Interstage HTTP Server: ログ機能におけるバッファオーバーフローの脆弱性 (2013年11月26日)


本セキュリティサイトについてのご注意

1. 脆弱性の説明

Interstage HTTP Serverのログ機能(ihsrlog/rotatelogs)において、バッファオーバーフローの脆弱性の問題が確認されました。

Interstageについては以下のページを参照してください。
http://www.fujitsu.com/jp/products/software/middleware/business-middleware/interstage/

富士通は、3.に示すセキュリティパッチを提供していますので、早急に適用する様にお願いします。

2. 脆弱性のもたらす脅威

悪意のある第三者によって、任意のコードが実行される可能性があります。

3. 該当システム・対策情報

3-1.該当システム

GP7000F, PRIMEPOWER, GP-S, PRIMERGY, GP5000, CELSIUS, FMVシリーズ, AT互換機, PRIMEQUEST, SPARC Enterprise

3-2.該当製品・対策Patch

Interstage Application Server
Interstage Studio
Interstage Web Server

Interstage Application Server
製品名バージョン対象OSパッケージ名Patch ID
Interstage Application Server Enterprise Edition[※a]V9.0.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2F3FMihsT001001WP-08
Interstage Application Server Enterprise EditionV9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT002174WP-06
Interstage Application Server Enterprise EditionV9.2.0/ V9.2.0AWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT004344WP-05
Interstage Application Server Enterprise EditionV9.3.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT004726WP-04
Interstage Application Server Enterprise EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT006036WP-02
Interstage Application Server Enterprise EditionV10.1.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Small Business Server 2011F3FMihsT006383WP-01
Interstage Application Server Standard-J Edition[※a]V9.0.0/ V9.0.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2F3FMihsT001001WP-08
Interstage Application Server Standard-J EditionV9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT002174WP-06
Interstage Application Server Standard-J EditionV9.2.0/ V9.2.0AWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT004344WP-05
Interstage Application Server Standard-J EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT006036WP-02
Interstage Application Server Standard-J EditionV10.1.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Small Business Server 2011F3FMihsT006383WP-01
Interstage Application Server Enterprise EditionV9.0.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2F3FMihsT001005IP-07
Interstage Application Server Enterprise EditionV9.1.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT002175IP-06
Interstage Application Server Enterprise EditionV9.2.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT004345IP-05
Interstage Application Server Standard-J EditionV9.0.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2F3FMihsT001005IP-07
Interstage Application Server Standard-J EditionV9.1.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT002175IP-06
Interstage Application Server Standard-J EditionV9.2.0Windows(IPF) Server 2003/ Windows(IPF) Server 2003 R2/ Windows(IPF) Server 2008F3FMihsT004345IP-05
Interstage Application Server Enterprise EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT004346XP-05
Interstage Application Server Enterprise EditionV9.3.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT005232XP-03
Interstage Application Server Enterprise EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT006037XP-02
Interstage Application Server Standard-J EditionV9.2.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT004346XP-05
Interstage Application Server Standard-J EditionV10.0.0Windows(EM64T) Server 2003/ Windows(EM64T) Server 2003 R2/ Windows(EM64T) Server 2008/ Windows(EM64T) Server 2008 R2F3FMihsT006037XP-02
Interstage Application Server Enterprise EditionV9.0.0/ V9.0.0BSolaris 9/ 10FJSVihsT001004SP-09
Interstage Application Server Enterprise EditionV9.1.0/ V9.1.0A/ V9.1.0BSolaris 9/ 10FJSVihsT002180SP-07
Interstage Application Server Enterprise EditionV9.2.0Solaris 9/ 10FJSVihsT004343SP-05
Interstage Application Server Enterprise EditionV9.3.0Solaris 9/ 10FJSVihsT005233SP-03
