Masaca's Blog 2



2008-09-29 18:10:05 | Weather
2008-09-25 06:20:42


2008-09-29 18:10:05


2008-09-29 18:07:22 | Weather



2008-09-29 12:41:22 | Health





2008-09-29 06:34:25 | Weblog

















2008-09-26 20:09:06 | Weblog






2008-09-26 19:39:45 | Swimming
  • 1,000 m Free ×2
  • 100 m Free ×3
  • 100 m Breast ×1
  • 100 m Individual medley ×1
  • 100 m Tread Water ×1
合計2,600 mでした。

ていうか書き忘れていました。久しぶりにHSさんから「行こうか」と誘われまして、喜び勇んで行ってきました。前回よりも距離を泳ぐのが多少楽に感じたので。1,000 mを二本ほどと100 mを数本、あとは隣の規制のないエリアに移動して巻き足を100 mやって終了。みっちりと泳ぎました。しかも、100 mの一本はダッシュ&スローをやった上に個メまでやったので、翌日には胸筋の筋肉痛…。けど、久しぶりに気持ちよく泳げました。玉に瑕なのは、帰りのバスと電車で異様に眠いこと…

本日の距離:2.5 km
YKでの累計の距離:5.1 km

Java for Mac OS X 10.4, Release 7

2008-09-25 06:35:02 | Apple
Java for Mac OS X 10.4, Release 7がソフトウェア・アップデート経由で出ているようです。
以下、Apple Product Securityからのメールを引用。

APPLE-SA-2008-09-24 Java for Mac OS X 10.4, Release 7

Java for Mac OS X 10.4, Release 7 is now available and addresses the following issues:

CVE-ID: CVE-2008-3637
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: An error checking issue leading to the use of an uninitialized variable exists in the Hash-based Message
Authentication Code (HMAC) provider used for generating MD5 and SHA-1 hashes. Visiting a website containing a maliciously crafted Java applet may lead to arbitrary code execution. This update addresses the issue through improved error handling. This is an Apple-specific issue. Credit to Radim Marek for reporting this issue.

CVE-ID: CVE-2008-1185, CVE-2008-1186, CVE-2008-1187, CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1192, CVE-2008-1195, CVE-2008-1196, CVE-2008-3104, CVE-2008-3107, CVE-2008-3108, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: Multiple vulnerabilities in Java 1.4.2_16
Description: Multiple vulnerabilities exist in Java 1.4.2_16, the most serious of which may allow untrusted Java applets to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution. These issues are addressed by updating Java 1.4 to version 1.4.2_18. Further information is available via the Sun Java website at

CVE-ID: CVE-2008-1185, CVE-2008-1186, CVE-2008-1187, CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1192, CVE-2008-1193, CVE-2008-1194, CVE-2008-1195, CVE-2008-1196, CVE-2008-3103, CVE-2008-3104, CVE-2008-3107, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114, CVE-2008-3115
Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
Impact: Multiple vulnerabilities in Java 1.5.0_13
Description: Multiple vulnerabilities exist in Java 1.5.0_13, the most serious of which may allow untrusted Java applets to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution. These issues are addressed by updating Java 1.5 to version 1.5.0_16. Further information is available via the Sun Java website at

Java for Mac OS X 10.4, Release 7 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site:

The download file is named: "JavaForMacOSX10.4Release7.dmg"
Its SHA-1 digest is: 67d17ba3e854101d890633f507b4c02e031b3a05

Information will also be posted to the Apple Security Updates web site:

Java for Mac OS X 10.5 アップデート 2 1.0

2008-09-25 06:34:12 | Apple
Java for Mac OS X 10.5 アップデート 2 1.0がソフトウェア・アップデート経由で出ています。

Java for Mac OS X 10.5 アップデート 2 1.0 136 MB
Java for Mac OS X 10.5 アップデート 2 によって、Mac OS X 10.5.4 以降で動作する Java SE 6、J2SE 5.0、および J2SE 1.4.2 の信頼性と互換性が向上します。このリリースによって、Java SE 6 はバージョン 1.6.0_07 に、 J2SE 5.0 はバージョン 1.5.0_16 に、 J2SE 1.4.2 は 1.4.2_18 にアップデートされます。

このアップデートについて詳しくは、この Web サイトを参照してください:
以下、Apple Product Securityからのメールを引用。
APPLE-SA-2008-09-24 Java for Mac OS X 10.5 Update 2

Java for Mac OS X 10.5 Update 2 is now available and addresses the following issues:

CVE-ID: CVE-2008-3638
Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: The Java plug-in does not block applets from launching file:// URLs. Visiting a website containing a maliciously crafted Java applet may allow a remote attacker to launch local files, which may lead to arbitrary code execution. This update addresses the issue through improved handling of URLs. This is an Apple-specific issue. Credit to Nitesh Dhanjani and Billy Rios for reporting this issue.

