<?xml version="1.0" encoding="UTF-8" ?>
<!DOCTYPE JpcertCcReport SYSTEM "http://www.jpcert.or.jp/wr/wr.dtd">
<JpcertCcReport>
	<Header>
		<Name>JPCERT-WR-2011-3102</Name>
		<Date>2011-08-17</Date>
		<From>2011-08-07</From>
		<To>2011-08-13</To>
	</Header>

	<Article RiskLevel="1" Type="RU">
		<Title>2011年8月 Microsoft セキュリティ情報について</Title>
		<Source>
			<Name>US-CERT Technical Cyber Security Alert TA11-221A</Name>
			<Title>Microsoft Updates for Multiple Vulnerabilities</Title>
			<URL>http://www.us-cert.gov/cas/techalerts/TA11-221A.html</URL>
		</Source>
		<Source>
			<Name>US-CERT Cyber Security Alert SA11-221A</Name>
			<Title>Microsoft Updates for Multiple Vulnerabilities</Title>
			<URL>http://www.us-cert.gov/cas/alerts/SA11-221A.html</URL>
		</Source>

		<Summary>
Microsoft Windows、Office、Internet Explorer、.NET Framework、
Developer Tools などの製品および関連コンポーネントには複数の脆弱
性があります。結果として、遠隔の第三者が任意のコードを実行したり、
サービス運用妨害 (DoS) 攻撃を行ったりする可能性があります。

この問題は、Microsoft Update などを用いて、セキュリティ更新プロ
グラムを適用することで解決します。
		</Summary>

		<Reference Language="JAPANESE">
			<Name>Microsoft TechNet</Name>
			<Title>2011 年 8 月のセキュリティ情報</Title>
			<URL>http://www.microsoft.com/japan/technet/security/bulletin/ms11-aug.mspx</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Microsoft TechNet Blogs > 日本のセキュリティチーム</Name>
			<Title>2011 年 8 月のセキュリティ情報 (月例)</Title>
			<URL>http://blogs.technet.com/b/jpsecurity/archive/2011/08/10/3446130.aspx</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Japan Vulnerability Notes JVNTA11-221A</Name>
			<Title>Microsoft 製品における複数の脆弱性に対するアップデート</Title>
			<URL>https://jvn.jp/cert/JVNTA11-221A/index.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>@police</Name>
			<Title>マイクロソフト社のセキュリティ修正プログラムについて(MS11-057,058,059,060,061,062,063,064,065,066,067,068,069)</Title>
			<URL>https://www.npa.go.jp/cyberpolice/topics/?seq=7005</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>株式会社日本レジストリサービス（JPRS）</Name>
			<Title>（緊急）Windows DNSサーバーの脆弱性を利用した攻撃について</Title>
			<URL>http://jprs.jp/tech/security/2011-08-11-msdns-vuln-naptr-remote-code.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>JPCERT/CC Alert 2011-08-10 JPCERT-AT-2011-0021</Name>
			<Title>2011年8月 Microsoft セキュリティ情報 (緊急 2件含) に関する注意喚起</Title>
			<URL>https://www.jpcert.or.jp/at/2011/at110021.html</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>Microsoft Security Research &#38; Defense</Name>
			<Title>Assessing the risk of the August security updates</Title>
			<URL>http://blogs.technet.com/b/srd/archive/2011/08/09/assessing-the-risk-of-the-august-2011-security-updates.aspx</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>Microsoft Security Research &#38; Defense</Name>
			<Title>Vulnerabilities in DNS Server Could Allow Remote Code Execution</Title>
			<URL>http://blogs.technet.com/b/srd/archive/2011/08/09/vulnerabilities-in-dns-server-could-allow-remote-code-execution.aspx</URL>
		</Reference>
	</Article>


	<Article RiskLevel="1" Type="RU">
		<Title>Adobe の複数の製品に脆弱性</Title>
		<Source>
			<Name>US-CERT Technical Cyber Security Alert TA11-222A</Name>
			<Title>Adobe Updates for Multiple Vulnerabilities</Title>
			<URL>http://www.us-cert.gov/cas/techalerts/TA11-222A.html</URL>
		</Source>
		<Source>
			<Name>US-CERT Cyber Security Alert SA11-222A</Name>
			<Title>Adobe Updates for Multiple Vulnerabilities</Title>
			<URL>http://www.us-cert.gov/cas/alerts/SA11-222A.html</URL>
		</Source>

