SOPHOS IPS Signature Update Release Notes
Total Page:16
File Type:pdf, Size:1020Kb
SOPHOS IPS Signature Update Release Notes Version : 9.16.41 Release Date : 31st October 2019 IPS Signature Update Release Information Upgrade Applicable on IPS Signature Release Version 9.16.40 CR250i, CR300i, CR500i-4P, CR500i-6P, CR500i-8P, CR500ia, CR500ia-RP, CR500ia1F, CR500ia10F, CR750ia, CR750ia1F, CR750ia10F, CR1000i-11P, CR1000i-12P, CR1000ia, CR1000ia10F, CR1500i-11P, CR1500i-12P, CR1500ia, CR1500ia10F Sophos Appliance Models CR25iNG, CR25iNG-6P, CR35iNG, CR50iNG, CR100iNG, CR200iNG/XP, CR300iNG/XP, CR500iNG- XP, CR750iNG-XP, CR2500iNG, CR25wiNG, CR25wiNG-6P, CR35wiNG, CRiV1C, CRiV2C, CRiV4C, CRiV8C, CRiV12C, XG85 to XG450, SG105 to SG650 Upgrade Information Upgrade type: Automatic Compatibility Annotations: None Introduction The Release Note document for IPS Signature Database Version 9.16.41 includes support for the new signatures. The following sections describe the release in detail. New IPS Signatures The Sophos Intrusion Prevention System shields the network from known attacks by matching the network traffic against the signatures in the IPS Signature Database. These signatures are developed to significantly increase detection performance and reduce the false alarms. Report false positives at [email protected], along with the application details. October 2019 Page 2 of 27 IPS Signature Update This IPS Release includes Two Hundred and Fifteen(215) signatures to address One Hundred and Eighty One(181) vulnerabilities. New signatures are added for the following vulnerabilities: Name CVE–ID Category Severity BROWSER-IE Microsoft Edge resource entry Browsers 1 same-origin-policy bypass attempt BROWSER-IE Microsoft Internet Explorer CVE- 2015-6140 CVE-2015- Browsers 1 SComputedStyle 6140 destructor out of bounds read attempt BROWSER-IE Microsoft Internet Explorer CVE-2015- GetPlainText negative Browsers 1 6084 start index out of bounds write attempt BROWSER-IE Microsoft Internet Explorer CVE-2015- Browsers 1 TextBlock out of bounds 6159 read attempt FILE-FLASH Adobe Flash CVE-2016-9163 Remote CVE-2016- Multimedia 1 Code Execution 9163 Vulnerability II FILE-FLASH Adobe Flash Player AAC audio CVE-2016- Multimedia 1 memory corruption 0970 attempt FILE-FLASH Adobe Flash CVE-2016- Multimedia 1 Player 4185 ABRControlParameters October 2019 Page 3 of 27 IPS Signature Update access memory corruption attempt FILE-FLASH Adobe Flash Player ActiveX same CVE-2019- Application 1 origin method 8069 and Software execution attempt FILE-FLASH Adobe Flash Player BitmapData CVE-2016- Multimedia 1 method memory 0969 corruption attempt FILE-FLASH Adobe Flash Player BlurFilter CVE-2016- Multimedia 2 memory corruption 0964 attempt FILE-FLASH Adobe Flash Player CVE-2015-8426 CVE-2015- Multimedia 1 TextField setter Use 8426 After Free Attempt FILE-FLASH Adobe Flash Player CVE-2018-12824 CVE-2018- Multimedia 2 Information Disclosure 12827 Vulnerability FILE-FLASH Adobe Flash CVE-2008- Player CVE-2018-15982 Multimedia 2 2992 Use After Free FILE-FLASH Adobe Flash Player ExportAssets CVE-2016- Multimedia 1 count memory 1012 corruption attempt FILE-FLASH Adobe Flash Player FLV invalid CVE-2016- reference frame