概要
TA04-315A は、Microsoft Internet Explorer HTML elements の脆弱性に関するものでした。
この脆弱性に対する更新プログラムは、Microsoft Security Bulletin MS04-040 に含まれます。
影響を受けるシステム
- Microsoft Windows NT Server 4.0 Service Pack 6a
- Microsoft Windows NT Server 4.0 Terminal Server Edition, Service Pack 6
- Microsoft Windows 2000 Service Pack 3, Service Pack 4
- Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1
- Microsoft Windows 98、Microsoft Windows 98 Second Edition (SE)
- Microsoft Windows Millennium Edition (Me)
- Microsoft Windows 2000 Service Pack 3、Microsoft Windows 2000 Service Pack 4
または Microsoft Windows XP Service Pack 1 上の Internet Explorer 6 Service Pack 1 - Microsoft Windows NT Server 4.0 Service Pack 6a、
Microsoft Windows NT Server 4.0 Terminal Service Edition Service Pack 6、
Microsoft Windows 98、Microsoft Windows 98 SE、
Microsoft Windows Me 上の Internet Explorer 6 Service Pack 1 - Windows XP Service Pack 1 (64-Bit Edition) 上の Internet Explorer 6
詳細情報
想定される影響
Web ページや HTML 形式の電子メールなどを経由して ログオンしているユーザの権限で任意のコードを実行する可能性があります。
対策方法
ベンダ情報
| ベンダ | リンク |
|---|---|
| 富士通 | TA04-336Aに対する富士通の情報 |
| 富士通 | TA04-336Aに対するSolaris OEの情報 |
| マイクロソフト | Internet Explorer 用の累積的なセキュリティ更新プログラム (889293) (MS04-040) |
参考情報
-
US-CERT Alert TA04-315A
Buffer Overflow in Microsoft Internet Explorer
JPCERT/CCからの補足情報
JPCERT/CCによる脆弱性分析結果
謝辞
関連文書
| JPCERT 緊急報告 | |
| JPCERT REPORT | |
| CERT Advisory |
Technical Cyber Security Alert TA04-336A Update for Microsoft Internet Explorer HTML Elements Vulnerability |
| CPNI Advisory | |
| TRnotes | |
| CVE | |
| JVN iPedia |