Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-01-24

This SRU number: 2017-01-24-001
Previous SRU number: 2017-01-20-001

Applies to:

This SEU number: 1603
Previous SEU: 1601

Applies to:

This is the complete list of rules added in SRU 2017-01-24-001 and SEU 1603.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
341368FILE-OTHERTRUFFLEHUNTER TALOS-2017-0273 attack attemptoffoffoff
341369FILE-OTHERTRUFFLEHUNTER TALOS-2017-0273 attack attemptoffoffoff
341370FILE-OTHERTRUFFLEHUNTER TALOS-2016-0269 attack attemptoffdropdrop
341371FILE-OTHERTRUFFLEHUNTER TALOS-2016-0269 attack attemptoffdropdrop
341372FILE-IMAGEOracle Outside In libvs_gif out of bounds write attemptoffoffdrop
341373FILE-IMAGEOracle Outside In libvs_gif out of bounds write attemptoffoffdrop
141374MALWARE-CNCWin.Trojan.NetWiredRC variant registration messageoffoffdrop
141375MALWARE-CNCWin.Trojan.NetWiredRC variant check logsoffoffdrop
141376MALWARE-CNCWin.Trojan.NetWiredRC variant keepaliveoffoffdrop
141377BROWSER-IEMicrosoft Internet Explorer runtimeStyle use-after-free attemptoffoffoff
141378BROWSER-IEMicrosoft Internet Explorer runtimeStyle use-after-free attemptoffoffoff
141383SERVER-WEBAPPPHP ZipArchive getFromIndex and getFromName integer overflow attemptoffoffoff
141384SERVER-WEBAPPPHP ZipArchive getFromIndex and getFromName integer overflow attemptoffoffoff
141385BROWSER-IEMicrosoft Edge mutation event memory corruption attemptoffoffdrop
141386BROWSER-IEMicrosoft Edge mutation event memory corruption attemptoffoffdrop
141387SERVER-WEBAPPZyXEL P660HN ADSL Router logset.asp command injection attemptoffoffdrop
141388SERVER-WEBAPPZyXEL P660HN ADSL Router viewlog.asp command injection attemptoffoffdrop
141389POLICY-OTHERCisco Firepower Management Console rule import access detectedoffoffoff
141390SERVER-WEBAPPApache Commons Library FileUpload unauthorized Java object upload attemptoffdropdrop
141391FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141392FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141393FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141394FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141395FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141396FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141397FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141398FILE-IMAGEAdobe Acrobat TIFF ICC tag heap buffer overflow attemptoffdropdrop
141399FILE-PDFAdobe Acrobat Reader xfa subform use after free attemptoffdropdrop
141400FILE-PDFAdobe Acrobat Reader xfa subform use after free attemptoffdropdrop
141401SERVER-WEBAPPBillion 5200W ADSL Router adv_remotelog.asp command injection attemptoffoffdrop
141402SERVER-WEBAPPBillion 5200W ADSL Router tools_time.asp command injection attemptoffoffdrop
141403BLACKLISTUser-Agent known malicious user-agent string - Visbotoffdropdrop
141404SERVER-WEBAPPJoomla JCE multiple plugin arbitrary PHP file upload attemptoffoffoff
141405BROWSER-IEMicrosoft Internet Explorer object property change use after free attemptoffdropdrop
141406BROWSER-IEMicrosoft Internet Explorer object property change use after free attemptoffdropdrop
141407BROWSER-OTHERCisco WebEx extension command execution attemptoffdropdrop
141408BROWSER-OTHERCisco WebEx extension command execution attemptoffdropdrop
141409POLICY-OTHERCisco WebEx explicit use of web pluginoffoffoff
341410SERVER-WEBAPPTRUFFLEHUNTER TALOS-2016-0229 attack attemptoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141366SERVER-OTHERIBM Tivoli Storage Manager FastBack server denial of service attemptoffoffoff
341367SERVER-OTHERTRUFFLEHUNTER TALOS-2016-0260 attack attemptoffdropdrop
141379SERVER-OTHERSquid HTTP Vary response header denial of service attemptoffoffoff
141380SERVER-OTHEROpenLDAP BER Message denial of service attemptoffoffoff
141381SERVER-OTHEROpenLDAP BER Message denial of service attemptoffoffoff
141382SERVER-OTHEROpenLDAP BER Message denial of service attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.