Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-09-08

This SRU number: 2016-09-07-001
Previous SRU number: 2016-09-06-001

Applies to:

This SEU number: 1541
Previous SEU: 1540

Applies to:

This is the complete list of rules modified in SRU 2016-09-07-001 and SEU 1541.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
136952FILE-OTHERMicrosoft Windows Font Viewer cmap offset integer underflow attemptoffdropdrop
136953FILE-OTHERMicrosoft Windows Font Viewer cmap offset integer underflow attemptoffdropdrop
139112FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139113FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139114FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139115FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139136FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139137FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139138FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139139FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139140FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139141FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139142FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139143FILE-IMAGEAdobe Pro DC Exif ModifyDate metadata memory corruption attemptoffoffdrop
139144FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139145FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139146FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139147FILE-IMAGEAdobe Pro DC Exif Software metadata memory corruption attemptoffoffdrop
139826BROWSER-IEMicrosoft Internet Explorer CStr internal string use-after-free attemptoffdropdrop
139827BROWSER-IEMicrosoft Internet Explorer CStr internal string use-after-free attemptoffdropdrop