Oracle Java SE JDKããã³JREã®èå¼±æ§ã«ãããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ï¼CVE-2012-1723ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
2012/07/17
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
è¾» 伸å¼
æ³ç° 幸å®
ãæ¦è¦ã
Oracle Java SE JDKããã³JREã«ããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ãçºè¦ããã¾ããã æ¬èå¼±æ§ã¯ãJavaãã¤ãã³ã¼ããHotspot VMã«ã¦å¦çãè¡ãéã«ãã³ã¼ãã®æ¤è¨¼ãä¸ååã§ãããããJavaã®ãµã³ãããã¯ã¹ãåé¿ããããã¨ã«ããçºçãã¾ãã
ãã®èå¼±æ§ã«ããããªã¢ã¼ãããJavaãå®è¡ãããã¼ã«ã«ã¦ã¼ã¶ã¨åãæ¨©éã§ä»»æã®ã³ã¼ããå®è¡ãããå±éºæ§ãããã¾ããæ»æè ã¯ããã©ã¦ã¶çµç±ã§Javaã¢ãã¬ãããèªã¿è¾¼ã¾ããããã«ç¹å¥ã«ç´°å·¥ãããWebãµã¤ãã«ã¦ã¼ã¶ãèªå°ãããã¨ããç´°å·¥ãããJavaã¢ããªã±ã¼ã·ã§ã³ãæ·»ä»ããé»åã¡ã¼ã«ãéä¿¡ããæ»æå¯¾è±¡ã¦ã¼ã¶ã«ãã¡ã¤ã«ãéããããã¨ã§ãã°ãªã³ãã¦ããã¦ã¼ã¶ã¨åãæ¨©éã奪åãããå±éºæ§ãããã¾ãã
ãã®èå¼±æ§ãä¿®æ£ããããã¼ã¸ã§ã³ã®JDKããã³JREããOracle社ãã6æ12æ¥ã«ãªãªã¼ã¹ããã¦ããã¾ããããããªãããæ»æãæç«ãããããã®ã³ã¼ãã容æã«å ¥æå¯è½ã§ããããã¤èå¼±æ§ã«å¯¾ããæ»æã容æã§ãããã¨ãã¾ãæ»æãåããéã«ã·ã¹ãã ã¸ã®å½±é¿ã大ãããã¨ãããä»åããã®èå¼±æ§ï¼CVE-2012-1723ï¼ã®åç¾æ§ã«ã¤ãã¦æ¤è¨¼ãè¡ãã¾ããã
Oracle Java SE JDKããã³JREã®èå¼±æ§ã«ãããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ï¼CVE-2012-1723ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
ãå½±é¿ãåããã¨ããã¦ããã·ã¹ãã ã
- Oracle Java JDK and JRE 7 Update 4以å
- Oracle Java JDK and JRE 6 Update 32以å
- Oracle Java JDK and JRE 5 Update 35以å
- Java SDK and JRE 1.4.2_37以å
ãå¯¾çæ¡ã
Oracle社ããããã®èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ããªãªã¼ã¹ããã¦ãã¾ãã
å½è©²èå¼±æ§ãä¿®æ£ããããã¼ã¸ã§ã³ã«ã¢ãããã¼ããã¦ããã ããã¨ãæ¨å¥¨ãããã¾ãã
- Oracle Java JDK and JRE 7 Update 5
- Oracle Java JDK and JRE 6 Update 33
ãåèãµã¤ãã
CVE-2012-1723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1723
Oracle Java SE Critical Patch Update Advisory - June 2012
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
2012å¹´6æ Java SE ã®èå¼±æ§ãçãæ»æã«é¢ããæ³¨æåèµ·
https://www.jpcert.or.jp/at/2012/at120021.html
Oracle Java SE Support Roadmap
http://www.oracle.com/technetwork/java/eol-135779.html
ãæ¤è¨¼ã¤ã¡ã¼ã¸ã

ãæ¤è¨¼ã¿ã¼ã²ããã·ã¹ãã ã
- Windows XP SP3
- Java SE JRE 6 Update 32
ãæ¤è¨¼æ¦è¦ã
ã¿ã¼ã²ããã·ã¹ãã ä¸ã§ãæªæã®ããã¦ã¼ã¶ã使ããWebãã¼ã¸ãé²è¦§ããããã¨ã§ãæ»æã³ã¼ããå®è¡ããã¾ããããã«ãã£ã¦ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ä»»æã®ã³ã¼ããå®è¡ããã¾ãã
ã¿ã¼ã²ããã·ã¹ãã ã¯ãæªæã®ããã¦ã¼ã¶ãç¨æãããã¹ãã«å¶å¾¡ãèªå°ããã¾ãã
ä»åã®æ¤è¨¼ã«ç¨ããã³ã¼ãã¯ãã¿ã¼ã²ããã·ã¹ãã ä¸ããç¹å®ã®ãµã¼ãããã¼ãã¸ã³ãã¯ã·ã§ã³ã確ç«ãããããèªå°ããã·ã¹ãã ã®å¶å¾¡ã奪åãããã®ã§ãã
ããã«ããããªã¢ã¼ãããã¿ã¼ã²ããã·ã¹ãã ãæä½å¯è½ã¨ãªãã¾ãã
ï¼ èªå°å ã®ã·ã¹ãã 㯠Debian ã§ãã
ãæ¤è¨¼çµæã
ä¸å³ã¯ãæ»æå¾ã®èªå°å ã®ã·ã¹ãã ç»é¢ã§ãã
ä¸å³ã®èµ¤ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãèªå°å
ã®ã³ã³ãã¥ã¼ã¿ï¼Debianï¼ã®ã³ã³ã½ã¼ã«ä¸ã«ã¿ã¼ã²ããã·ã¹ãã ï¼Windows XPï¼ã®ããã³ããã表示ããã¦ãã¾ãã
é»ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ãã³ãã³ããå®è¡ããçµæã表示ããã¦ãã¾ããããã«ãããã¿ã¼ã²ããã·ã¹ãã ã®å¶å¾¡ã®å¥ªåã«æåããã¨è¨ãã¾ãã

PDFçã®ãã¦ã³ãã¼ãã¯ãã¡ããããPDFç
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ããTweet