count Multimedia 1 0972 memory corruption attempt October 2019 Page 4 of 27 IPS Signature Update FILE-FLASH Adobe Flash Player hitTest CVE-2016- BitmapData object Multimedia 1 0963 integer overflow attempt FILE-FLASH Adobe Flash Player invalid CVE-2016- sourceRect copyPixels Multimedia 1 0968 heap corruption attempt FILE-FLASH Adobe Flash Player JPEG handling CVE-2016- Multimedia 1 memory corruption 4229 attempt FILE-FLASH Adobe Flash CVE-2016- Player list filter memory Multimedia 1 0965 corruption attempt FILE-FLASH Adobe Flash Player M3U8 parser CVE-2015- Multimedia 1 logic memory 8457 corruption attempt FILE-FLASH Adobe Flash Player malformed tag CVE-2016- Multimedia 1 out of bounds read 4176 attempt FILE-FLASH Adobe Flash Player MP3 ID3 data CVE-2015- Multimedia 1 parsing heap buffer 8446 overflow attempt FILE-FLASH Adobe Flash Player onSetFocus CVE-2017- Multimedia 1 movieclip use after free 2932 attempt FILE-FLASH Adobe Flash CVE-2015- Multimedia 1 October 2019 Page 5 of 27 IPS Signature Update Player oversize source 8419 bitmap memory corruption attempt FILE-FLASH Adobe Flash Player Point object CVE-2016- Multimedia 1 integer overflow 0976 attempt FILE-FLASH Adobe Flash Player Point object CVE-2016- Multimedia 1 integer overflow 0979 attempt FILE-FLASH Adobe Flash Player ShaderParameter CVE-2015- Multimedia 1 integer overflow 8445 attempt FILE-FLASH Adobe Flash Player SharedObject CVE-2015- Multimedia 1 send stack buffer 8407 overflow attempt FILE-FLASH Adobe Flash Player CVE-2017- ShimContentResolver Multimedia 1 2996 out of bounds memory access attempt FILE-FLASH Adobe Flash CVE-2016- Player si32 integer Multimedia 1 0993 overflow attempt FILE-FLASH Adobe Flash Player String length CVE-2015- Multimedia 1 heap buffer overflow 8438 attempt FILE-FLASH Adobe Flash CVE-2016- Player TextLine memory Multimedia 1 0966 corruption attempt October 2019 Page 6 of 27 IPS Signature Update FILE-FLASH Adobe Flash Player toString type CVE-2016- Multimedia 1 confusion memory 1019 corruption attempt FILE-IDENTIFY Adobe Acrobat JOBOPTIONS CVE-2019- Application 4 File Parsing Out of 7111 and Software Bounds Write FILE-IDENTIFY FDF file Application 4 download request and Software FILE-IMAGE Adobe Acrobat CVE-2017- CVE-2017- 16399 XPS unicode Multimedia 2 16399 glyph pointer out of bounds FILE-MULTIMEDIA Adobe Acrobat CVE-2017- ImageConversion EMF Multimedia 3 11227 Parsing Integer Overflow FILE-OFFICE LibreOffice CVE-2018-6871 CVE-2018- Office Tools 2 WEBSERVICE 6871 Information Disclosure FILE-OFFICE Microsoft CVE-2018- Excel out of bounds Office Tools 2 1030 read attempt FILE-OFFICE Microsoft Office CVE-2018-1028 CVE-2018- Office Tools 2 Remote Code Execution 1028 Vulnerability FILE-OFFICE Microsoft CVE-2017- Office Tools 1 Office Equation Editor 11882 object stack buffer October 2019 Page 7 of 27 IPS Signature Update overflow attempt FILE-OFFICE Microsoft Office Word OGL CVE-2015- Office Tools 1 module out of bounds 6106 read attempt FILE-OTHER Acrobat Reader CVE-2018-12761 CVE-2018- Application 1 Information Disclosure 12761 and Software Vulnerability FILE-OTHER Acrobat Reader CVE-2018-12856 CVE-2018- Application 2 Information Disclosure 12856 and Software Vulnerability FILE-OTHER