Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-03-28

This SRU number: 2017-03-27-002
Previous SRU number: 2017-03-22-001

Applies to:

This SEU number: 1638
Previous SEU: 1633

Applies to:

This is the complete list of rules added in SRU 2017-03-27-002 and SEU 1638.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
135828FILE-OTHEROpenOffice Starview metafile arbitrary read write attemptoffoffoff
135829FILE-OTHEROpenOffice Starview metafile arbitrary read write attemptoffoffoff
136212FILE-OTHERLibgraphite LocaLookup out-of-bounds read attemptoffdropdrop
136213FILE-OTHERLibgraphite LocaLookup out-of-bounds read attemptoffdropdrop
136216FILE-OTHERlibgraphite TTF opcode handling out of bounds read attemptoffoffdrop
136217FILE-OTHERlibgraphite TTF opcode handling out of bounds read attemptoffoffdrop
136385FILE-OTHERSIL LibGraphite BracketPairStack out of bounds access exploit attemptoffdropdrop
136386FILE-OTHERSIL LibGraphite BracketPairStack out of bounds access exploit attemptoffdropdrop
136387FILE-OTHERLibgraphite context item handling arbitrary code execution attemptoffoffdrop
136388FILE-OTHERLibgraphite context item handling arbitrary code execution attemptoffoffdrop
137493FILE-OTHERlhasa decode_level3_header heap corruption attemptoffoffdrop
137494FILE-OTHERlhasa decode_level3_header heap corruption attemptoffoffdrop
137495FILE-PDFIBM Domino KeyView PDF filter compressed stream length code execution attemptoffoffoff
137496FILE-PDFIBM Domino KeyView PDF filter compressed stream length code execution attemptoffoffoff
137497FILE-PDFIBM Domino KeyView PDF filter encrypted stream code execution attemptoffoffoff
137498FILE-PDFIBM Domino KeyView PDF filter encrypted stream code execution attemptoffoffoff
137499FILE-PDFIBM Domino KeyView PDF Filter Basefont string overflow attemptoffoffoff
137500FILE-PDFIBM Domino KeyView PDF Filter Basefont string overflow attemptoffoffoff
137501FILE-PDFIBM Domino KeyView PDF Filter Trailer ID array heap buffer overflow attemptoffoffoff
137502FILE-PDFIBM Domino KeyView PDF Filter Trailer ID array heap buffer overflow attemptoffoffoff
137517FILE-OTHERApple OSX local privilege escalation attemptoffoffdrop
137518FILE-OTHERApple OSX local privilege escalation attemptoffoffdrop
137519FILE-OTHERIntel HD Graphics Windows kernel driver local privilege escalation attemptoffoffdrop
137520FILE-OTHERIntel HD Graphics Windows kernel driver local privilege escalation attemptoffoffdrop
137862FILE-PDFOracle Outside In libvs_pdf integer overflow attemptoffoffoff
137863FILE-PDFOracle Outside In libvs_pdf integer overflow attemptoffoffoff
137864FILE-PDFOracle Outside In libvs_pdf xref offset out of bounds read attemptoffoffoff
137865FILE-PDFOracle Outside In libvs_pdf xref offset out of bounds read attemptoffoffoff
137868FILE-PDFOracle Outside In libvs_pdf integer overflow attemptoffoffoff
137869FILE-PDFOracle Outside In libvs_pdf integer overflow attemptoffoffoff
138289FILE-PDFOracle IOT IX SDK libvs_pdf null pointer dereference attemptoffoffoff
138290FILE-PDFOracle IOT IX SDK libvs_pdf null pointer dereference attemptoffoffoff
138293FILE-OTHER7zip UDF partition reference out of bounds read attemptoffoffoff
138294FILE-OTHER7zip UDF partition reference out of bounds read attemptoffoffoff
138295FILE-OTHER7zip UDF partition reference out of bounds read attemptoffoffoff
138296FILE-OTHER7zip UDF partition reference out of bounds read attemptoffoffoff
138323FILE-OTHER7zip HFS+ handling heap buffer overflow attemptoffoffoff
138324FILE-OTHER7zip HFS+ handling heap buffer overflow attemptoffoffoff
138342FILE-PDFOracle Outside In libvs_pdf Root xref stack exhaustion attemptoffoffoff
138343FILE-PDFOracle Outside In libvs_pdf Root xref stack exhaustion attemptoffoffoff
