警報解除 2/3 : Adobe Flash Player
Posted in security on 7 月 31st, 2009 by gnome
Adobe Flash Player
永らくFlashを見るのを自粛していた方、お待ちどう様でした。
昨日ニコニコ生中継を見てたクセに!
また、関連して Adobe AIRを使用中の方もアップデートしてください
Security updates available for Adobe Flash Player
| Flash Player 10.x | → | 10.0.32.18 |
| Flash Player 9.x | → | 9.0.246.0 |
| Adobe AIR 1.5.1 | → | 1.5.2 |
注意:
バージョンチェックのページの最新版表記が更新されました。尚、IEの場合一度ブラウザを再起動しないと正確な表示ができません。複数のブラウザを使用中の方は、必ず各ブラウザ上でバージョンチェックを行い、10.0.32.18 (もしくは 9.0.246.0)になっていることを確認してください。
※基本的にはIEだけ別コンポネンツのはずですが・・・
----------
Security Bulletin Posted for Adobe Flash PlayerCVE:
CVE-2009-1862Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
CVE-2009-0901The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability."
CVE-2009-2395SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
CVE-2009-2493The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
以下はreserved (非公開脆弱性)
CVE-2009-1863
CVE-2009-1864
CVE-2009-1865
CVE-2009-1866
CVE-2009-1867
CVE-2009-1868
CVE-2009-1869
CVE-2009-1870----------
セキュ各社報道:
6:30(JST)ではまだ無かった・・・
----------
シス管の方へ
コレでもカジリながらインストールしてください(笑)
ちなみに、まだ Adobe (Acrobat) Reader も残っています
(明日パッチ予定:月曜ですね・・)
Ciscoのルータを導入している方には更に楽しい(?)日になりそうです・・・
システム管理者の日
Happy patching day
CentOS-announce
A Security Vulnerability in Solaris BIND named(1M) Due to Insufficient Input Validation of Dynamic Update Requests Can Lead to Denial of Service (DoS)
[SECURITY] Fedora 11 Update: bind-9.6.1-4.P1.fc11
[SECURITY] [DSA 1847-1] New bind9 packages fix denial of service
USN-808-1: Bind vulnerability -- Ubuntu
Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities
BlackHat USA+2009
Null Character Hack Allows SSL Spoofing
exact same way to fake being a popular website
Black Hat DC 09 Moxie Marlinspike Interview
Busy day at Black Hat
Vegas Baby!
URL bar spoofing vulnerability
BIND Dynamic Update DoS
Important: bind security update
Adobe Releases Shockwave Player Update and Flash Player Security Advisory
MSが臨時パッチをリリース、Visual StudioとIEの脆弱性を修正
Active Template Library Security Update for Developers
速報―MicrosoftとYahooの検索提携の主な内容
iPhone SMS attack to be unleashed at Black Hat
TrendWatch
http://update.microsoft.com/microsoftupdate/
ISC BIND 9 におけるサービス運用妨害 (DoS) の脆弱性
bind can be crashed with an update packet:
MySQL Connector/J SQL Injection Vulnerability
C.6.1.1. Changes in MySQL Connector/J 5.1.8 (16 July 2009)
逃避中
Microsoft Security Advisory 973882, Microsoft Security Bulletins MS09-034 and MS09-035 Released
Microsoft Active Template Library patches published out-of-band
Poking around MSVIDCTL.DLL -- Thursday, July 09, 2009
Microsoft to ship emergency IE, Visual Studio patches
twitterview.net
1&1 Internet AG
Gaming Harber ToolBar
AT&T Statement Regarding img.4chan.org
digg あたりで大騒ぎ
JUNIK
Bigness Group Ltd.
WEDARE(We Dare BV Autonomous System)
molo.tw
脆弱性一覧
Not Enough Magic by Spammers Using the Potter Tale
Rumors of Emma Watson's Death Leading to Rogue AV Sites
アンダーグラウンドの臭いがする「Nine-ball」,アジアに忍び寄る危機 
文科省のサイトが改ざん 中国サイト?にリンク
Report MD5:e41e16d0ec09d694caab8f0350add417
Mal/EncPk-JB, TrojanDownloader:Win32/Harnig.gen!P, Hoax.Win32.Renos.vchc..
China Network Communications
installb.exe0 received 2009.07.25 02:33:29 (UTC)

KILL Acrobat JavaScript
Apple QuickTime 7.5.6
Firefox 3.6.3
Chrome 4.1.249.1045
Opera 10.51
Thunderbird 3.0.4
O
OOo 3.2
RealPlayer SP1.1.2(12.0.0.641)
Skype 4.2.0.155
Pidgin 2.6.6
Wordpress 2.9.2
WireShark 1.2.7






BEFORE BURNER
