Oracle Java SE JDKããã³JREã®Deploymentãµãã³ã³ãã¼ãã³ãã«ãããèå¼±æ§ (CVE-2012-0500)ã«é¢ããæ¤è¨¼ã¬ãã¼ã
2012/02/28
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
è¾» 伸å¼
å°ç°å ç§æ
ãæ¦è¦ã
Oracle Java SE JDK ããã³ JRE ã® Deployment ãµãã³ã³ãã¼ãã³ãã«ãä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ï¼CVE-2012-0500ï¼ãåå¨ãã¾ãããã®èå¼±æ§ã¯ãJNLPãã¡ã¤ã«å
ã§å®è¡ãã©ã¡ã¼ã¿ãå¦çããéã«çºçããå
¥åæ¤è¨¼ã¨ã©ã¼ã«èµ·å ãã¾ããããã«ãããæªè³ªãª JNLPãã¡ã¤ã«ãå¦çããããã¨ã§ãæ»æå¯è½ãªç¶æ
ã¨ãªãã¾ãã
ãã®èå¼±æ§ãæªç¨ãã¦ãæ»æè
ã¯ã¿ã¼ã²ãããã¹ãä¸ã§ä»»æã®ã³ã¼ãã®å®è¡ãå¯è½ã§ããæ»æè
ã¯ãå·§å¦ã«ç´°å·¥ãããJava Appletã¾ãã¯Java Web Startã¢ããªã±ã¼ã·ã§ã³ãæä¾ããWebãµã¤ãã«ã¦ã¼ã¶ãèªå°ãããã¨ã§ããã®èå¼±æ§ãæªç¨ãã¾ãã
æ³å®ããã被害ã¨ãã¦ã¯ã奪åãããã¦ã¼ã¶æ¨©éã«ããæ
å ±åå¾ãæ¹ãããã¾ãã¯ãã¯ã¼ã ãã¹ãã¤ã¦ã§ã¢ãªã©ã®æªæããããã°ã©ã ãã·ã¹ãã å
ã«ã¤ã³ã¹ãã¼ã«ããããã¨ãèãããã¾ãã
ä»åãOracle Java SE JDKããã³JREã®èå¼±æ§ï¼CVE-2012-0500ï¼ã®åç¾æ§ã«ã¤ãã¦æ¤è¨¼ãè¡ãã¾ããã
Oracle Java SE JDKããã³JREã®Deploymentãµãã³ã³ãã¼ãã³ãã«ãããèå¼±æ§ (CVE-2012-0500)ã«é¢ããæ¤è¨¼ã¬ãã¼ã
ãå½±é¿ãåããã¨ããã¦ããã·ã¹ãã ã
- Oracle Java JDK and JRE 7 Update 2 ããã³ãã以å
- Oracle Java JDK and JRE 6 Update 30 ããã³ãã以å
- Oracle JavaFX 2.0.2 ããã³ãã以å
ã対çæ¡ã
Oracle社ããããã®èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ããã¾ããå½è©²èå¼±æ§ãä¿®æ£ããããã¼ã¸ã§ã³ã«ã¢ãããã¼ããã¦ããã ããã¨ãæ¨å¥¨ãããã¾ãã
- Oracle Java JDK and JRE 7 Update 3
- Oracle Java JDK and JRE 6 Update 31
- Oracle JavaFX 2.0.3
ãåèãµã¤ãã
Oracle Java SE Critical Patch Update Advisory - February 2012
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
CVE-2012-0500
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2012-0500
ãæ¤è¨¼ã¤ã¡ã¼ã¸ã
ãæ¤è¨¼ã¿ã¼ã²ããã·ã¹ãã ã
Windows XP SP3 Internet Explorer 8
ãæ¤è¨¼æ¦è¦ã
ã¿ã¼ã²ããã·ã¹ãã ã«ãWebãã¼ã¸ãé²è¦§ãããJava Web Startã¢ããªã±ã¼ã·ã§ã³ãéããããã¨ã§ãæ»æã³ã¼ããå®è¡ããã¾ããããã«ãã£ã¦ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ä»»æã®ã³ã¼ããå®è¡ããã¾ãã
ã¿ã¼ã²ããã·ã¹ãã ã¯ãæªæã®ããã¦ã¼ã¶ãç¨æãããã¹ãã«å¶å¾¡ãèªå°ããã¾ãã
ä»åã®æ¤è¨¼ã«ç¨ããã³ã¼ãã¯ãã¿ã¼ã²ããã·ã¹ãã ä¸ããç¹å®ã®ãµã¼ãããã¼ãã¸ã³ãã¯ã·ã§ã³ã確ç«ãããããèªå°ããã·ã¹ãã ã®å¶å¾¡ã奪åãããã®ã§ãã
ããã«ããããªã¢ã¼ãããã¿ã¼ã²ããã·ã¹ãã ãæä½å¯è½ã¨ãªãã¾ãã
ï¼ èªå°å ã®ã·ã¹ãã ã¯Debian 5.05 ã§ãã
ãæ¤è¨¼çµæã
ä¸å³ã®èµ¤ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãèªå°å
ã®ã³ã³ãã¥ã¼ã¿ï¼Debianï¼ã®ã³ã³ã½ã¼ã«ä¸ã«ã¿ã¼ã²ããã·ã¹ãã ï¼Windows XPï¼ã®ããã³ããã表示ããã¦ãã¾ãã
é»ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ãã³ãã³ããå®è¡ããçµæã表示ããã¦ãã¾ãã
ããã«ãããã¿ã¼ã²ããã·ã¹ãã ã®å¶å¾¡ã®å¥ªåã«æåããã¨è¨ãã¾ãã
PDFçã®ãã¦ã³ãã¼ãã¯ãã¡ããããPDFç
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ããTweet