138344SERVER-OTHERPidgin MXIT is operation null pointer dereference attemptoffoffoff
138345SERVER-OTHERPidgin MXIT is operation null pointer dereference attemptoffoffoff
138545SERVER-OTHERPidgin mxit_update_contact out of bounds read attemptoffoffoff
138546SERVER-OTHERPidgin MXIT table markup command out of bounds read attemptoffoffoff
138547SERVER-OTHERPidgin MXIT table markup command out of bounds read attemptoffoffoff
138548SERVER-OTHERPidgin MXIT protocol handling null pointer dereference attemptoffoffoff
138549SERVER-OTHERPidgin mxit_parse_cmd_extprofile out of bounds read attemptoffoffoff
138550SERVER-OTHERPidgin MXIT protocol handling splash_remove directory traversal attemptoffoffoff
138551SERVER-OTHERPidgin MXIT protocol handling splash_remove directory traversal attemptoffoffoff
138578SERVER-OTHERPidgin multimx_message_received out of bounds read attemptoffoffoff
138583SERVER-OTHERPidgin mxit_parse_cmd_suggestcontacts out of bounds read attemptoffoffoff
138627FILE-OTHERlibarchive zip_read_mac_metadata heap buffer overflow attemptoffoffdrop
138628FILE-OTHERlibarchive zip_read_mac_metadata heap buffer overflow attemptoffoffdrop
138856FILE-OTHERHancom Hangul HCell pConnectionSites OfficeArt record heap buffer overflow attemptoffoffoff
138857FILE-OTHERHancom Hangul HCell pVertices OfficeArt record heap buffer overflow attemptoffoffoff
138858FILE-OTHERHancom Hangul HCell pConnectionSites OfficeArt record heap buffer overflow attemptoffoffoff
138859FILE-OTHERHancom Hangul HCell pVertices OfficeArt record heap buffer overflow attemptoffoffoff
138860FILE-OTHEROracle OIT ContentAccess libvs_mwkd out of bounds write attemptoffdropdrop
138861FILE-OTHEROracle OIT ContentAccess libvs_mwkd out of bounds write attemptoffdropdrop
138867SERVER-OTHERPidgin mxit_chunk_parse_get_avatar out of bounds read attemptoffoffoff
138868FILE-OTHERHancom Hangul Office HShow integer-based heap buffer overflow attemptoffdropdrop
138869FILE-OTHERHancom Hangul Office HShow integer-based heap buffer overflow attemptoffdropdrop
138870SERVER-OTHERPidgin mxit_chunk_parse_cr out of bounds read attemptoffoffoff
139034FILE-OTHERlibarchive mtree parse_device stack buffer overflow attemptoffoffoff
139035FILE-OTHERlibarchive mtree parse_device stack buffer overflow attemptoffoffoff
139045FILE-OTHERlibarchive RAR RestartModel out of bounds write attemptoffoffoff
139046FILE-OTHERlibarchive RAR RestartModel out of bounds write attemptoffoffoff
139047FILE-EXECUTABLEKaspersky Internet Security kl1.sys out of bounds read attemptoffoffoff
139048FILE-EXECUTABLEKaspersky Internet Security kl1.sys out of bounds read attemptoffoffoff
139049FILE-OFFICEHancom Hangul Office NXDeleteLineObj memory corruption attemptoffoffoff
139050FILE-OFFICEHancom Hangul Office NXDeleteLineObj memory corruption attemptoffoffoff
139110FILE-OFFICEHancom Hangul Office HCell HncChart out of bounds write attemptoffoffoff
139111FILE-OFFICEHancom Hangul Office HCell HncChart out of bounds write attemptoffoffoff
139148FILE-OFFICEDocument Foundation LibreOffice RTF stylesheet use after free attemptoffdropdrop
139149FILE-OFFICEDocument Foundation LibreOffice RTF stylesheet use after free attemptoffdropdrop
139150SERVER-OTHERPidgin MXIT negative message length underflow attemptoffoffoff
139151SERVER-OTHERPidgin MXIT message length overflow attemptoffoffoff
139161FILE-PDFGoogle Chrome PDFium jpeg2000 SIZ segment check failure heap buffer overflow attemptoffdropdrop
139162FILE-PDFGoogle Chrome PDFium jpeg2000 SIZ segment check failure heap buffer overflow attemptoffdropdrop
139593FILE-IMAGEOracle OIT BMP file parsing heap buffer overflow attemptoffoffoff