		<Summary>
Adobe Shockwave Player、Flash Media Server、Flash Player、Adobe
AIR、Photoshop CS5、RoboHelp には、複数の脆弱性があります。結果と
して、遠隔の第三者が任意のコードを実行したり、サービス運用妨害
(DoS) 攻撃を行ったりする可能性があります。

この問題は、Adobe が提供する修正済みのバージョンに、該当する製品
を更新することで解決します。なお、RoboHelp 9.0.1.262 は、本脆弱
性の影響を受けないとのことです。詳細については、Adobe が提供する
情報を参照してください。
		</Summary>

		<Reference Language="JAPANESE">
			<Name>Adobe セキュリティ情報</Name>
			<Title>APSB11-19：Adobe Shockwave Player に関するセキュリティアップデート公開</Title>
			<URL>http://kb2.adobe.com/jp/cps/914/cpsid_91449.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Adobe セキュリティ情報</Name>
			<Title>APSB11-20: Adobe Flash Media Server に関するセキュリティアップデート公開</Title>
			<URL>http://kb2.adobe.com/jp/cps/914/cpsid_91453.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Adobe セキュリティ情報</Name>
			<Title>APSB11-21: Adobe Flash Player に関するセキュリティアップデート公開</Title>
			<URL>http://kb2.adobe.com/jp/cps/914/cpsid_91448.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Adobe セキュリティ情報</Name>
			<Title>APSB11-22: Adobe Photoshop CS5 用セキュリティアップデート公開</Title>
			<URL>http://kb2.adobe.com/jp/cps/914/cpsid_91450.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Adobe セキュリティ情報</Name>
			<Title>APSB11-23: Adobe RoboHelp に関するセキュリティアップデート公開</Title>
			<URL>http://kb2.adobe.com/jp/cps/914/cpsid_91451.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>Japan Vulnerability Notes JVNTA11-222A</Name>
			<Title>Adobe 製品における複数の脆弱性</Title>
			<URL>https://jvn.jp/cert/JVNTA11-222A/index.html</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>@police</Name>
			<Title>アドビシステムズ社の Adobe Flash Player のセキュリティ修正プログラムについて</Title>
			<URL>https://www.npa.go.jp/cyberpolice/topics/?seq=7003</URL>
		</Reference>
		<Reference Language="JAPANESE">
			<Name>JPCERT/CC Alert 2011-08-10 JPCERT-AT-2011-0022</Name>
			<Title>Adobe Flash Player の脆弱性に関する注意喚起</Title>
			<URL>https://www.jpcert.or.jp/at/2011/at110022.html</URL>
		</Reference>

	</Article>


	<Article RiskLevel="1" Type="RU">
		<Title>ISC DHCP サーバに脆弱性</Title>
		<Source>
			<Name>Internet Systems Consortium</Name>
			<Title>ISC DHCP Server Halt</Title>
			<URL>http://www.isc.org/software/dhcp/advisories/cve-2011-2748</URL>
		</Source>

		<Summary>
ISC DHCP サーバには、脆弱性があります。結果として、遠隔の第三者
がサービス運用妨害 (DoS) 攻撃を行う可能性があります。

対象となるバージョンは以下の通りです。

- ISC DHCP バージョン 3.1-ESV-R3 より前のバージョン
- ISC DHCP バージョン 4.1-ESV-R3 より前のバージョン
- ISC DHCP バージョン 4.2.2 より前のバージョン

この問題は、使用している OS のベンダや配布元が提供する修正済みの
バージョンに ISC DHCP サーバを更新することで解決します。詳細につ
いては、各ベンダや配布元が提供する情報を参照してください。
		</Summary>

	</Article>


	<Article RiskLevel="1" Type="RU">
		<Title>BlackBerry Enterprise Server に脆弱性</Title>
		<Source>
			<Name>US-CERT Current Activity Archive</Name>
			<Title>RIM Releases Security Advisory for BlackBerry Enterprise Server</Title>
			<URL>http://www.us-cert.gov/current/archive/2011/08/10/archive.html#rim_releases_security_advisory_for5</URL>
		</Source>

