Rule Update
15-031 (October 13, 2015)
Publish date: October 13, 2015
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Application Control For File Sharing
1003655* - Application Control For Share NT5
Directory Server LDAP
1002614* - OpenLDAP ber_get_next BER Decoding Denial of Service
HP AutoPass License Server
1006811 - HP AutoPass License Server Remote Code Execution Vulnerability (CVE-2013-6221)
Microsoft Office
1006941* - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2477)
1007110 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2555)
1007111 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2557)
1007112 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2558)
OpenSSL
1006854* - OpenSSL X509_cmp_time Denial Of Service Vulnerability (CVE-2015-1789)
OpenSSL Client
1006920* - OpenSSL Client X509_cmp_time Denial Of Service Vulnerability (CVE-2015-1789)
Suspicious Client Application Activity
1007116 - VMware vCenter Java JMX Server Insecure Configuration Java Code Execution Vulnerability
Web Application PHP Based
1006656* - Magento Admin Authentication Bypass Vulnerability
Web Client Common
1007090 - Adobe Flash Player Buffer Overflow Vulnerability (CVE-2015-6676)
1007093 - Adobe Flash Player Buffer Overflow Vulnerability (CVE-2015-6678)
1006772* - Adobe Flash Player Cross Domain Policy Bypass Vulnerability
1006985* - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5547)
1006986* - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5548)
1007073 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5567)
1007078 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5574)
1007079 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5575)
1007080 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5576)
1007081 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5578)
1007082 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5579)
1007083 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5580)
1007085 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5582)
1007088 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5588)
1002948* - Adobe Flash Player SWF Version Null Pointer Dereference Denial Of Service
1007076 - Adobe Flash Player Security Bypass Vulnerability (CVE-2015-5572)
1007091 - Adobe Flash Player Security Bypass Vulnerability (CVE-2015-6679)
1007087 - Adobe Flash Player Stack Buffer Overflow Vulnerability (CVE-2015-5587)
1007077 - Adobe Flash Player Type Confusion Vulnerability (CVE-2015-5573)
1007115 - Adobe Flash Player Use After Free Vulnerability
1006590* - Adobe Flash Player Use After Free Vulnerability (CVE-2015-0342)
1006780* - Adobe Flash Player Use After Free Vulnerability (CVE-2015-3106)
1007075 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5570)
1007084 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5581)
1007086 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5584)
1007092 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-6682)
1007074 - Adobe Flash Player Vector Length Corruption Vulnerability (CVE-2015-5568)
1007063 - Foxit Reader PNG Conversion Arbitrary Code Execution Vulnerability
1006631* - Identified File Protocol Handler In HTTP Location Header
1006820* - Java SE Remote Security Vulnerability (CVE-2015-0491)
1007061 - Mozilla Firefox Arbitrary JavaScript Code Execution
1005849* - RealNetworks RealPlayer Stack Based Buffer Overflow Vulnerability
Web Client Internet Explorer
1007106 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6046)
1007102 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6053)
1007108 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6059)
1007097 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6042)
1007098 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6045)
1007099 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6048)
1007100 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6049)
1007101 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6050)
1007096 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2015-2482)
1007103 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2015-6055)
1007107 - Microsoft Internet Explorer VBScript And JScript ASLR Bypass Vulnerability (CVE-2015-6052)
1007105 - Microsoft Windows Shell Tablet Input Band Use After Free Vulnerability (CVE-2015-2548)
1007104 - Microsoft Windows Shell Toolbar Use After Free Vulnerability (CVE-2015-2515)
Web Client SSL
1006606* - Identified Fraudulent Digital Certificate - 1
Web Server Common
1007117 - Identified Python Werkzeug Debugger Remote Code Execution
Web Server IIS
1004396* - IIS Repeated Parameter Request Denial Of Service Vulnerability
Web Server Miscellaneous
1006808 - Novell Zenworks Configuration Management Multiple Information Disclosure Vulnerabilities
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Application Control For File Sharing
1003655* - Application Control For Share NT5
Directory Server LDAP
1002614* - OpenLDAP ber_get_next BER Decoding Denial of Service
HP AutoPass License Server