139594FILE-IMAGEOracle OIT BMP file parsing heap buffer overflow attemptoffoffoff
139595FILE-IMAGEOracle OIT BMP file parsing heap buffer overflow attemptoffoffoff
139596FILE-IMAGEOracle OIT BMP file parsing heap buffer overflow attemptoffoffoff
139597FILE-MULTIMEDIAApple OSX SceneKit invalid COLLADA file geometry attribute type confusion attemptoffoffoff
139598FILE-MULTIMEDIAApple OSX SceneKit invalid COLLADA file geometry attribute type confusion attemptoffoffoff
139599FILE-IMAGEApple OSX EXR image tile size heap buffer overflow attemptoffoffoff
139600FILE-IMAGEApple OSX EXR image tile size heap buffer overflow attemptoffoffoff
139601FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139602FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139603FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139604FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139605FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139606FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139607FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139608FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139609FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139610FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139611FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139612FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139613FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139614FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139615FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139616FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139617FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139618FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139619FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139620FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139621FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139622FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139623FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139624FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139625FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139626FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139627FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139628FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139629FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139630FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139631FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139632FILE-IMAGEApple OSX and iOS TIFF tile size buffer overflow attemptoffoffdrop
139634FILE-IMAGEApple OSX EXR image invalid box2i attribute heap buffer overflow attemptoffoffdrop
139635FILE-IMAGEApple OSX EXR image invalid box2i attribute heap buffer overflow attemptoffoffdrop
139660FILE-OTHEROracle OIT gem metafile n_integers heap buffer overflow attemptoffoffoff
139661FILE-OTHEROracle OIT gem metafile n_integers heap buffer overflow attemptoffoffoff
139663FILE-OTHEROracle OIT ContentAccess libvs_mwkd VwStreamReadRecord out of bounds write attemptoffoffoff
139664FILE-OTHEROracle OIT ContentAccess libvs_mwkd VwStreamReadRecord out of bounds write attemptoffoffoff
139665FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139666FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139667FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139668FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139671FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139672FILE-OTHEROracle OIT libvs_word ContentAccess out of bounds write attemptoffoffoff
139673FILE-IMAGEOracle OIT CYMK TIFF parsing heap buffer overflow attemptoffoffoff
139674FILE-IMAGEOracle OIT CYMK TIFF parsing heap buffer overflow attemptoffoffoff
