Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-04-06

This SRU number: 2017-04-06-001
Previous SRU number: 2017-04-03-002

Applies to:

This SEU number: 1648
Previous SEU: 1645

Applies to:

This is the complete list of rules modified in SRU 2017-04-06-001 and SEU 1648.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
313469FILE-OFFICEMicrosoft Word ole stream memory corruption attemptoffoffoff
313582FILE-OFFICEMicrosoft Excel sst record arbitrary code execution attemptoffoffoff
313790FILE-OFFICEMicrosoft Word malformed css remote code execution attemptoffoffoff
313803FILE-OFFICERTF control word overflow attemptoffoffoff
313958FILE-OFFICEWordPerfect Graphics file invalid RLE buffer overflow attemptoffoffoff
313969FILE-OFFICEPowerpoint Viewer malformed msoDrawing property table buffer overflow attemptoffoffoff
314655FILE-OFFICEExcel rept integer underflow attemptoffoffoff
315117FILE-OFFICEMicrosoft Excel malformed OBJ record arbitrary code execution attemptoffoffoff
315125FILE-OFFICEMicrosoft Word rich text file unpaired dpendgroup exploit attemptoffoffoff
315298FILE-OFFICEMicrosoft Visio could allow remote code executionoffoffoff
315365FILE-OFFICEMicrosoft Excel extrst record arbitrary code excecution attemptoffoffoff
315454FILE-OFFICEMicrosoft Office PowerPoint malformed msofbtTextbox exploit attemptoffoffoff
315465FILE-OFFICEMicrosoft Excel malformed object record remote code execution attemptoffoffoff
315498FILE-OFFICEMicrosoft PowerPoint CString atom overflow attemptoffoffoff
315519FILE-OFFICEMicrosoft Office Excel BRAI record remote code execution attemptoffoffoff
315521FILE-OFFICEMicrosoft Office Excel ExternSheet record remote code execution attemptoffoffoff
316230FILE-OFFICEMicrosoft Excel oversized ib memory corruption attemptoffoffoff
316649FILE-OFFICEMicrosoft Excel HFPicture record stack buffer overflow attemptoffoffoff
316662FILE-OFFICEMicrosoft Excel SxView heap overflow attemptoffoffoff
317251FILE-OFFICEOutlook RTF remote code execution attemptoffoffoff
317665FILE-OFFICEOpenOffice Word document table parsing multiple heap based buffer overflow attemptoffdropdrop
317762FILE-OFFICEMicrosoft Excel corrupted TABLE record clean up exploit attemptoffoffoff
318063FILE-OFFICEMicrosoft Office embedded Office Art drawings execution attemptoffoffoff
318676FILE-OFFICEMicrosoft Office Excel DV record buffer overflow attemptoffoffoff
318949FILE-OFFICEPowerPoint malformed RecolorInfoAtom exploit attemptoffoffoff
322089FILE-OFFICEMicrosoft RTF improper listoverride nesting attemptoffoffdrop
324666FILE-OFFICEExcel invalid data item buffer overflow attemptoffoffdrop
333587FILE-OFFICEMicrosoft RTF improper listoverride nesting attemptoffoffdrop
137919EXPLOIT-KITGong da exploit kit landing pageoffdropdrop
339082FILE-OFFICETRUFFLEHUNTER TALOS-CAN-0160 attack attemptoffoffoff
339083FILE-OFFICETRUFFLEHUNTER TALOS-CAN-0160 attack attemptoffoffoff
139242BROWSER-IEMicrosoft Internet Explorer Typed Array use after free attemptoffoffdrop
139243BROWSER-IEMicrosoft Internet Explorer Typed Array use after free attemptoffoffdrop
139565FILE-FLASHAdobe Flash Player malformed tag parsing memory corruption attemptoffdropdrop
139566FILE-FLASHAdobe Flash Player malformed tag parsing memory corruption attemptoffdropdrop
140773FILE-PDFOracle Outside In Technology remote code execution attemptoffoffoff
140774FILE-PDFOracle Outside In Technology remote code execution attemptoffoffoff
340927FILE-OFFICETRUFFLEHUNTER TALOS-2016-0207 attack attemptoffdropdrop
340928FILE-OFFICETRUFFLEHUNTER TALOS-2016-0207 attack attemptoffdropdrop
340929FILE-OFFICETRUFFLEHUNTER TALOS-2016-0208 attack attemptoffdropdrop
340930FILE-OFFICETRUFFLEHUNTER TALOS-2016-0208 attack attemptoffdropdrop
340931FILE-OFFICETRUFFLEHUNTER TALOS-2016-0209 attack attemptoffdropdrop
340932FILE-OFFICETRUFFLEHUNTER TALOS-2016-0209 attack attemptoffdropdrop
341468FILE-OFFICETRUFFLEHUNTER TALOS-2017-0272 attack attemptoffoffdrop
341469FILE-OFFICETRUFFLEHUNTER TALOS-2017-0272 attack attemptoffoffdrop
341511FILE-OFFICETRUFFLEHUNTER TALOS-2017-2783 attack attemptoffdropdrop
341512FILE-OFFICETRUFFLEHUNTER TALOS-2017-2783 attack attemptoffdropdrop
341543FILE-OFFICETRUFFLEHUNTER TALOS-2017-0285 attack attemptoffoffdrop
341544FILE-OFFICETRUFFLEHUNTER TALOS-2017-0285 attack attemptoffoffdrop
341545FILE-OFFICETRUFFLEHUNTER TALOS-2017-0284 attack attemptoffoffdrop
341546FILE-OFFICETRUFFLEHUNTER TALOS-2017-0284 attack attemptoffoffdrop
341703FILE-OFFICETRUFFLEHUNTER TALOS-2016-0197 TALOS-2017-0288 attack attemptoffoffdrop
341704FILE-OFFICETRUFFLEHUNTER TALOS-2016-0197 TALOS-2017-0288 attack attemptoffoffdrop
341726FILE-OFFICETRUFFLEHUNTER TALOS-2017-0292 attack attemptoffdropdrop
341727FILE-OFFICETRUFFLEHUNTER TALOS-2017-0292 attack attemptoffdropdrop
341753FILE-OFFICETRUFFLEHUNTER TALOS-2017-0291 attack attemptoffoffdrop
341754FILE-OFFICETRUFFLEHUNTER TALOS-2017-0291 attack attemptoffoffdrop
341759FILE-OFFICETRUFFLEHUNTER TALOS-2017-0290 attack attemptoffoffdrop
341760FILE-OFFICETRUFFLEHUNTER TALOS-2017-0290 attack attemptoffoffdrop
341765FILE-OFFICETRUFFLEHUNTER TALOS-2017-0286 attack attemptoffoffdrop
341766FILE-OFFICETRUFFLEHUNTER TALOS-2017-0286 attack attemptoffoffdrop
342008FILE-OFFICETRUFFLEHUNTER TALOS-2017-0295 attack attemptoffoffdrop
342009FILE-OFFICETRUFFLEHUNTER TALOS-2017-0295 attack attemptoffoffdrop
342076FILE-OFFICETRUFFLEHUNTER TALOS-2017-0300 attack attemptoffoffdrop
342077FILE-OFFICETRUFFLEHUNTER TALOS-2017-0300 attack attemptoffoffdrop