Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-11-03

This SRU number: 2016-11-02-001
Previous SRU number: 2016-11-01-001

Applies to:

This SEU number: 1567
Previous SEU: 1566

Applies to:

This is the complete list of rules added in SRU 2016-11-02-001 and SEU 1567.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140613SERVER-WEBAPPOracle Application Testing Suite authentication bypass attemptoffoffoff
140614SERVER-WEBAPPOracle Application Testing Suite authentication bypass attemptoffoffoff
140615SERVER-WEBAPPOracle Application Testing Suite authentication bypass attemptoffoffoff
140616SERVER-WEBAPPOracle Application Testing Suite authentication bypass attemptoffoffoff
140617SERVER-WEBAPPOracle Application Testing Suite authentication bypass attemptoffoffoff
140618FILE-PDFAdobe Reader XML Metadata memory corruption attemptoffdropdrop
140619FILE-PDFAdobe Reader XML Metadata memory corruption attemptoffdropdrop
140620FILE-OFFICEMicrosoft Office RTF WRAssembly CLSID ASLR bypass download attemptoffoffdrop
140621FILE-OFFICEMicrosoft Office RTF WRLoader ASLR bypass download attemptoffoffdrop
140622FILE-OFFICEMicrosoft Office RTF WRLoader CLSID ASLR bypass download attemptoffoffdrop
140623FILE-OFFICEMicrosoft Office RTF hex encoded WRLoader ASLR bypass download attemptoffoffdrop
140624FILE-OFFICEMicrosoft Office RTF hex encoded wrLoader ASLR bypass download attemptoffoffdrop
140625FILE-OFFICEMicrosoft Office RTF WRAssembly CLSID ASLR bypass download attemptoffoffdrop
140626FILE-OFFICEMicrosoft Office RTF WRLoader ASLR bypass download attemptoffoffdrop
140627FILE-OFFICEMicrosoft Office RTF WRLoader CLSID ASLR bypass download attemptoffoffdrop
140628FILE-OFFICEMicrosoft Office RTF hex encoded WRAsembly ASLR bypass download attemptoffoffdrop
140629FILE-OFFICEMicrosoft Office RTF hex encoded WRAssembly ASLR bypass download attemptoffoffdrop
140630FILE-OFFICEMicrosoft Office RTF hex encoded WRLoader ASLR bypass download attemptoffoffdrop
140631FILE-OFFICEMicrosoft Office RTF hex encoded wrLoader ASLR bypass download attemptoffoffdrop
140632FILE-OFFICEMicrosoft Office RTF hex encoded WRAssembly CLSID ASLR bypass download attemptoffoffdrop
140633FILE-OFFICEMicrosoft Office RTF hex encoded WRLoader CLSID ASLR bypass download attemptoffoffdrop
140634FILE-OFFICEMicrosoft Office RTF hex encoded WRAssembly CLSID ASLR bypass download attemptoffoffdrop
140635FILE-OFFICEMicrosoft Office RTF hex encoded WRLoader CLSID ASLR bypass download attemptoffoffdrop
340637POLICY-OTHERTL1 ACT-USER login detectedoffoffoff
340638PROTOCOL-VOIPCisco Meeting Server SIP SDP media description buffer overflow attemptoffoffdrop
140639FILE-PDFAdobe Acrobat Reader XFA addInstance use after free attemptoffdropdrop
140640FILE-PDFAdobe Acrobat Reader XFA addInstance use after free attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
340636POLICY-OTHERCisco Prime Home API insecure SSO authentication detectedoffoffoff

Updated Rules:

Updated rules can be found at this link.