139675FILE-IMAGEOracle OIT CYMK TIFF parsing heap buffer overflow attemptoffoffoff
139676FILE-IMAGEOracle OIT CYMK TIFF parsing heap buffer overflow attemptoffoffoff
139757FILE-OFFICEHancom Hangul HCell TableStyle record heap buffer overflow attemptoffoffoff
139758FILE-OFFICEHancom Hangul HCell TableStyle record heap buffer overflow attemptoffoffoff
139759FILE-OFFICEHancom Hangul HCell TableStyle record heap buffer overflow attemptoffoffoff
139760FILE-OFFICEHancom Hangul HCell TableStyle record heap buffer overflow attemptoffoffoff
139761FILE-OFFICEHancom Hangul Hcell cssValFormat checkUnderbar out of bounds write attemptoffoffoff
139762FILE-OFFICEHancom Hangul Hcell cssValFormat checkUnderbar out of bounds write attemptoffoffoff
139877PROTOCOL-SNMPAllen-Bradley MicroLogix PLC firmware update detectedoffoffoff
139883FILE-IMAGEFreeImage library XPM handling out of bounds write attemptoffoffdrop
139884FILE-IMAGEFreeImage library XPM handling out of bounds write attemptoffoffdrop
140125FILE-OTHERIchitaro Office Excel TxO record heap overflow attemptoffoffoff
140126FILE-OTHERIchitaro Office Excel TxO record heap overflow attemptoffoffoff
140314FILE-IMAGEOpenJPEG JPEG2000 MCC record parsing heap memory corruption attemptoffoffdrop
140315FILE-IMAGEOpenJPEG JPEG2000 MCC record parsing heap memory corruption attemptoffoffdrop
140336FILE-PDFIceni Argus ipfSetColourStroke stack buffer overflow attemptoffoffdrop
140337FILE-PDFIceni Argus ipfSetColourStroke stack buffer overflow attemptoffoffdrop
140468SERVER-OTHERMemcached append opcode request heap buffer overflow attemptoffoffdrop
140469SERVER-OTHERMemcached append opcode request heap buffer overflow attemptoffoffdrop
140470SERVER-OTHERMemcached prepend opcode request heap buffer overflow attemptoffoffdrop
140471SERVER-OTHERMemcached prepend opcode request heap buffer overflow attemptoffoffdrop
140472SERVER-OTHERMemcached appendq opcode request heap buffer overflow attemptoffoffdrop
140473SERVER-OTHERMemcached appendq opcode request heap buffer overflow attemptoffoffdrop
140474SERVER-OTHERMemcached prependq opcode request heap buffer overflow attemptoffoffdrop
140475SERVER-OTHERMemcached prependq opcode request heap buffer overflow attemptoffoffdrop
140476SERVER-OTHERMemcached set opcode request heap buffer overflow attemptoffoffdrop
140477SERVER-OTHERMemcached setq opcode request heap buffer overflow attemptoffoffdrop
140478SERVER-OTHERMemcached add opcode request heap buffer overflow attemptoffoffdrop
140479SERVER-OTHERMemcached addq opcode request heap buffer overflow attemptoffoffdrop
140480SERVER-OTHERMemcached replace opcode request heap buffer overflow attemptoffoffdrop
140481SERVER-OTHERMemcached replaceq opcode request heap buffer overflow attemptoffoffdrop
140482SERVER-OTHERMemcached SASL auth opcode request heap buffer overflow attemptoffoffdrop
140483SERVER-OTHERMemcached SASL auth opcode request heap buffer overflow attemptoffoffdrop
140484FILE-PDFIceni Argus ipNameAdd stack buffer overflow attemptoffoffoff
140485FILE-PDFIceni Argus ipNameAdd stack buffer overflow attemptoffoffoff
140486FILE-PDFIceni Argus ipNameAdd stack buffer overflow attemptoffoffoff
140487FILE-PDFIceni Argus ipNameAdd stack buffer overflow attemptoffoffoff
140488FILE-EXECUTABLEHopper Disassembler ELF section header memory corruption attemptoffoffdrop
140489FILE-EXECUTABLEHopper Disassembler ELF section header memory corruption attemptoffoffdrop
140490FILE-OFFICEJustSystems Ichitaro Word Processor malformed PersistDirectory memory corruption attemptoffoffdrop
140491FILE-OFFICEJustSystems Ichitaro Word Processor malformed PersistDirectory memory corruption attemptoffoffdrop
140525FILE-IMAGELibTIFF tiff2pdf JPEG compression tables heap buffer overflow attemptoffoffoff