		<Summary>
BlackBerry Enterprise Server に含まれる BlackBerry MDS Connection 
Service および BlackBerry Messaging Agent には、脆弱性があります。
結果として、遠隔の第三者が細工した Web ページを閲覧させたり、細
工した PNG 形式または TIFF 形式の画像を埋め込んだ電子メールを送
付したりすることで、任意のコードを実行したり、サーバに不正にアク
セスしたりする可能性があります。

この問題は、Research In Motion が提供する修正済みのバージョンに 
BlackBerry Enterprise Server を更新することで解決します。詳細に
ついては、Research In Motion が提供する情報を参照してください。
		</Summary>

		<Reference Language="ENGLISH">
			<Name>Research In Motion - Security Advisory KB27244</Name>
			<Title>Vulnerabilities in BlackBerry Enterprise Server components that process images could allow remote code execution</Title>
			<URL>http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displayKC&#38;docType=kc&#38;externalId=KB27244</URL>
		</Reference>
	</Article>


	<Article RiskLevel="1" Type="RU">
		<Title>McAfee SaaS Endpoint Protection に複数の脆弱性</Title>
		<Source>
			<Name>DOE-CIRC Technical Bulletin T-688</Name>
			<Title>McAfee Security Bulletin - McAfee SaaS Endpoint Protection update fixes multiple ActiveX issues</Title>
			<URL>http://www.doecirc.energy.gov/bulletins/t-688.shtml</URL>
		</Source>

		<Summary>
McAfee SaaS Endpoint Protection の ActiveX コントロールには、複数
の脆弱性があります。結果として、遠隔の第三者が任意のコードを実行
したり、ファイルを上書きしたりする可能性があります。

対象となるバージョンは以下の通りです。

- McAfee SaaS Endpoint Protection 5.2.1 およびそれ以前

この問題は、McAfee が提供する修正済みのバージョンに McAfee SaaS
Endpoint Protection を更新することで解決します。なお、日本語版製
品を使用している場合、McAfee が9月下旬提供予定のMcAfee SaaS
Endpoint Protection に更新することで解決します。
		</Summary>

		<Reference Language="ENGLISH">
			<Name>マカフィー サポート Q&amp;A</Name>
			<Title>SaaS Endpoint Protection で発見された ActiveX コントロールの脆弱性について</Title>
			<URL>https://www.mcafee.com/japan/pqa/aMcAfeeTPS50.asp?ancQno=TP511081901&amp;ancProd=McAfeeTPS50</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>McAfee Security Bulletin</Name>
			<Title>McAfee SaaS Endpoint Protection update fixes multiple ActiveX issues</Title>
			<URL>https://kc.mcafee.com/corporate/index?page=content&#38;id=SB10016</URL>
		</Reference>
	</Article>


	<Memo>
		<Title>Web ブラウザのセキュリティ関連アドオン</Title>
		<Content>
現在広く使われている Web ブラウザの多くは、アドオンを追加すること
で機能を拡張する仕組みが実装されています。様々な開発者からアドオ
ンが提供されていますが、その中には Web ブラウザ使用時のセキュリティ
を向上させるアドオンや、Web アプリのセキュリティ監査を支援するた
めのアドオンなどもあります。

主なアドオンを機能別にまとめた情報などもありますので、お使いの
Web ブラウザへの導入を検討する際の参考にしてはいかがでしょうか。
</Content>

		<Reference Language="ENGLISH">
			<Name>Mozilla</Name>
			<Title>Add-ons for Firefox</Title>
			<URL>https://addons.mozilla.org/en-US/firefox/collections/?sort=featured</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>Apple</Name>
			<Title>Safari Extentions Gallery</Title>
			<URL>http://extensions.apple.com/#security-extentions</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>FireCAT: Firefox Catalog of Auditing exTensions</Name>
			<URL>http://www.firecat.fr/the_catalog.html</URL>
		</Reference>
		<Reference Language="ENGLISH">
			<Name>KromCAT - The Google Chrome Catalog of Auditing exTensions v1.0 Beta</Name>
			<URL>http://www.firecat.fr/kromcat/the_catalog.html</URL>
		</Reference>

	</Memo>

</JpcertCcReport>

