セキュリティホール memo - 2019.02

Last modified: Mon Mar 30 12:18:31 2019 +0900 (JST)


 このページの情報を利用される前に、注意書きをお読みください。


■ 2019.02.28


■ 2019.02.27


■ 2019.02.26

■ BIND 方面
(JPRS, 2019.02.22)

 来てます。

 BIND 9.12.3-P4 / 9.11.5-P4 で修正されている。

■ いろいろ (2019.02.26)
(various)

Explzh

NVIDIA ディスプレイドライバー


■ 2019.02.22

■ Security Updates available for Adobe Acrobat and Reader | APSB19-13
(Adobe, 2019.02.21)

 Acrobat / Reader またまた更新。1 件のセキュリティ欠陥 (情報漏洩 / Critical) を修正。Priority: 2。

種別 更新版
Acrobat DC / Acrobat Reader DC (Continuous Track) 2019.010.20098
Acrobat 2017 / Acrobat Reader DC 2017 (Classic 2017) 2017.011.30127
Acrobat DC / Acrobat Reader DC (Classic 2015) 2015.006.30482

 関連:

■ Drupal core - Highly critical - Remote Code Execution - SA-CORE-2019-003
(Drupal, 2019.02.20)

 Drupal に、remote から任意の PHP コードの実行を許す欠陥。 発動条件:

 Drupal 8 については 8.6.10 / 8.5.11 で修正されている。Drupal 7 本体には欠陥はない。 また contributed modules のいくつかに影響を受けるものがあり、それらは個別にアップデートする必要があるみたい。


■ 2019.02.21

■ いろいろ (2019.02.21)
(various)

WinRAR

2019.03.18 追記:

Linux Kernel

systemd

VMware Integrated OpenStack with Kubernetes, PKS, vCloud Director Container Service Extension, vSphere Integrated Containers


■ 2019.02.20

■ 追記

WordPress 5.0.1 Security Release (2018.12.17)

 WordPress 5.0.0 Remote Code Execution (RIPS Technologies, 2019.02.19)。WordPress 4.9.9 / 5.0.1 で修正された、「投稿者が特別に細工された入力を使うことで、権限のない投稿タイプの投稿を作成できてしまう」件について。またこの他に Path Traversal な欠陥が、修正されずに残っているのだという。

This blog post detailed a Remote Code Execution in the WordPress core that was present for over 6 years. It became non-exploitable with a patch for another vulnerability reported by RIPS in versions 5.0.1 and 4.9.9. However, the Path Traversal is still possible and can be exploited if a plugin is installed that still allows overwriting of arbitrary Post Data. Since certain authentication to a target WordPress site is needed for exploitation, we decided to make the vulnerability public after 4 months of initially reporting the vulnerabilities.

顧客情報、令状なく取得 検察、方法記すリスト共有 (2019.01.22)

 関連:


■ 2019.02.19

■ 追記

総務省 IoT機器に無差別侵入し調査へ 前例ない調査に懸念も (2019.01.26)

 関連:

2019 年 2 月のセキュリティ更新プログラム (月例) (2019.02.13)

 Windows 10 Version 1809 / Server 2019 用の累積更新プログラム KB4487044 で、元号がらみの不具合発生だそうです。


■ 2019.02.18

■ 追記

Firefox 65.0 / ESR 60.5.0 公開 (2019.01.30)

 Thunderbird 60.5.1 も出ています。

韓国でSNIフィールドを使った特定サイトの接続遮断が始まる (2019.02.14)

 政府によるインターネットの検閲とSNIについて (catatsuy / medium.com, 2019.02.16)。本件についての包括的な解説。


■ 2019.02.15


■ 2019.02.14

■ 韓国でSNIフィールドを使った特定サイトの接続遮断が始まる
(スラド, 2019.02.13)

 韓国、2019.02.12 から、暗号化されていない SNI フィールドを用いて https の遮断を実施。

 対抗策としては DNS 暗号化 (DNS over TLS/DTLS/HTTPS) + SNI 暗号化 (encrypted SNI) が考えられるが、encrypted SNI は TLS 1.3 拡張へ向けて提案中の段階。

