Oracle Java SE JDK7ããã³JRE7ã®ãµã³ãããã¯ã¹è¿åã«ããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ï¼CVE-2012-4681ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
2012/08/30
2012/09/03æ´æ°
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
è¾» 伸å¼
å°ç°å ç§æ
å°æ¾ å¾¹ä¹
ãæ¦è¦ã
Oracle Java SE JDK7ããã³JRE7ã«ããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ãçºè¦ããã¾ããã æ¬èå¼±æ§ã¯ãJavaã®ãµã³ãããã¯ã¹æ©è½ãå¶å¾¡ããã»ãã¥ãªãã£ããã¼ã¸ã£ã¯ã©ã¹ãç´°å·¥ããã³ã¼ãã«ããç¡å¹åãããã¨ã«ãããJavaã®ã»ãã¥ãªãã£æ©æ§ãè¿åããããã¨ã«ããçºçãã¾ãã
2012å¹´8æ29æ¥æç¹ã«ããã¦Oracle社ããèå¼±æ§ã¸ã®å¯¾çãåé¿çãªã©ã®ã¢ãã¦ã³ã¹ã¯ããã¾ãããã¾ããæ¬èå¼±æ§ãå©ç¨ããPoison Ivyã使ç¨ããæ»æã観測ããã¦ãã¾ããæ¬èå¼±æ§åã³Poison Ivyã使ç¨ããæ»æã観測ããã¦ãããã¨ãæ»æãã®ãã®ã容æã§ããã·ã¹ãã ã«ä¸ããå½±é¿ãå¤ãããã¨ãããæ¬èå¼±æ§(CVE-2012-4681)ã«ã¤ãã¦åç¾æ§ãæ¤è¨¼ãããã¾ããã
Oracle Java SE JDK7ããã³JRE7ã®ãµã³ãããã¯ã¹è¿åã«ããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ï¼CVE-2012-4681ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
ãå½±é¿ãåããã¨ããã¦ããã·ã¹ãã ã
- Oracle Java JDK and JRE 7 Update 6以å
ã(2012å¹´8æ29æ¥æç¹)
ã対çæ¡ã
2012å¹´8æ29æ¥æç¹ã«ããã¦ãOracle社ããæ¬èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ã¯ãªãªã¼ã¹ããã¦ããã¾ãããæ»æãæç«ããæ©ä¼ãæ¸ããããã以ä¸ã®å¯¾å¿ãèãããã¾ãã
- ã¦ã¤ã«ã¹å¯¾çã½ããã®å®ç¾©ãã¡ã¤ã«ãææ°ã«ãã
- ä¸å¿ è¦ãªWebãµã¤ãã«ã¢ã¯ã»ã¹ããªã
- ã¯ã©ã¤ã¢ã³ãã«ä½è¨ãªéä¿¡ã許å¯ããªã
ä¸è¨å¯¾å¿ã¯ãæ®æ®µããå®æ½ããã ããã¨ãæ¨å¥¨ãããã¾ãã
ã¾ããæ¥åçã§Javaãå¿
è¦ãªãµã¤ã以å¤ã¯ãä¸æçã«ä½¿ç¨ãã¦ãããã©ã¦ã¶ã®Javaãã©ã°ã¤ã³ãç¡å¹åãããã¨ã対çã¨ãªãã¾ãã
ãªããOracle社ããæ¬èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ããªãªã¼ã¹ãããéã«ã¯ãå©ç¨ç°å¢ã¸ã®å½±é¿ã確èªã®ä¸ãã¢ãããã¼ãããã ããã¨ãæ¨å¥¨ãããã¾ãã
Java SEãã¦ã³ãã¼ããµã¤ã
http://www.oracle.com/technetwork/java/javase/downloads/index.html
2012å¹´9æ3æ¥è¿½è¨ï¼
Oracle社ãããä¿®æ£ããã°ã©ã ï¼Oracle Java JDK and JRE 7 Update 7ï¼ããªãªã¼ã¹ããã¦ãã¾ãã