140526FILE-IMAGELibTIFF tiff2pdf JPEG compression tables heap buffer overflow attemptoffoffoff
140533FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140534FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140535FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140536FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140537FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140538FILE-IMAGELibTIFF FAX IFD entry parsing type confusion attemptoffoffoff
140539FILE-IMAGELibTIFF PixarLogDecode heap buffer overflow attemptoffoffdrop
140540FILE-IMAGELibTIFF PixarLogDecode heap buffer overflow attemptoffoffdrop
140756FILE-PDFNitro Pro PDF Font Widths tag out of bounds read attemptoffoffdrop
140757FILE-PDFNitro Pro PDF Font Widths tag out of bounds read attemptoffoffdrop
140773FILE-PDFOracle Outside In Technology remote code execution attemptoffoffoff
140774FILE-PDFOracle Outside In Technology remote code execution attemptoffoffoff
140776FILE-PDFNitro Pro out of bounds memory write attemptoffdropdrop
140777FILE-PDFNitro Pro out of bounds memory write attemptoffdropdrop
140791FILE-OTHERHDF5 msg_dtype H5T_ARRAY heap buffer overflow attemptoffoffdrop
140792FILE-OTHERHDF5 msg_dtype H5T_ARRAY heap buffer overflow attemptoffoffdrop
140793FILE-OTHERHDF5 msg_dtype H5T_ARRAY heap buffer overflow attemptoffoffdrop
140794FILE-OTHERHDF5 msg_dtype H5T_ARRAY heap buffer overflow attemptoffoffdrop
140801FILE-OTHERHDF5 H5Z_NBIT filter heap buffer overflow attemptoffoffdrop
140802FILE-OTHERHDF5 H5Z_NBIT filter heap buffer overflow attemptoffoffdrop
140803FILE-OTHERHDF5 H5O_dtype_decode_helper heap buffer overflow attemptoffdropdrop
140804FILE-OTHERHDF5 H5O_dtype_decode_helper heap buffer overflow attemptoffdropdrop
140805FILE-OTHERHDF5 object modification time out of bounds write attemptoffoffdrop
140806FILE-OTHERHDF5 object modification time out of bounds write attemptoffoffdrop
140807FILE-OTHERHDF5 symbol table message out of bounds write attemptoffoffdrop
140808FILE-OTHERHDF5 symbol table message out of bounds write attemptoffoffdrop
140809FILE-OTHERHDF5 new object modification time out of bounds write attemptoffoffdrop
140810FILE-OTHERHDF5 new object modification time out of bounds write attemptoffoffdrop
140872FILE-PDFIceni Argus loadTrailer heap corruption attemptoffoffoff
140873FILE-PDFIceni Argus loadTrailer heap corruption attemptoffoffoff
140874FILE-PDFIceni Argus icnChainAlloc heap corruption attemptoffoffoff
140875FILE-PDFIceni Argus icnChainAlloc heap corruption attemptoffoffoff
140894FILE-OTHERR Project PDF encoding buffer overflow attemptoffoffoff
140895FILE-OTHERR Project PDF encoding buffer overflow attemptoffoffoff
140898OS-OTHERJoyent SmartOS ioctl integer underflow attemptoffdropdrop
140899OS-OTHERJoyent SmartOS ioctl integer underflow attemptoffdropdrop
140900OS-OTHERJoyent SmartOS file system name buffer overflow attemptoffdropdrop
140901OS-OTHERJoyent SmartOS file system name buffer overflow attemptoffdropdrop
140902OS-OTHERJoyent SmartOS file system path buffer overflow attemptoffdropdrop
140903OS-OTHERJoyent SmartOS file system path buffer overflow attemptoffdropdrop
140917FILE-PDFIceni Argus PDF uninitialized WordStyle color length code overflow attemptoffdropdrop
140918FILE-PDFIceni Argus PDF uninitialized WordStyle color length code overflow attemptoffdropdrop
140919FILE-PDFIceni ArgusPDF convertor malformed embedded TTF file cmap table memory corruption attemptoffoffdrop
140920FILE-PDFIceni ArgusPDF convertor malformed embedded TTF file cmap table memory corruption attemptoffoffdrop
140921FILE-PDFIceni Argus loadLZWBuffer out of bounds write attemptoffoffoff