Interstage Application Server Enterprise EditionV10.0.0Solaris 9/ 10FJSVihsT006035SP-02
Interstage Application Server Standard-J EditionV9.0.0Solaris 9/ 10FJSVihsT001004SP-09
Interstage Application Server Standard-J EditionV9.1.0/ V9.1.0A/ V9.1.0BSolaris 9/ 10FJSVihsT002180SP-07
Interstage Application Server Standard-J EditionV9.2.0/ V9.2.0ASolaris 9/ 10FJSVihsT004343SP-05
Interstage Application Server Standard-J EditionV10.0.0Solaris 9/ 10FJSVihsT006035SP-02
Interstage Application Server Enterprise EditionV9.0.0/ V9.0.0B/ V9.0.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT001003LP-07
Interstage Application Server Enterprise EditionV9.1.0/ V9.1.0BRHEL-AS4(x86)/ AS4(EM64T)FJSVihsT002176LP-06
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT004338LP-05
Interstage Application Server Enterprise EditionV9.3.0/ V9.3.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT005234LP-03
Interstage Application Server Standard-J EditionV9.0.0/ V9.0.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT001003LP-07
Interstage Application Server Standard-J EditionV9.1.0/ V9.1.0BRHEL-AS4(x86)/ AS4(EM64T)FJSVihsT002176LP-06
Interstage Application Server Standard-J EditionV9.2.0/ V9.3.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT004338LP-05
Interstage Application Server Enterprise EditionV9.0.0/ V9.0.1/ V9.0.1BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT001044LP-07
Interstage Application Server Enterprise EditionV9.1.0/ V9.1.0BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT002177LP-06
Interstage Application Server Enterprise EditionV9.2.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT004339LP-05
Interstage Application Server Enterprise EditionV9.3.0/ V9.3.1RHEL5(x86)/ RHEL5(Intel64)FJSVihsT005235LP-03
Interstage Application Server Enterprise EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT006038LP-02
Interstage Application Server Standard-J EditionV9.0.0/ V9.0.0B/ V9.0.1/ V9.0.1BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT001044LP-07
Interstage Application Server Standard-J EditionV9.1.0/ V9.1.0BRHEL5(x86)/ RHEL5(Intel64)FJSVihsT002177LP-06
Interstage Application Server Standard-J EditionV9.2.0/ V9.3.1RHEL5(x86)/ RHEL5(Intel64)FJSVihsT004339LP-05
Interstage Application Server Standard-J EditionV10.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT006038LP-02
Interstage Application Server Enterprise EditionV9.3.1RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006033LP-02
Interstage Application Server Enterprise EditionV10.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006039LP-02
Interstage Application Server Standard-J EditionV9.3.1RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006033LP-02
Interstage Application Server Standard-J EditionV10.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006039LP-02
Interstage Application Server Enterprise Edition[※b]V9.0.0RHEL-AS4(IPF)FJSVihsT001002QP-07
Interstage Application Server Enterprise EditionV9.1.0RHEL-AS4(IPF)FJSVihsT002178QP-06
Interstage Application Server Enterprise EditionV9.2.0RHEL-AS4(IPF)FJSVihsT004340QP-05
Interstage Application Server Standard-J Edition[※b]V9.0.0RHEL-AS4(IPF)FJSVihsT001002QP-07
Interstage Application Server Standard-J EditionV9.1.0RHEL-AS4(IPF)FJSVihsT002178QP-06
Interstage Application Server Standard-J EditionV9.2.0RHEL-AS4(IPF)FJSVihsT004340QP-05
Interstage Application Server Enterprise Edition[※c]V9.0.0RHEL5(IPF)FJSVihsT001043QP-07
Interstage Application Server Enterprise EditionV9.1.0RHEL5(IPF)FJSVihsT002179QP-06
Interstage Application Server Enterprise EditionV9.2.0RHEL5(IPF)FJSVihsT004341QP-05
Interstage Application Server Standard-J Edition[※c]V9.0.0RHEL5(IPF)FJSVihsT001043QP-07
Interstage Application Server Standard-J EditionV9.1.0RHEL5(IPF)FJSVihsT002179QP-06
Interstage Application Server Standard-J EditionV9.2.0RHEL5(IPF)FJSVihsT004341QP-05
