Rule Update

19-003 (January 22, 2019)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DHCPv6 Client - Incoming
1008949 - ISC dhclient Buffer Overflow Vulnerability (CVE-2018-5732)


Database MySQL
1009357* - MySQL 5.5.8 NULL Pointer Dereference Denial Of Service Vulnerability (CVE-2011-5049)


Memcached
1009459* - Memcached 'process_bin_append_prepend' Integer Overflow Vulnerability (CVE-2016-8704)
1009458* - Memcached 'process_bin_update' Function And 'body_len' Parameter Integer Overflow Vulnerability (CVE-2016-8705)


Web Application Common
1009308 - Moodle PHP Unserialize Remote Code Execution Vulnerability (CVE-2018-14630)
1009401 - Nagios XI Magpie 'cURL' Argument Injection Vulnerability (CVE-2018-15708)


Web Application PHP Based
1009395* - PHP 'imap_open()' Remote Code Execution Vulnerability (CVE-2018-19518)


Web Client Common
1009206* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-21) - 1
1009211* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-21) - 6
1009215* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB18-21) - 9
1009405* - Adobe Flash Player Use After Free Vulnerability (CVE-2018-15982)
1009403 - Apache Traffic Server ESI Plugin Cookie Header Information Disclosure (CVE-2018-8040)
1009338* - Microsoft Windows Shell Remote Code Execution Vulnerability (CVE-2018-8495)


Web Server Apache Tika
1009142 - Apache Tika tika-server Command Injection Vulnerability (CVE-2018-1335)


Web Server Common
1007185* - Java Unserialize Remote Code Execution Vulnerability


Web Server Oracle
1009417* - Oracle WebLogic Server DeploymentServiceServlet Insecure Deserialization Vulnerability (CVE-2018-3252)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.