Rule Update

19-023 (April 30, 2019)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Mail Server Common
1000880* - Detected Format String Vulnerability In SMTP


Mail Server Miscellaneous
1000090* - Detected Format String Vulnerability In IMAP


TFTP Server
1009365* - Microsoft Windows Deployment Services TFTP Server Remote Code Execution Vulnerability (CVE-2018-8476)


Web Application Common
1009700 - Ghostscript Denial Of Service Vulnerability (CVE-2017-9835) - 1
1005934* - Identified Suspicious Command Injection Attack
1009315 - ImageMagick 'SetGrayscaleImage' Heap Overflow Vulnerability (CVE-2018-11625) - 1
1009352 - Libxml2 Null Pointer Dereference Vulnerability (CVE-2018-14404) - 1


Web Application PHP Based
1004998* - PHP-CGI Query String Parameter Vulnerability


Web Client Common
1009473 - GNU Libextractor ZIP File Comment Out-of-Bounds Read Vulnerability (CVE-2018-16430)
1009696 - Ghostscript Denial Of Service Vulnerability (CVE-2017-9835)
1009671 - Google Chrome JSCreateObject Operation Type Confusion Vulnerability (CVE-2018-17463)
1009314 - ImageMagick 'SetGrayscaleImage' Heap Overflow Vulnerability (CVE-2018-11625)
1009351 - Libxml2 Null Pointer Dereference Vulnerability (CVE-2018-14404)
1009702 - Microsoft Windows Elevation Of Privilege Vulnerability (CVE-2018-8468)
1009369* - Microsoft Windows VBScript Engine Remote Code Execution Vulnerability (CVE-2018-8544)


Web Client Internet Explorer/Edge
1009468* - Microsoft Edge Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2019-0567)
1009546 - Microsoft Edge Multiple Elevation Of Privilege Vulnerabilities
1009570* - Microsoft Internet Explorer Security Feature Bypass Vulnerability (CVE-2019-0768)
1009578* - Microsoft Internet Explorer VBScript Engine Remote Code Execution Vulnerability (CVE-2019-0667)


Web Server Apache Tika
1009142* - Apache Tika 'tika-server' Command Injection Vulnerability (CVE-2018-1335)


Web Server Common
1009705 - Atlassian Confluence Server Remote Code Execution Vulnerability (CVE-2019-3396)


Web Server Oracle
1009707* - Oracle Weblogic Server Remote Code Execution Vulnerability (CVE-2019-2725)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.