*** EX RELS 03348 Release *** Total number of signatures: 6009 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 10 rule(s): --------------- 1134058 WEB-CLIENT Microsoft Edge Chakra arguments Off By One -1 (CVE-2017-8671) 1134061 FILE Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption (CVE-2017-2988) 1134067 DNS Dnsmasq 2-byte Heap-Based Overflow (CVE-2017-14491) 1134068 DHCP Dnsmasq Heap-Based Overflow (CVE-2017-14493) 1134069 DNS Dnsmasq Integer Underflow (CVE-2017-14496) 1134070 ICMP Dnsmasq Heap-Based Overflow (CVE-2017-14492) 1134071 DNS Dnsmasq Lack of Free Denial of Service (CVE-2017-14495) 1134072 DHCP Dnsmasq IPv6 Information Leak (CVE-2017-14494) 1134073 DNS Dnsmasq Overly Large DNS Query Denial of Service (CVE-2017-13704) 1134091 FILE Microsoft Office OOXML Memory Corruption (CVE-2017-11826) Modified 6 rule(s): --------------- 1055396 WEB Cross-site Scripting -9 1120193 WEB URI Handler Buffer Overflow - POST -1 1132274 FTP ProFTPD mod_copy Unauthenticated Remote File Copying -2 (CVE-2015-3306) 1133407 WEB Brute Force Login -1.1021 1133952 WEB PHP gdImageCreateFromGifCtx Out of Bounds Read -1 (CVE-2017-7890) 1134057 WEB Netgear ReadyNAS Surveillance Unauthenticated Remote Command Execution Deleted 4 rule(s): --------------- 1060101 SOCIAL Friendfeed login via SSL -1 (old rule) 1063890 SOCIAL Friendfeed access via TCP -1 (old rule) 1068668 SOCIAL Friendfeed transfer-upload via TCP -1 (old rule) 1068669 SOCIAL Friendfeed access via TCP -2 (old rule)