CVE-ID: CVE-2008-3637
Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Visiting a maliciously crafted website may lead to arbitrary code execution
Description: An error checking issue leading to the use of an uninitialized variable exists in the Hash-based Message Authentication Code (HMAC) provider used for generating MD5 and SHA-1 hashes. Visiting a website containing a maliciously crafted Java applet may lead to arbitrary code execution. This update addresses the issue through improved error handling. This is an Apple-specific issue. Credit to Radim Marek for reporting this issue.

CVE-ID: CVE-2008-1185, CVE-2008-1186, CVE-2008-1187, CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1192, CVE-2008-1195, CVE-2008-1196, CVE-2008-3104, CVE-2008-3107, CVE-2008-3108, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114
Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Multiple vulnerabilities in Java 1.4.2_16
Description: Multiple vulnerabilities exist in Java 1.4.2_16, the most serious of which may allow untrusted Java applets to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution. These issues are addressed by updating Java 1.4 to version 1.4.2_18. Further information is available via the Sun Java website at

CVE-ID: CVE-2008-1185, CVE-2008-1186, CVE-2008-1187, CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1192, CVE-2008-1193, CVE-2008-1194, CVE-2008-1195, CVE-2008-1196, CVE-2008-3103, CVE-2008-3104, CVE-2008-3107, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114, CVE-2008-3115
Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Multiple vulnerabilities exist in Java 1.5.0_13
Description: Multiple vulnerabilities in Java 1.5.0_13, the most serious of which may allow untrusted Java applets to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution. These issues are addressed by updating Java 1.5 to version 1.5.0_16. Further information is available via the Sun Java website at

CVE-ID: CVE-2008-3103, CVE-2008-3104, CVE-2008-3105, CVE-2008-3106, CVE-2008-3107, CVE-2008-3109, CVE-2008-3110, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114, CVE-2008-3115
Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Multiple vulnerabilities in Java 1.6.0_05
Description: Multiple vulnerabilities exist in Java 1.6.0_05, the most serious of which may allow untrusted Java applets to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution. These issues are addressed by updating Java 1.6 to version 1.6.0_07. Further information is available via the Sun Java website at

Available for: Mac OS X v10.5.4 and later, Mac OS X Server v10.5.4 and later
Impact: Limited ability of applications to use stronger cryptographic keys
Description: The default jurisdiction policy distributed with Java 1.5 on Mac OS X v10.5 restricts the maximum strength of cryptographic keys supported in Java Cryptography Extension (JCE) to 128 bits. This update addresses the issue by changing the default jurisdiction policy to the unlimited strength version. Credit to Bruno Harbulot of the University of Manchester for reporting this issue.

Java for Mac OS X 10.5 Update 2 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site:

The download file is named: "JavaForMacOSX10.5Update2.dmg"
Its SHA-1 digest is: 5b2a8de347fe68d0638bcf0ede8a71ba35adbab9

Information will also be posted to the Apple Security Updates web site:

Apple 超コンパクト USB 電源アダプタ交換プログラム

2008-09-20 18:17:24 | Apple
Apple iPhone 3Gに付属する超コンパクトUSB電源アダプタがリコールされているようです。以下、Apple 超コンパクト USB 電源アダプタ交換プログラムの記載を引用。

Apple 超コンパクト USB 電源アダプタ交換プログラム


本日、アップルは Apple 超コンパクト USB 電源アダプタ交換プログラムを発表いたしました。

アップルでは、特定の状況下において Apple 超コンパクト USB 電源アダプタのプラグ部分(金属製の差し込み部分)が外れて電源コンセント内に残り、それによって感電の原因となる可能性があることを確認いたしました。販売済み製品のごく一部にこの問題が発生したとの報告がありましたが、それによって人体に危害がおよんだという報告は現時点では入っておりません。

超コンパクト USB 電源アダプタは、下記の国で販売されたすべての iPhone 3G に付属しています。また、アクセサリとして別途ご購入いただいた場合もあります。
  • 米国
  • 日本
  • カナダ
  • メキシコ
  • 中南米諸国(詳しくはこちらをクリックしてください)

    注:上記以外の国で販売された初代 iPhone または iPhone 3G に付属の Apple USB 電源アダプタには問題はありません。



    当面は、お使いの iPhone 3G を USB ケーブルでコンピュータに接続するか、または通常サイズの Apple USB 電源アダプタ(プラグ部分が折り畳み式になっているもの)を使って充電してください。