2019.02.18 追記:

 政府によるインターネットの検閲とSNIについて (catatsuy / medium.com, 2019.02.16)。本件についての包括的な解説。


■ 2019.02.13

■ Adobe 方面 (Flash Player, ColdFusion, Acrobat and Reader, Creative Cloud Desktop Application)
(Adobe, 2019.02.12)

 Priority は 2 (Flash Player, ColdFusion, Acrobat and Reader) あるいは 3 (Linux 用 Flash Player, Creative Cloud Desktop Application)。

■ いろいろ (2019.02.13)
(various)

runc, LXC

2019.02.14 追記:
2019.03.06 追記:

WebKitGTK+, WPE WebKit

Cisco Network Assurance Engine

Joomla

Django

Traq

Intel

■ 追記

Firefox 65.0 / ESR 60.5.0 公開 (2019.01.30)

 Firefox 65.0.1 / ESR 60.5.1 が出ました。セキュリティ修正を含みます。

■ 2019 年 2 月のセキュリティ更新プログラム (月例)
(Microsoft, 2019.02.13)

 はい月例来ました。IE / Edge, Windows, Office, ChakraCore, .NET Framework, Flash Player, Exchange, Visual Studio, Azure IoT SDK, Microsoft Dynamics, Team Foundation Server, Visual Studio Code 。

 0-day があるそうです。

 関連:

2019.02.18 追記:

 マイクロソフト月例パッチ(Microsoft Patch Tuesday)- 2019 年 2 月 (シマンテック, 2019.02.13)

2019.02.19 追記:

 Windows 10 Version 1809 / Server 2019 用の累積更新プログラム KB4487044 で、元号がらみの不具合発生だそうです。


■ 2019.02.12


■ 2019.02.08

■ 追記

FaceTimeのバグであなたのマイクロフォンとカメラを誰でも盗聴盗視可能に (2019.01.29)

 iOS 12.1.4、macOS Mojave 10.14.3 Supplemental Update で修正されました。

■ Chrome Stable Channel Update for Desktop
(Google, 2019.02.06)

 Chrome 72.0.3626.96 公開。1 件のセキュリティ修正が含まれる。


■ 2019.02.07


■ 2019.02.06

■ いろいろ (2019.02.06)
(various)

LibreOffice

curl

Android

Dovecot

  • [Dovecot-news] Release notify (2.2.36.1 and 2.3.4.1) (dovecot, 2019.02.05)

    * CVE-2019-3814: If imap/pop3/managesieve/submission client has trusted certificate with missing username field (ssl_cert_username_field), under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing.
    * ssl_cert_username_field setting was ignored with external SMTP AUTH, because none of the MTAs (Postfix, Exim) currently send the cert_username field. This may have allowed users with trusted certificate to specify any username in the authentication. This bug didn't affect Dovecot's Submission service.
  • CVE-2019-3814: Suitable client certificate can be used to login as other user (oss-sec ML, 2019.02.05)

    Vulnerable versions: 1.1.0 - 2.2.36 and 2.3.0 - 2.3.4

    欠陥が影響するのは、以下を設定している場合だそうです:

    auth_ssl_require_client_cert = yes
    auth_ssl_username_from_cert = yes

    発見者には $1000 が支払われています。 dovecot (hackerone) を見ると $1000 は High と Medium の間で、 $1000 はこれまでで最高の賞金だったようです。


■ 2019.02.05


■ 2019.02.04

■ いろいろ (2019.02.04)
(various)

Go 言語

■ 追記

Firefox 65.0 / ESR 60.5.0 公開 (2019.01.30)

 New Release: Tor Browser 8.0.5 (Tor Project, 2019.01.29)。Firefox ESR 60.5.0 対応など。 iida さん情報ありがとうございます。


■ 2019.02.01


[セキュリティホール memo]
[私について]