Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2018-01-31

This SRU number: 2018-01-31-002
Previous SRU number: 2018-01-29-001

Applies to:

This SEU number: 1791
Previous SEU: 1789

Applies to:

This is the complete list of rules added in SRU 2018-01-31-002 and SEU 1791.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
117663SERVER-OTHERApple CUPS SGI image decoding buffer overflow attemptoffoffoff
145571SERVER-OTHERCommvault Communications Service command injection attemptoffoffoff
145574MALWARE-CNCWin.Trojan.xxmm second stage configuration download attemptoffdropdrop
345575SERVER-OTHERCisco ASA VPN aggregateAuthDataHandler double free attemptoffdropdrop
145576BROWSER-FIREFOXMozilla Firefox Javascript Function focus overflow attemptoffoffoff
145585SERVER-WEBAPPPMSotware Simple Web Server connection header buffer overflow attemptoffoffoff
145591PROTOCOL-FTPLabF nfsAxe FTP Client buffer overflow attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
145577PROTOCOL-VOIPMr.SIP invite request denial of service attemptoffoffoff
145578PROTOCOL-VOIPMr.SIP options request denial of service attemptoffoffoff
145579PROTOCOL-VOIPMr.SIP subscribe request denial of service attemptoffoffoff
145580PROTOCOL-VOIPMr.SIP invite request denial of service attemptoffoffoff
145581PROTOCOL-VOIPMr.SIP options request denial of service attemptoffoffoff
145582PROTOCOL-VOIPMr.SIP subscribe request denial of service attemptoffoffoff
145583PROTOCOL-VOIPMr.SIP SIP servers discovery attemptoffoffoff
145584PROTOCOL-VOIPMr.SIP SIP servers discovery attemptoffoffoff
145586FILE-MULTIMEDIAMicrosoft Windows Media Player or Explorer Malformed MIDI File DOS attemptoffoffoff
145587SERVER-OTHERFirefly Media Server malformed HTTP request denial of service attemptoffoffoff
145588SERVER-OTHERFirefly Media Server malformed HTTP request denial of service attemptoffoffoff
145589SERVER-OTHERFirefly Media Server malformed HTTP request denial of service attemptoffoffoff
145590SERVER-OTHERFirefly Media Server malformed HTTP request denial of service attemptoffoffoff