  • iPhone 3Gをご利用の方は、交換方法などを当該ページにて直接ご確認ください。


    2008-09-20 18:05:51 | Weather



    2008-09-20 12:19:25 | Health



    Apple Remote Desktop 3.2.2 クライアントアップデート

    2008-09-17 06:34:56 | Apple
    Apple Remote Desktop クライアントアップデート 3.2.2がソフトウェア・アップデート経由で出ています。

    Apple Remote Desktop クライアントアップデート 3.2.2 4.4 MB
    3.2.2 アップデートは、全体的な信頼性とセキュリティに関するいくつかの問題を解決します。すべての Apple Remote Desktop クライアントにこのアップデートを推奨します。
    以下、Apple Product Securityからのメールを引用。
    APPLE-SA-2008-09-16 Apple Remote Desktop 3.2.2

    Apple Remote Desktop 3.2.2 is now available and addresses the following issue:

    Apple Remote Desktop
    CVE-ID: CVE-2008-2830
    Available for: Apple Remote Desktop 3.2.1, Mac OS X v10.3 through v10.5.5, Mac OS X Server v10.3 through v10.5.5
    Impact: A local user may execute commands with elevated privileges unless Security Update 2008-005 has been installed
    Description: A design issue exists in the Open Scripting Architecture libraries when determining whether to load scripting addition plugins into applications running with elevated privileges. This update mitigates the issue for Apple Remote Desktop by disabling scripting of ARDAgent. This issue does not affect systems that have installed Security Update 2008-005. Credit to Charles Srstka for reporting this issue.

    Apple Remote Desktop 3.2.2 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site:

    For Apple Remote Desktop 3.2.2 Client
    The download file is named: "RemoteDesktopClient.dmg"
    Its SHA-1 digest is: b1a81f17724d9b2f7b6dbffed56bc9a0463d1d7e

    For Apple Remote Desktop 3.2.2 Admin
    The download file is named: "RemoteDesktopAdmin322.dmg"
    Its SHA-1 digest is: d9657c10ed4bc29cfe8cc64e0727ffd4ed8a1425

    Information will also be posted to the Apple Security Updates web site:

    デジタルカメラ RAW互換性アップデート 2.2

    2008-09-17 06:29:58 | Apple
    デジタルカメラ RAW互換性アップデート 2.2がソフトウェア・アップデート経由で出ています。

    デジタルカメラ RAW互換性アップデート 2.2 4.1 MB
    このアップデートは、Aperture 2 および iPhoto ’08 の RAW ファイル互換性を拡張し、以下のカメラに対応します:

    Canon EOS Digital Rebel XS/Kiss Digital F/1000D
    Kodak DCS Pro SLR/n
    Nikon D700
    Olympus EVOLT E-420
    Olympus EVOLT E-520
    Olympus SP-570
    Samsung GX-10
    Samsung GX-20
    Sony DSLR-A300
    Sony DSC-R1


    2008-09-16 18:07:58 | Health




    Mac OS X アップデート 10.5.5

    2008-09-16 06:33:38 | Apple
    Mac OS X アップデート 10.5.5がソフトウェア・アップデート経由で出ています。

    Mac OS X アップデート 10.5.5 136 MB
    10.5.5 アップデートは、Mac OS X Leopard を使用しているすべてのユーザにお勧めします。お使いの Mac の安定性、互換性、およびセキュリティを向上させるオペレーティングシステムの全般的な修正が含まれています。

    このアップデートについて詳しくは、次の Web サイトを参照してください:
    セキュリティアップデートについて詳しくは、次の Web サイトを参照してください:
    以下、Apple Product Securityからのメールを項目のみ引用。
    APPLE-SA-2008-09-15 Mac OS X v10.5.5 and Security Update 2008-006

    Mac OS X v10.5.5 and Security Update 2008-006 are now available and address the following issues:

    CVE-ID: CVE-2008-2305
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Viewing a document containing a maliciously crafted font may lead to arbitrary code execution

    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: BIND is updated to address performance issues

    CVE-ID: CVE-2008-1100, CVE-2008-1387, CVE-2008-0314, CVE-2008-1833, CVE-2008-1835, CVE-2008-1836, CVE-2008-1837, CVE-2008-2713, CVE-2008-3215
    Available for: Mac OS X Server v10.4.11, Mac OS X Server v10.5 through v10.5.4
    Impact: Multiple vulnerabilities in ClamAV 0.92.1

    Directory Services
    CVE-ID: CVE-2008-2329
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: A person with access to the login screen may be able to list user names

    Directory Services
    CVE-ID: CVE-2008-2330
    Available for: Mac OS X Server v10.4.11, Mac OS X Server v10.5 through v10.5.4
    Impact: A local user may obtain the server password if an OpenLDAP system administrator runs slapconfig

