Rule Update

19-039 (July 23, 2019)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DCERPC Services
1008647* - Microsoft Windows Search Information Disclosure Vulnerability (CVE-2017-8544)


Microsoft Office
1009853* - Microsoft Excel Remote Code Execution Vulnerability (CVE-2019-1110)


SSL Client Applications
1001113* - SSL/TLS Client (ATT&CK T1032, T1043, T1071)


Web Application Common
1009711 - GraphicsMagick Heap Buffer Overflow Vulnerability (CVE-2019-11505) - 1
1009391 - Identified Redirect Sequence In URI


Web Application PHP Based
1006141* - PHP Fileinfo Denial Of Service Vulnerability (CVE-2014-1943)


Web Client Common
1009748 - Cisco Webex Teams URI Handler Remote Code Execution Vulnerability (CVE-2019-1636)
1009846 - Google Chrome AudioWorkletGlobalScope::Process Use-After-Free Vulnerability
1009712 - GraphicsMagick Heap Buffer Overflow Vulnerability (CVE-2019-11505)
1009823* - Microsoft Windows ActiveX Data Objects (ADO) Remote Code Execution Vulnerability (CVE-2019-0888)
1009760* - Microsoft Windows Jet Database Engine Multiple Remote Code Execution Vulnerabilities (May-2019)


Web Server Apache
1009609* - Apache Subversion 'mod_dav_svn' Denial Of Service Vulnerability (CVE-2018-11803)


Web Server Oracle
1009471* - Oracle WebLogic Server SAML Authentication Bypass Vulnerability (CVE-2018-2998)
1009830* - Oracle Weblogic Server Remote Code Execution Vulnerability (CVE-2019-2649)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.

Featured Stories