Interstage Application Server Enterprise EditionV9.2.0RHEL5(Intel64)FJSVihsT004342LP-05
Interstage Application Server Enterprise EditionV9.3.0/ V9.3.1RHEL5(Intel64)FJSVihsT005236LP-03
Interstage Application Server Enterprise EditionV10.0.0RHEL5(Intel64)FJSVihsT006040LP-02
Interstage Application Server Standard-J EditionV9.2.0/ V9.3.1RHEL5(Intel64)FJSVihsT004342LP-05
Interstage Application Server Standard-J EditionV10.0.0RHEL5(Intel64)FJSVihsT006040LP-02
Interstage Application Server Enterprise EditionV9.3.1RHEL6(Intel64)FJSVihsT006034LP-02
Interstage Application Server Enterprise EditionV10.0.0RHEL6(Intel64)FJSVihsT006041LP-02
Interstage Application Server Standard-J EditionV9.3.1RHEL6(Intel64)FJSVihsT006034LP-02
Interstage Application Server Standard-J EditionV10.0.0RHEL6(Intel64)FJSVihsT006041LP-02
Interstage Studio
製品名バージョン対象OSパッケージ名Patch ID
Interstage Studio Enterprise Edition[※a]V9.0.0/ V9.0.0A/ V9.0.1Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows XP/ Windows VistaF3FMihsT001001WP-08
Interstage Studio Enterprise EditionV9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows XP/ Windows VistaF3FMihsT002174WP-06
Interstage Studio Enterprise EditionV9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT004344WP-05
Interstage Studio Standard-J Edition[※a]V9.0.0/ V9.0.0A/ V9.0.1/ V9.0.1AWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows XP/ Windows VistaF3FMihsT001001WP-08
Interstage Studio Standard-J EditionV9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows XP/ Windows VistaF3FMihsT002174WP-06
Interstage Studio Standard-J EditionV9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT004344WP-05
Interstage Studio Standard-J EditionV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT006036WP-02
Interstage Studio Standard-J EditionV10.1.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7/ Windows Small Business Server 2011F3FMihsT006383WP-01
Interstage Studio with UML Modeling Tool[※a]V9.0.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows XP/ Windows VistaF3FMihsT001001WP-08
Interstage Studio with UML Modeling ToolV9.1.0/ V9.1.0BWindows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows XP/ Windows VistaF3FMihsT002174WP-06
Interstage Studio with UML Modeling ToolV9.2.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows XP/ Windows Vista/ Windows 7F3FMihsT004344WP-05
Interstage Web Server
製品名バージョン対象OSパッケージ名Patch ID
Interstage Web Server[※a]V9.0.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2F3FMihsT001001WP-08
Interstage Web ServerV9.1.0Windows 2000 Server/ Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT002174WP-06
Interstage Web ServerV10.0.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2F3FMihsT006036WP-02
Interstage Web ServerV10.1.0Windows Server 2003/ Windows Server 2003 R2/ Windows Server 2008/ Windows Server 2008 R2/ Windows Small Business Server 2011F3FMihsT006383WP-01
Interstage Web ServerV9.0.0Solaris 9/ 10FJSVihsT001004SP-09
Interstage Web ServerV9.1.0/ V9.1.0ASolaris 9/ 10FJSVihsT002180SP-07
Interstage Web ServerV10.0.0Solaris 9/ 10FJSVihsT006035SP-02
Interstage Web ServerV9.0.0/ V9.0.1RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT001003LP-07
Interstage Web ServerV9.1.0RHEL-AS4(x86)/ AS4(EM64T)FJSVihsT002176LP-06
Interstage Web ServerV9.0.0/ V9.0.1RHEL5(x86)/ RHEL5(Intel64)FJSVihsT001044LP-07
Interstage Web ServerV9.1.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT002177LP-06
Interstage Web ServerV10.0.0RHEL5(x86)/ RHEL5(Intel64)FJSVihsT006038LP-02
Interstage Web ServerV10.0.0RHEL6(x86)/ RHEL6(Intel64)FJSVihsT006039LP-02

[※a] T001001WP-01~07 を適用した場合のみ、本脆弱性に該当します。
[※b] T001002QP-01~06 を適用した場合のみ、本脆弱性に該当します。
[※c] T001043QP-01~06 を適用した場合のみ、本脆弱性に該当します。

パッチ入手に関しては、当社サポートセンターにお問い合わせください。

参考: 該当製品の確認方法

製品のバージョンを確認するには、製品に添付されている「ソフトウェア説明書」を参照してください。

3-3. 回避方法

    ありません。

4. 関連情報

    ありません。

5. 改版履歴

  • 2013年11月26日 新規掲載

ページの先頭へ