Adobe Acrobat and Reader CVE-2018- Application docID Stack Buffer 2 4901 and Software Overflow crash CVE- 2018-4901 FILE-OTHER Adobe Acrobat and Reader CVE-2018- Application docID Stack Buffer 2 4901 and Software Overflow leak CVE- 2018-4901 FILE-OTHER Adobe Acrobat CVE-2018- CVE-2018- Application 2 15986 Memory 15986 and Software Corruption FILE-OTHER Adobe Acrobat EMF CVE-2018- CVE-2018- Application 5067 EmfPlusDrawLines 2 5067 and Software Count Heap Buffer Overflow FILE-OTHER Adobe CVE-2018- Application 2 Acrobat EMF 16020 and Software EMR_CREATEMONOBR October 2019 Page 8 of 27 IPS Signature Update USH out-of-bounds write attempt FILE-OTHER Adobe Acrobat EMF file GIF CVE-2017- Application 2 sub-block memory 11260 and Software corruption attempt FILE-OTHER Adobe Acrobat JavaScript CVE-2019- Application 2 engine security bypass 7041 and Software attempt FILE-OTHER Adobe Acrobat JOBOPTIONS CVE-2019- Application 2 File Parsing Out of 7111 and Software Bounds Write FILE-OTHER Adobe CVE-2019- Application Acrobat out-of-bounds 2 7122 and Software read attempt FILE-OTHER Adobe CVE-2019- Application Acrobat out-of-bounds 2 7127 and Software read attempt FILE-OTHER Adobe Acrobat PostScript file CVE-2019- Application 2 parsing TBuildCharDict 7084 and Software use after free attempt FILE-OTHER Adobe Acrobat Pro CVE-2018- CVE-2018- Application 19704 XPS file image- 2 19704 and Software load out-of-bounds read attempt FILE-OTHER Adobe Acrobat pro CVE-2018- CVE-2018- Application 1 4916 Out Of Bounds 4916 and Software Read Attempt October 2019 Page 9 of 27 IPS Signature Update FILE-OTHER Adobe CVE-2019- Application Acrobat type confusion 2 7069 and Software attempt FILE-OTHER Adobe CVE-2019- Application Acrobat type confusion 2 7128 and Software attempt FILE-OTHER Adobe Acrobat XPS Path CVE-2018- Application 1 Element Out of Bounds 4898 and Software Write CVE-2018-4898 FILE-OTHER Adobe Photoshop CVE-2016- CVE-2016- Application 0953 CC Bridge CC IFF 2 0953 and Software File Parsing Buffer Overflow FILE-OTHER Adobe CVE-2019- Application Reader CVE-2019-7828 2 7828 and Software Heap Overflow FILE-OTHER Adobe Reader EMF CVE-2018- CVE-2018- Application 2 15990 Remote Code 15990 and Software Execution FILE-OTHER Adobe CVE-2018- Application Reader EMF CVE-2018- 2 16006 and Software 16006 Use After Free FILE-OTHER Adobe CVE-2018- Application Reader XPS CVE-2018- 2 16015 and Software 16015 Out Of Bounds FILE-OTHER Delta Industrial Automation CVE-2019- Application CNCSoft ScreenEditor 4 10947 and Software DPB wFontTextLen Stack Buffer Overflow October 2019 Page 10 of 27 IPS Signature Update FILE-OTHER Microsoft CVE-2017- Application Graphics remote code 2 11763 and Software execution attempt FILE-OTHER Microsoft CVE-2018- Application Graphics remote code 2 8344 and Software execution attempt FILE-OTHER Microsoft Windows Defender CVE-2018- Application malformed RAR 2 0986 and Software memory corruption attempt FILE-OTHER Microsoft CVE-2017- Application Windows TTF file out of 1 0083 and Software bounds access attempt FILE-OTHER TrueType Font Windows EOT font CVE-2018- Application 2 engine remote code 1016 and Software execution attempt FILE-OTHER VMware CVE-2019- Application Fusion Guest