ååãªæ¤è¨¼ã®å¾ãéç¨ã«æ¯éãããããªããã¨ãã確èªã®ä¸ãä¿®æ£ããã°ã©ã ã®é©ç¨ãè¡ãªããã¨ãæ¨å¥¨ããã¾ãã
http://www.oracle.com/technetwork/java/javase/7u7-relnotes-1835816.html
ä¿®æ£ããã°ã©ã ãé©ç¨ãã以ä¸ã®ã·ã¹ãã ã«å¯¾ãã¦å度æ¤è¨¼ãè¡ã£ãçµæãèå¼±æ§ã®åç¾ãã§ããªããã¨ã確èªããã¾ããã
- Windows XP SP3
- Java SE JRE 7 Update 7
- Internet Explorer 7
- Firefox 14
- Google Chrome 21
ãåèãµã¤ãã
CVE-2012-4681
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2012-4681
JVNTA12-240A: Oracle Java 7 ã«èå¼±æ§
http://jvn.jp/cert/JVNTA12-240A/
FireEye社blog(è±èª)
http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html
2012å¹´9æ3æ¥è¿½è¨ï¼
Oracle Security Alert for CVE-2012-4681
http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html
ãæ¤è¨¼ã¤ã¡ã¼ã¸ã
ãæ¤è¨¼ã¿ã¼ã²ããã·ã¹ãã ã
- Windows XP SP3
- Java SE JRE 7 Update 6
ä¸è¨ç°å¢ã§ä»¥ä¸ã®ãã©ã¦ã¶ãä»ãã¦æ»æãæç«ãããã¨ã確èªãã¾ããã
- Internet Explorer 7
- Firefox 14
- Google Chrome 21
ãæ¤è¨¼æ¦è¦ã
ã¿ã¼ã²ããã·ã¹ãã ä¸ã§ãæªæã®ããã¦ã¼ã¶ãä½æããWebãã¼ã¸ãé²è¦§ããããã¨ã§ãæ»æã³ã¼ããå®è¡ããã¾ããããã«ãã£ã¦ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ä»»æã®ã³ã¼ããå®è¡ããã¾ãã
ã¿ã¼ã²ããã·ã¹ãã ã¯ãæªæã®ããã¦ã¼ã¶ãç¨æãããã¹ãã«å¶å¾¡ãèªå°ããã¾ãã
ä»åã®æ¤è¨¼ã«ç¨ããã³ã¼ãã¯ãã¿ã¼ã²ããã·ã¹ãã ä¸ããç¹å®ã®ãµã¼ãããã¼ãã¸ã³ãã¯ã·ã§ã³ã確ç«ãããããèªå°ããã·ã¹ãã ã®å¶å¾¡ã奪åãããã®ã§ãã
ããã«ããããªã¢ã¼ãããã¿ã¼ã²ããã·ã¹ãã ãæä½å¯è½ã¨ãªãã¾ãã
ï¼ èªå°å ã®ã·ã¹ãã 㯠Debian ã§ãã
ãæ¤è¨¼çµæã
ä¸å³ã¯ãæ»æå¾ã®èªå°å ã®ã·ã¹ãã ç»é¢ã§ãã
ä¸å³ã®èµ¤ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãèªå°å
ã®ã³ã³ãã¥ã¼ã¿ï¼Debianï¼ã®ã¿ã¼ããã«ä¸ã«ã¿ã¼ã²ããã·ã¹ãã ï¼Windows XPï¼ã®ããã³ããã表示ããã¦ãã¾ãã
é»ç·ã§å²ã¾ãã¦ããé¨åã®ç¤ºãããã«ãã¿ã¼ã²ããã·ã¹ãã ã«ããã¦ãã³ãã³ããå®è¡ããçµæã表示ããã¦ãã¾ããããã«ãããã¿ã¼ã²ããã·ã¹ãã ã®å¶å¾¡ã®å¥ªåã«æåããã¨è¨ãã¾ãã
PDFçã®ãã¦ã³ãã¼ãã¯ãã¡ããããPDFç
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã¯ãå社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ããTweet