*** NK8 RELS 3401 Release *** Total number of signatures: 3220 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 3 rule(s): --------------- 1135055 WEB-CLIENT Windows Powershell Remote Command Injection -3 (Possible Exploit Kit) 1135058 WEB-CLIENT Windows Powershell Remote Command Injection -5 (Possible Exploit Kit) 1135062 WEB Apache Pluto PortletV3AnnotatedDemo MultipartPortlet Arbitrary File Upload -1 (CVE-2018-1306) Modified 6 rule(s): --------------- 1064428 FILE WebFileTransfer img transfer-download via TCP -1 1064429 FILE WebFileTransfer rpm transfer-download via TCP -1 1066225 FILE WebFileTransfer transfer-upload via TCP -1 1068326 FILE WebFileTransfer gho transfer-download via TCP -1 1068329 FILE WebFileTransfer transfer-download via TCP -1 1135023 WEB-CLIENT Windows Powershell Remote Command Injection -1 (Possible Exploit Kit) Deleted 11 rule(s): --------------- 1131606 FILE IBM Lotus Domino BMP Color Palette Stack Buffer Overflow (CVE-2015-1903) (old rule) 1132456 SSL TLS FREAK with CBC Cipher TLS_RSA_EXPORT1024_WITH_RC4_56_MD5 -1.1 (old rule) 1132460 SSL TLS FREAK with CBC Cipher TLS_RSA_EXPROT1024_WITH_RC4_56_SHA -1.1 (old rule) 1132464 SSL TLS FREAK with CBC Cipher TLS_DH_RSA_EXPORT_WITH_DES40_CBC_SHA -1.1 (old rule) 1132723 WEB GD Library libgd gd_gd2.c Heap Buffer Overflow -1 (CVE-2016-3074) (old rule) 1132726 WEB GD Library libgd gd_gd2.c Heap Buffer Overflow -2 (CVE-2016-3074) (old rule) 1132727 WEB GD Library libgd gd_gd2.c Heap Buffer Overflow -3 (CVE-2016-3074) (old rule) 1132815 EXPLOIT HPE Data Protector EXEC_BAR username Buffer Overflow -1 (CVE-2016-2005) (old rule) 1133389 WEB Netgear WNR2000v5 Remote Code Execution Vulnerability (old rule) 1133448 WEB Multiple NETGEAR Products Information Disclosure Vulnerability (CVE-2017-5521) (old rule) 1133449 SMB Microsoft SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability (CVE-2017-0016) (old rule)