Rule Update

18-035 (June 28, 2018)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption


CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution


FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow


HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow


LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow


Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service


RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability


Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability


Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1


Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)


Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability


Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)


Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability


Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.

Featured Stories