    CVE-ID: CVE-2008-2331
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: The Get Info window may not display the actual privileges for a file

    CVE-ID: CVE-2008-3613
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: An attacker with access to the local network may cause a denial of service

    CVE-ID: CVE-2008-2327
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution

    CVE-ID: CVE-2008-2332
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution

    CVE-ID: CVE-2008-3608
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Viewing a large maliciously crafted JPEG image may lead to an unexpected application termination or arbitrary code execution

    CVE-ID: CVE-2008-1382
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: libpng in ImageIO is updated to version 1.2.29

    CVE-ID: CVE-2008-3609
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Files may be accessed by a local user who does not have the proper permissions

    CVE-ID: CVE-2008-1447
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: libresolv is susceptible to DNS cache poisoning and may return forged information

    Login Window
    CVE-ID: CVE-2008-3610
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: A user may log in without providing a password

    Login Window
    CVE-ID: CVE-2008-3611
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
    Impact: A person with access to the login screen may be able to change a user's password

    CVE-ID: CVE-2008-1447
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: mDNSResponder is susceptible to DNS cache poisoning and may return forged information

    CVE-ID: CVE-2008-1483, CVE-2008-1657
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Multiple vulnerabilities in OpenSSH, the most serious of which is local X11 session control

    QuickDraw Manager
    CVE-ID: CVE-2008-3614
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution

    CVE-ID: CVE-2008-2376
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Running a Ruby script that uses untrusted input as the arguments to the Array#fill method may lead to an unexpected application termination or arbitrary code execution

    CVE-ID: CVE-2008-3616
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Applications passing untrusted input to the SearchKit API may lead to an unexpected application termination or arbitrary code execution

    System Configuration
    CVE-ID: CVE-2008-2312
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11
    Impact: A local user may obtain the PPP password

    System Preferences
    CVE-ID: CVE-2008-3617
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Users may be misled into believing their passwords are stronger than they are

    System Preferences
    CVE-ID: CVE-2008-3618
    Available for: Mac OS X v10.5 through v10.5.4
    Impact: Authenticated users may have unexpected remote access to files and directories

    Time Machine
    CVE-ID: CVE-2008-3619
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Backing up a system with Time Machine may lead to the disclosure of sensitive information

    CVE-ID: CVE-2008-3621
    Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: Videoconferencing with a malicious user may lead to an unexpected application termination or arbitrary code execution

    Wiki Server
    CVE-ID: CVE-2008-3622
    Available for: Mac OS X v10.5 through v10.5.4, Mac OS X Server v10.5 through v10.5.4
    Impact: A remote attacker may cause persistent JavaScript injection on a Wiki server

    Mac OS X v10.5.5 and Security Update 2008-006 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site:

    The Software Update utility will present the update that applies to your system configuration. Only one is needed, either Mac OS X v10.5.5 or Security Update 2008-006.

    For Mac OS X v10.5.4
    The download file is named: "MacOSXUpd10.5.5.dmg"
    Its SHA-1 digest is: bd9bf9304a5b3162f391233fe74fc64f6dbc2bf5

    For Mac OS X v10.5 - v10.5.3
    The download file is named: "MacOSXUpdCombo10.5.5.dmg"
    Its SHA-1 digest is: 91ac9b720ba3b4166e5dc1dd518b1651d77c0f46

    For Mac OS X Server v10.5.4
    The download file is named: "MacOSXServerUpd10.5.5.dmg"
    Its SHA-1 digest is: 00264fd6990b568b5017f1244820d1eeebda8ab2

    For Mac OS X Server v10.5 - v10.5.3
    The download file is named: "MacOSXServerUpdCombo10.5.5.dmg"
    Its SHA-1 digest is: cc463a4f2b2d2079fca56704057f407f86b96661

    For Mac OS X v10.4.11 (Intel)
    The download file is named: "SecUpd2008-006Intel.dmg"
    Its SHA-1 digest is: c64a7aa8b13377b2066110fa86b4f879e0ca746b

    For Mac OS X v10.4.11 (PowerPC)
    The download file is named: "SecUpd2008-006PPC.dmg"
    Its SHA-1 digest is: 61898bf315d04958aaf487bb92ba257d059a33ce

    For Mac OS X Server v10.4.11 (Universal)
    The download file is named: "SecUpdSrvr2008-006Univ.dmg"
    Its SHA-1 digest is: 0309967cb7e6ae990bd3726e8af4abfeca776b63

    For Mac OS X Server v10.4.11 (PowerPC)
    The download file is named: "SecUpdSrvr2008-006PPC.dmg"
    Its SHA-1 digest is: 61898bf315d04958aaf487bb92ba257d059a33ce

    Information will also be posted to the Apple Security Updates web site: