Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-09-18

This SRU number: 2014-09-17-002
Previous SRU number: 2014-09-15-001

Applies to:

This SEU number: 1172
Previous SEU: 1170

Applies to:

This is the complete list of rules modified in SRU 2014-09-17-002 and SEU 1172.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
120534FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
122077FILE-OFFICEMicrosoft Office Excel ObjectLink invalid wLinkVar2 value attemptoffdropdrop
127858FILE-OFFICEMicrosoft Office Word malformed OCXINFO element EoP attemptoffdropdrop
127859FILE-OFFICEMicrosoft Office Word malformed OCXINFO element EoP attemptoffdropdrop
127945FILE-OFFICEMicrosoft Office Excel ObjectLink invalid wLinkVar2 value attemptoffdropdrop
128205FILE-OFFICEMicrosoft Office Word 2003 macro byte opcode large data structure arbitrary code execution attemptoffdropdrop
128206FILE-OFFICEMicrosoft Office Word 2003 macro byte opcode large data structure arbitrary code execution attemptoffdropdrop
128549FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
128550FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
129723FILE-OFFICEMicrosoft Office Word invalid sprmPNumRM recordoffoffdrop
129724FILE-OFFICEMicrosoft Office Word invalid sprmPNumRM recordoffoffdrop
129725FILE-OFFICEMicrosoft Office Word invalid sprmPNumRM recordoffoffdrop
129726FILE-OFFICEMicrosoft Office Word invalid sprmPNumRM recordoffoffdrop
131125FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
131126FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
131127FILE-OFFICEMicrosoft Office Excel rtToolbarDef record integer overflow attemptoffoffoff
131276EXPLOIT-KITCottonCastle exploit kit Adobe flash outbound connectiondropdropdrop
131712MALWARE-CNCWin.Trojan.Ragua variant outbound connectionoffdropdrop
131713MALWARE-CNCWin.Trojan.Ragua variant outbound connectionoffdropdrop
131714MALWARE-CNCWin.Trojan.Ragua variant outbound connectionoffdropdrop
131751FILE-OFFICEMicrosoft Office Outlook mailto injection attemptoffoffoff
131752FILE-OFFICEMicrosoft Office Outlook mailto injection attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
126379SERVER-OTHERSquid proxy Accept-Language denial of service attemptoffoffoff
330884PROTOCOL-VOIPCisco MXP Telepresence gssapi-data unauthenticated denial of service attemptoffoffoff