IEã®DOMå¦çã«ããã¦ãªã¢ã¼ãããæ»æå¯è½ãªã¡ã¢ãªç ´å£ã®èå¼±æ§ï¼CVE-2011-1256,MS11-050ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
2011/6/20
NTTãã¼ã¿ã»ã»ãã¥ãªãã£æ ªå¼ä¼ç¤¾
è¾» 伸å¼
å°ç°åãç§æ
æ³ç°ã幸å®
ãæ¦è¦ã
Microsoft社ã®Internet Explorer(ä»¥ä¸ IE)ã«ããªã¢ã¼ãããæ»æå¯è½ãªã¡ã¢ãªç ´å£ã®èå¼±æ§(CVE-2011-1256)ãçºè¦ããã¾ããã
ãã®èå¼±æ§ã¯IEã®DOM夿´å¦çã«åå¨ãã¾ããIEãæ£ããåæåããã¦ããªããªãã¸ã§ã¯ããåé¤ããããªãã¸ã§ã¯ããå¦çããéã«ãã¡ã¢ãªç ´å£ãå¼ãèµ·ããå¯è½æ§ãããã¾ãã
ãã®èå¼±æ§ã«ãããç´°å·¥ãããWebãã¼ã¸ã®é²è¦§ãªã©ã§ããã¼ã«ã«ã¦ã¼ã¶ã¨åãæ¨©éã奪åãããå±éºæ§ãããã¾ããæ³å®ããã被害ã¨ãã¦ã¯ããã¼ã«ã«ã¦ã¼ã¶æ¨©éã§ã®æ
å ±åå¾ãæ¹ãããã¾ãã¯ãã¯ã¼ã ãã¹ãã¤ã¦ã§ã¢ãªã©ã®æªæããããã°ã©ã ãã·ã¹ãã å
ã«ã¤ã³ã¹ãã¼ã«ããããã¨ãèãããã¾ãã
ä»åããã®IEã®èå¼±æ§(CVE-2011-1256)ã®åç¾æ§ã«ã¤ãã¦æ¤è¨¼ãè¡ãã¾ããã
IEã®DOMå¦çã«ããã¦ãªã¢ã¼ãããæ»æå¯è½ãªã¡ã¢ãªç ´å£ã®èå¼±æ§ï¼CVE-2011-1256,MS11-050ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
ãå½±é¿ãåããã¨ããã¦ããã¢ããªã±ã¼ã·ã§ã³ã
ç¾å¨ã®ã¨ãããå½±é¿ãåããå¯è½æ§ãå ±åããã¦ããã®ã¯æ¬¡ã®éãã§ãã
- Windows XP Service Pack 3 Internet Explorer 6
- Windows XP Professional x64 Edition Service Pack 2 Internet Explorer 6
- Windows Server 2003 Service Pack 2 Internet Explorer 6
- Windows Server 2003 x64 Edition Service Pack 2 Internet Explorer 6
- Windows Server 2003 with SP2 for Itanium-based Systems Internet Explorer 6
- Windows XP Service Pack 3 Internet Explorer 7
- Windows XP Professional x64 Edition Service Pack 2 Internet Explorer 7
- Windows Server 2003 Service Pack 2 Internet Explorer 7
- Windows Server 2003 x64 Edition Service Pack 2 Internet Explorer 7
- Windows Server 2003 with SP2 for Itanium-based Systems Internet Explorer 7
- Windows Vista Service Pack 1 ããã³ Windows Vista Service Pack 2 Internet Explorer 7
- Windows Vista x64 Edition Service Pack 1 ããã³ Windows Vista x64 Edition Service Pack 2 Internet Explorer 7
- Windows Server 2008 for 32-bit Systems ããã³ Windows Server 2008 for 32-bit Systems Service Pack 2 Internet Explorer 7
- Windows Server 2008 for x64-based Systems ããã³ Windows Server 2008 for x64-based Systems Service Pack 2 Internet Explorer 7
- Windows Server 2008 for Itanium-based Systems ããã³ Windows Server 2008 for Itanium-based Systems Service Pack 2 Internet Explorer 7
- Windows XP Service Pack 3 Internet Explorer 8
- Windows XP Professional x64 Edition Service Pack 2 Internet Explorer 8
- Windows Server 2003 Service Pack 2 Internet Explorer 8
- Windows Server 2003 x64 Edition Service Pack 2 Internet Explorer 8
- Windows Vista Service Pack 1 ããã³ Windows Vista Service Pack 2 Internet Explorer 8
- Windows Vista x64 Edition Service Pack 1 ããã³ Windows Vista x64 Edition Service Pack 2 Internet Explorer 8
- Windows Server 2008 for 32-bit Systems ããã³ Windows Server 2008 for 32-bit Systems Service Pack 2 Internet Explorer 8
- Windows Server 2008 for x64-based Systems ããã³ Windows Server 2008 for x64-based Systems Service Pack 2 Internet Explorer 8
- Windows 7 for 32-bit Systemsããã³ Windows 7 for 32-bit Systems Service Pack 1 Internet Explorer 8
- Windows 7 for x64-based Systems ããã³ Windows 7 for x64-based Systems Service Pack 1 Internet Explorer 8
- Windows Server 2008 R2 for x64-based Systems ããã³ Windows Server 2008 R2 for x64-based Systems Service Pack 1 Internet Explorer 8
- Windows Server 2008 R2 for Itanium-based Systems ããã³ Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 Explorer 8
ãå¯¾çæ¡ã
Microsoft社ããããã®èå¼±æ§ãä¿®æ£ããããã°ã©ã (MS11-050)ããªãªã¼ã¹ããã¦ããã¾ãã
å½è©²èå¼±æ§ãä¿®æ£ãããä¿®æ£ããã°ã©ã ãé©ç¨ãã¦ããã ããã¨ãæ¨å¥¨ãããã¾ãã
ã¾ããMicrosoft社ã§ã¯ä»¥ä¸ã®åé¿çãæç¤ºãã¦ããã¾ããä¿®æ£ããã°ã©ã ã®é©ç¨ãå°é£ã§ããå ´åã¯ãæ¤è¨ä¸ããã
- â Enhanced Mitigation Experience Toolkit (EMET) ã使ç¨ããã
- â¡ ã¤ã³ã¿ã¼ãããããã³ãã¼ã«ã« ã¤ã³ãã©ããã ã»ãã¥ãªã㣠ã¾ã¼ã³ã®è¨å®ããé«ãã«è¨å®ãããããã®ã¾ã¼ã³ã§ ActiveX ã³ã³ããã¼ã«ããã³ã¢ã¯ãã£ã ã¹ã¯ãªããããããã¯ããã
- ⢠ã¤ã³ã¿ã¼ãããããã³ãã¼ã«ã« ã¤ã³ãã©ããã ã»ãã¥ãªã㣠ã¾ã¼ã³ã§ãã¢ã¯ãã£ã ã¹ã¯ãªãããå®è¡ãããåã«ãã¤ã¢ãã°ã表示ããããã«è¨å®ããã
- ⣠ã¤ã³ã¿ã¼ãããããã³ãã¼ã«ã« ã¤ã³ãã©ããã ã»ãã¥ãªã㣠ã¾ã¼ã³ã§ãã¢ã¯ãã£ã ã¹ã¯ãªããã®å®è¡ãç¡å¹åããã
ãåèãµã¤ãã
ãæ¤è¨¼ã¤ã¡ã¼ã¸ã

ãæ¤è¨¼ã¿ã¼ã²ããã·ã¹ãã ã
Windows XP Professional SP3 ããã³ Internet Explorer 7(XPã¯SP3é©ç¨ç´å¾ã®ç¶æ )
ãæ¤è¨¼æ¦è¦ã
ã¿ã¼ã²ããã·ã¹ãã ã«IEãéãã¦ãç´°å·¥ãããWebãã¼ã¸ãé²è¦§ãããIEã®èå¼±æ§ãå©ç¨ããæ»æã³ã¼ããå®è¡ãããã¨ã§ä»»æã®ã³ã¼ããå®è¡ããã¾ãã
ä»åã®æ¤è¨¼ã«ç¨ããã³ã¼ãã¯ãã¿ã¼ã²ããã·ã¹ãã ä¸ããç¹å®ã®ãµã¼ãããã¼ãã¸ã³ãã¯ã·ã§ã³ã確ç«ãããããã«èªå°ããã·ã¹ãã ã®å¶å¾¡ã奪åãããã®ã§ãã
ããã«ããããªã¢ã¼ãããã¿ã¼ã²ããã·ã¹ãã ã®æä½ãå¯è½ã¨ãªãã¾ãã
ï¼ èªå°å ã®ã·ã¹ãã 㯠Linuxã§ãã
ãæ¤è¨¼çµæã
ä¸å³ã示ãããã«ãèªå°å
ã®ã³ã³ãã¥ã¼ã¿(Debian)ä¸ã«ã¿ã¼ã²ããã·ã¹ãã (Windows XPï¼ã®ããã³ããã表示ããã¦ãã¾ãã
ããã«ãããã¿ã¼ã²ããã·ã¹ãã ã®å¶å¾¡ã®å¥ªåã«æåããã¨è¨ãã¾ãã

PDFçã®ãã¦ã³ãã¼ãã¯ãã¡ããããPDFç
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ããTweet