140922FILE-PDFIceni Argus loadLZWBuffer out of bounds write attemptoffoffoff
140923FILE-PDFIceni Argus PDF font-encoding glyphmap adjustment code execution vulnerability attemptoffoffdrop
140924FILE-PDFIceni Argus PDF font-encoding glyphmap adjustment code execution vulnerability attemptoffoffdrop
140925FILE-PDFIceni Argus PDF TextToPolys rasterization code execution vulnerability attemptoffoffdrop
140926FILE-PDFIceni Argus PDF TextToPolys rasterization code execution vulnerability attemptoffoffdrop
140934FILE-EXECUTABLENvidia Windows kernel mode driver denial of service attemptoffdropdrop
140935FILE-EXECUTABLENvidia Windows kernel mode driver denial of service attemptoffdropdrop
141108FILE-OFFICEOracle Outside In Technology image export use after free attemptoffoffdrop
141109FILE-OFFICEOracle Outside In Technology image export use after free attemptoffoffdrop
141110FILE-OFFICEIchitaro Office JTD Figure handling code execution attemptoffdropdrop
141111FILE-OFFICEIchitaro Office JTD Figure handling code execution attemptoffdropdrop
141206SERVER-OTHERAerospike Database Server index name buffer overflow attemptoffoffdrop
141209SERVER-OTHERAerospike Database Server Fabric particle_vtable out of bounds read attemptoffoffdrop
141212SERVER-OTHERAerospike Database Server digest_ripe message field out of bounds read attemptoffoffdrop
141213SERVER-OTHERAerospike Database Server client batch request exploit attemptoffoffdrop
141216SERVER-OTHERAerospike Database Server si_prop stack buffer overflow attemptoffoffdrop
141219SERVER-OTHERAerospike Database Server Fabric denial of service attemptoffoffoff
141310FILE-IMAGElibBPG restore_tqb_pixel out of bounds write attemptoffdropdrop
141311FILE-IMAGElibBPG restore_tqb_pixel out of bounds write attemptoffdropdrop
141327FILE-PDFIceni Argus ipStringCreate integer overflow attemptoffoffdrop
141328FILE-PDFIceni Argus ipStringCreate integer overflow attemptoffoffdrop
141350FILE-OTHERApple Garageband .band file out of bounds write attemptoffoffdrop
141351FILE-OTHERApple Garageband .band file out of bounds write attemptoffoffdrop
141370FILE-OTHERNational Instruments LabVIEW LvVarientUnflatten remote code execution attemptoffdropdrop
141371FILE-OTHERNational Instruments LabVIEW LvVarientUnflatten remote code execution attemptoffdropdrop
141447FILE-OTHERApple GarageBand out of bounds write attemptoffdropdrop
141448FILE-OTHERApple GarageBand out of bounds write attemptoffdropdrop
141505SERVER-OTHERPharos PopUp Printer Client DecodeString heap overflow attemptoffoffdrop
141506SERVER-OTHERPharos PopUp Printer Client DecodeString heap overflow attemptoffoffdrop
141508SERVER-OTHERPharos PopUp Printer Client Memcpy heap overflow attemptoffoffdrop
141509SERVER-OTHERPharos PopUp Printer Client DecodeBinary heap overflow attemptoffoffdrop
141510SERVER-OTHERPharos PopUp Printer Client DecodeBinary heap overflow attemptoffoffdrop
141999OS-OTHERApple OSX and iOS x509 certificate name constraints parsing use after free attemptoffdropdrop
342076FILE-OFFICETRUFFLEHUNTER TALOS-2017-0300 attack attemptoffoffdrop
342077FILE-OFFICETRUFFLEHUNTER TALOS-2017-0300 attack attemptoffoffdrop
342078SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0299 attack attemptoffoffdrop
142079MALWARE-CNCWin.Trojan.Jenxcus outbound connection attempt with unique User-Agentoffdropdrop
142080MALWARE-CNCWin.Trojan.Jenxcus outbound connection attempt with unique User-Agentoffdropdrop
142081MALWARE-CNCWin.Trojan.Jenxcus outbound POST request attemptoffdropdrop
142082INDICATOR-COMPROMISERequest for external IP address detectedoffoffoff
142083MALWARE-CNCWin.Trojan.Downeks variant initial outbound connection attemptoffdropdrop
342084FILE-IMAGETRUFFLEHUNTER TALOS-2017-0297 attack attemptoffoffoff
