Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-10-20

This SRU number: 2016-10-20-001
Previous SRU number: 2016-10-17-001

Applies to:

This SEU number: 1559
Previous SEU: 1557

Applies to:

This is the complete list of rules added in SRU 2016-10-20-001 and SEU 1559.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140493SERVER-WEBAPPEktron ServerControlWS.asmx XSL transform code injection attemptoffoffdrop
140494SERVER-WEBAPPWordpress Symposium PHP file upload attemptoffdropdrop
140495FILE-FLASHAdobe Standalone Flash Player PSDK FlashRuntime mediaplayer pause attemptoffdropdrop
140496FILE-FLASHAdobe Standalone Flash Player PSDK FlashRuntime mediaplayer pause attemptoffdropdrop
140497SERVER-WEBAPPWordPress Plugin RevSlider file upload attemptoffdropdrop
340498SERVER-WEBAPPCisco ASA Crypto CA Server out of bounds read attemptoffoffdrop
340499SERVER-OTHERCisco ASA NBSTAT response stack buffer overflow attemptoffdropdrop
140500MALWARE-CNCAndr.Tool.Snowfox Androidbauts/snowfox outbound connectionoffdropdrop
140501MALWARE-CNCAndr.Tool.Snowfox Androidbauts/snowfox outbound connectionoffdropdrop
140502FILE-FLASHAdobe Flash Player QOSProvider use-after-free attemptoffdropdrop
140503FILE-FLASHAdobe Flash Player QOSProvider use-after-free attemptoffdropdrop
140505FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140506FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140507FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140508FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140509FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140510FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140511FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140512FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140513FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140514FILE-PDFAdobe Reader XSLT Transform use after free attemptoffdropdrop
140515FILE-PDFAdobe Acrobat Reader malformed unicode font name code execution attemptoffdropdrop
140516FILE-PDFAdobe Acrobat Reader malformed unicode font name code execution attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
340504SERVER-OTHERCisco Snort HTTP chunked transfer encoding processing denial of service attemptoffoffoff
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140492PUA-ADWAREWin.Adware.DownloadManager outbound connectionoffoffoff

Updated Rules:

Updated rules can be found at this link.