Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-03-28

This SRU number: 2017-03-27-002
Previous SRU number: 2017-03-22-001

Applies to:

This SEU number: 1638
Previous SEU: 1633

Applies to:

This is the complete list of rules modified in SRU 2017-03-27-002 and SEU 1638.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
134334EXPLOIT-KITFiesta exploit kit Adobe Reader exploit downloadoffoffoff
136968BROWSER-IEMicrosoft Internet Explorer CTableRow memory corruption attemptoffoffoff
136969BROWSER-IEMicrosoft Internet Explorer CTableRow memory corruption attemptoffoffoff
137045MALWARE-CNCWin.Trojan.Kovter outbound connectionoffdropdrop
139864FILE-PDFAdobe Reader CoolType engine FlateDecode use-after-free attemptoffdropdrop
139865FILE-PDFAdobe Reader CoolType engine FlateDecode use-after-free attemptoffdropdrop
340758SERVER-OTHERTRUFFLEHUNTER TALOS-2016-0231 attack attemptoffoffdrop
141527INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141530INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141533INDICATOR-COMPROMISESOCKS5 proxy inbound connection on non-standard portoffoffoff
141853OS-LINUXcURL and libcurl set-cookie remote code execution attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
340820SERVER-WEBAPPTRUFFLEHUNTER TALOS-2016-0239 attack attemptoffoffoff
340821SERVER-WEBAPPTRUFFLEHUNTER TALOS-2016-0241 attack attemptoffoffoff
340822SERVER-WEBAPPTRUFFLEHUNTER TALOS-2016-0241 attack attemptoffoffoff
342060SERVER-OTHERCisco IOS DHCP client dummy XID denial of service attemptoffoffdrop