ããä¸ããæ¹ãç¡é£ã£ã½ãããã¨ãè±èªã®ãªãªã¼ã¹ãã¼ããè¦ã¦ä¸ãããã æ¥æ¬èªçã§ã¯åå以ä¸è¨â¦
http://java.sun.com/javase/ja/6/download.html Buffer Overflow in Java ActiveX component jar protocol allows LiveConnect code to connect to any port on localhost Encoding values in JNLP files can cause buffer overflow ããã辺ãåé¡ããªï¼ â¦
http://java.sun.com/j2se/1.3/ja/download.html Solarisç¨ä»¥å¤ã¯1.3.1_20ã§ã¹ããããã¦ã¾ãããSolaris8ã®å»¶é·ãµãã¼ãï¼ãããã®ã§ãJ2SE1.3.1ãä¿®æ£ãã«ããç´°ã ã¨åºã¦ããã¿ããã§ããã ã¾ããã¿ã¤ã ã¾ã¼ã³ã®ä¿®æ£ãªã©ã ãã§ããã°ã¬ãä¿®æ£ããã ã*1ãªâ¦
å»å¢ã¨åãã¦ã¾ãããè²ã æãä»ããããªãã¦æ´æ°åºæ¥ãç¶æ³ã«ãªãããã§ãã è²ã ã¨æ å ±ãã¢ãããã¼ããããã®ã§ããã»ã»ã»ã¾ã ãã°ããã¯ç¡çã£ã½ãã