342085FILE-IMAGETRUFFLEHUNTER TALOS-2017-0297 attack attemptoffoffoff
342086FILE-IMAGETRUFFLEHUNTER TALOS-2017-0297 attack attemptoffoffoff
342087FILE-IMAGETRUFFLEHUNTER TALOS-2017-0297 attack attemptoffoffoff
342088FILE-IMAGETRUFFLEHUNTER TALOS-2017-0298 attack attemptoffoffdrop
342089FILE-IMAGETRUFFLEHUNTER TALOS-2017-0298 attack attemptoffoffdrop
342090FILE-IMAGETRUFFLEHUNTER TALOS-2017-0298 attack attemptoffoffdrop
342091FILE-IMAGETRUFFLEHUNTER TALOS-2017-0298 attack attemptoffoffdrop
142092POLICY-OTHERNetBiter WebSCADA ws100/ws200 logo modification attemptoffoffoff
142093POLICY-OTHERNetBiter WebSCADA ws100/ws200 file read attemptoffoffoff
142094SERVER-WEBAPPNetBiter WebSCADA ws100/ws200 information gathering attemptoffoffoff
142095SERVER-WEBAPPNetBiter WebSCADA ws100/ws200 directory traversal attemptoffoffoff
142096FILE-FLASHAdobe Flash Player Resolution Opportunity parameter memory corruption attemptoffdropdrop
142097FILE-FLASHAdobe Flash Player Resolution Opportunity parameter memory corruption attemptoffdropdrop
142098MALWARE-CNCWin.Trojan.Winpud encoded payload download attemptoffdropdrop
142099MALWARE-CNCWin.Trojan.Winpud encoded payload download attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
136225FILE-OTHERLibgraphite empty feature list denial of service attemptoffdropdrop
136226FILE-OTHERLibgraphite empty feature list denial of service attemptoffdropdrop
136227FILE-OTHERLibgraphite empty feature list denial of service attemptoffdropdrop
136228FILE-OTHERLibgraphite empty feature list denial of service attemptoffdropdrop
136229FILE-FLASHAdobe Flash Player On2 VP6 video codec fragment read access violation attemptoffdropdrop
136230FILE-FLASHAdobe Flash Player On2 VP6 video codec fragment read access violation attemptoffdropdrop
137841SERVER-OTHERntpd reference clock impersonation attemptoffoffoff
137842SERVER-OTHERntpd reference clock impersonation attemptoffoffoff
137843SERVER-OTHERNTP crypto-NAK possible DoS attemptoffoffoff
137866FILE-PDFOracle Outside In libvs_pdf arbitrary pointer access attemptoffoffoff
137867FILE-PDFOracle Outside In libvs_pdf arbitrary pointer access attemptoffoffoff
138849OS-WINDOWSKaspersky Internet Security KLIF driver denial of service attemptoffdropdrop
138850OS-WINDOWSKaspersky Internet Security KLIF driver denial of service attemptoffdropdrop
139078OS-WINDOWSKaspersky Internet Security KLIF driver denial of service attemptoffdropdrop
139079OS-WINDOWSKaspersky Internet Security KLIF driver denial of service attemptoffdropdrop
139466FILE-EXECUTABLESymantec Norton Security IDSvix86 out of bounds read attemptoffoffdrop
139467FILE-EXECUTABLESymantec Norton Security IDSvix86 out of bounds read attemptoffoffdrop
139876PROTOCOL-SNMPAllen-Bradley MicroLogix PLC SNMP request via undocumented community string attemptoffdropdrop
139918FILE-EXECUTABLEKaspersky Anti-Virus unhandled windows messages denial of service vulnerability attemptoffoffoff
139919FILE-EXECUTABLEKaspersky Anti-Virus unhandled windows messages denial of service vulnerability attemptoffoffoff
140429FILE-PDFFoxit PDF Reader JBIG2 parser out of bounds read attemptoffoffdrop
140430FILE-PDFFoxit PDF Reader JBIG2 parser out of bounds read attemptoffoffdrop
141217OS-OTHERJoyent SmartOS add entries denial of service attemptoffdropdrop
141218OS-OTHERJoyent SmartOS add entries denial of service attemptoffdropdrop
141507SERVER-OTHERPharos PopUp Printer Client DecodeString denial of service attemptoffoffoff
142073PROTOCOL-SCADATraceMode Runtime DOS attemptoffoffoff
142074PROTOCOL-SCADATraceMode Runtime DOS attemptoffdropoff
142075PROTOCOL-SCADATraceMode Runtime DOS attemptdropoffoff

Updated Rules:

Updated rules can be found at this link.