Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2015-12-22

This SRU number: 2015-12-22-001
Previous SRU number: 2015-12-21-003

Applies to:

This SEU number: 1401
Previous SEU: 1400

Applies to:

This is the complete list of rules modified in SRU 2015-12-22-001 and SEU 1401.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
115995FILE-MULTIMEDIAMicrosoft Windows DirectX malformed mjpeg arbitrary code execution attemptoffoffoff
135062MALWARE-CNCLinux.Backdoor.Powbot inbound variant connection offdropdrop
135063MALWARE-CNCLinux.Backdoor.Powbot inbound variant connection offdropdrop
335897SERVER-OTHERIBM Tivoli Storage Manager FastBack command injection attemptdropdropdrop
335898SERVER-OTHERIBM Tivoli Storage Manager FastBack buffer overflow attemptdropdropdrop
335909SERVER-OTHERSiemens Desigo Insight buffer overflow attemptdropdropdrop
335910SERVER-OTHERSiemens Desigo Insight information disclosure attemptdropdropdrop
335926SERVER-WEBAPPOracle Identity Management authorization bypass attemptdropdropdrop
335927SERVER-WEBAPPOracle Identity Management remote file execution attemptdropdropdrop