1006811 - HP AutoPass License Server Remote Code Execution Vulnerability (CVE-2013-6221)
Microsoft Office
1006941* - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2477)
1007110 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2555)
1007111 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2557)
1007112 - Microsoft Office Memory Corruption Vulnerability (CVE-2015-2558)
OpenSSL
1006854* - OpenSSL X509_cmp_time Denial Of Service Vulnerability (CVE-2015-1789)
OpenSSL Client
1006920* - OpenSSL Client X509_cmp_time Denial Of Service Vulnerability (CVE-2015-1789)
Suspicious Client Application Activity
1007116 - VMware vCenter Java JMX Server Insecure Configuration Java Code Execution Vulnerability
Web Application PHP Based
1006656* - Magento Admin Authentication Bypass Vulnerability
Web Client Common
1007090 - Adobe Flash Player Buffer Overflow Vulnerability (CVE-2015-6676)
1007093 - Adobe Flash Player Buffer Overflow Vulnerability (CVE-2015-6678)
1006772* - Adobe Flash Player Cross Domain Policy Bypass Vulnerability
1006985* - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5547)
1006986* - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5548)
1007073 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5567)
1007078 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5574)
1007079 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5575)
1007080 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5576)
1007081 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5578)
1007082 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5579)
1007083 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5580)
1007085 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5582)
1007088 - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5588)
1002948* - Adobe Flash Player SWF Version Null Pointer Dereference Denial Of Service
1007076 - Adobe Flash Player Security Bypass Vulnerability (CVE-2015-5572)
1007091 - Adobe Flash Player Security Bypass Vulnerability (CVE-2015-6679)
1007087 - Adobe Flash Player Stack Buffer Overflow Vulnerability (CVE-2015-5587)
1007077 - Adobe Flash Player Type Confusion Vulnerability (CVE-2015-5573)
1007115 - Adobe Flash Player Use After Free Vulnerability
1006590* - Adobe Flash Player Use After Free Vulnerability (CVE-2015-0342)
1006780* - Adobe Flash Player Use After Free Vulnerability (CVE-2015-3106)
1007075 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5570)
1007084 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5581)
1007086 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-5584)
1007092 - Adobe Flash Player Use After Free Vulnerability (CVE-2015-6682)
1007074 - Adobe Flash Player Vector Length Corruption Vulnerability (CVE-2015-5568)
1007063 - Foxit Reader PNG Conversion Arbitrary Code Execution Vulnerability
1006631* - Identified File Protocol Handler In HTTP Location Header
1006820* - Java SE Remote Security Vulnerability (CVE-2015-0491)
1007061 - Mozilla Firefox Arbitrary JavaScript Code Execution
1005849* - RealNetworks RealPlayer Stack Based Buffer Overflow Vulnerability
Web Client Internet Explorer
1007106 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6046)
1007102 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6053)
1007108 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2015-6059)
1007097 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6042)
1007098 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6045)
1007099 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6048)
1007100 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6049)
1007101 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6050)
1007096 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2015-2482)
1007103 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2015-6055)
1007107 - Microsoft Internet Explorer VBScript And JScript ASLR Bypass Vulnerability (CVE-2015-6052)
1007105 - Microsoft Windows Shell Tablet Input Band Use After Free Vulnerability (CVE-2015-2548)
1007104 - Microsoft Windows Shell Toolbar Use After Free Vulnerability (CVE-2015-2515)
Web Client SSL
1006606* - Identified Fraudulent Digital Certificate - 1
Web Server Common
1007117 - Identified Python Werkzeug Debugger Remote Code Execution
Web Server IIS
1004396* - IIS Repeated Parameter Request Denial Of Service Vulnerability
Web Server Miscellaneous
1006808 - Novell Zenworks Configuration Management Multiple Information Disclosure Vulnerabilities
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more
- A Closer Exploration of Residential Proxies and CAPTCHA-Breaking ServicesThis article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.Read more
- How Residential Proxies and CAPTCHA-Solving Services Become Agents of AbuseThis article, the first of a two-part series, provides insights on how abusers and cybercriminals use residential proxies and CAPTCHA-solving services to enable bots, scrapers, and stuffers, and proposes security countermeasures for organizations.Read more