IPS Signature Release Note V7.16.66
Total Page:16
File Type:pdf, Size:1020Kb
SOPHOS IPS Signature Update Release Notes Version : 7.16.66 Release Date : 16th January 2020 IPS Signature Update Release Information Upgrade Applicable on IPS Signature Release Version 7.16.65 Sophos Appliance Models XG-550, XG-750, XG-650 Upgrade Information Upgrade type: Automatic Compatibility Annotations: None Introduction The Release Note document for IPS Signature Database Version 7.16.66 includes support for the new signatures. The following sections describe the release in detail. New IPS Signatures The Sophos Intrusion Prevention System shields the network from known attacks by matching the network traffic against the signatures in the IPS Signature Database. These signatures are developed to significantly increase detection performance and reduce the false alarms. Report false positives at [email protected], along with the application details. January 2020 Page 2 of 54 IPS Signature Update This IPS Release includes Four Hundred and Fifty(450) signatures to address Three Hundred and Eighty Eight(388) vulnerabilities. New signatures are added for the following vulnerabilities: Name CVE–ID Category Severity BROWSER-CHROME Google Chrome CVE-2014- locationAttributeSetter Browsers 2 1713 Use After Free (Published Exploit) BROWSER-FIREFOX Mozilla Firefox Built-in CVE-2015- PDF Viewer Same Origin Browsers 3 4495 Policy Bypass (Published Exploit) BROWSER-FIREFOX Mozilla Firefox CVE- CVE-2017- 2017-5428 Browsers 2 5428 createImageBitmap Integer Overflow BROWSER-FIREFOX Mozilla Firefox CVE-2006- DOMNodeRemoved Browsers 1 2779 Memory Corruption (Published Exploit) BROWSER-FIREFOX Mozilla Firefox IconURL CVE-2005- Browsers 3 Arbitrary JavaScript 1477 Execution BROWSER-FIREFOX Mozilla Firefox CVE-2005- JavaScript Engine Browsers 3 0989 Information Disclosure (Published Exploit) January 2020 Page 3 of 54 IPS Signature Update BROWSER-FIREFOX Mozilla Firefox CVE-2009- nsPropertyTable Browsers 1 3070 PropertyList Memory Corruption BROWSER-FIREFOX Mozilla Firefox PKCS11 CVE-2009- Browsers 1 Module Installation 3076 Code Execution BROWSER-FIREFOX Mozilla Firefox Plugin CVE-2005- Browsers 3 Access Control 0527 Vulnerability BROWSER-FIREFOX Mozilla Firefox XUL CVE-2008- Browsers 3 Frame Tree Memory 5016 Corruption BROWSER-FIREFOX Mozilla Multiple CVE-2012- Products WAV Browsers 3 4186 Processing Buffer Overflow BROWSER-FIREFOX Mozilla Products CVE-2005- Malformed GIF Buffer Browsers 3 0399 Overflow (Published Exploit) BROWSER-IE IBM SPSS SamplePower CVE- CVE-2012- 2012-5945 Vsflex8l Browsers 2 5945 ActiveX Control Buffer Overflow BROWSER-IE Microsoft CVE-2017- Browsers 2 Edge Chakra CVE-2017- 0010 0010 Remote Code January 2020 Page 4 of 54 IPS Signature Update Execution BROWSER-IE Microsoft Edge Chakra Eval CVE- CVE-2017- Browsers 1 2017-8636 Integer 8636 Overflow BROWSER-IE Microsoft Edge Chakra JavaScript CVE-2016- CVE-2016-0024 engine Browsers 1 0024 out of bounds read attempt BROWSER-IE Microsoft Edge CVE-2016-7242 CVE-2016- Browsers 3 Array.concat Type 7242 Confusion Attempt BROWSER-IE Microsoft Edge CVE-2017-0208 CVE-2017- repeat Sign Extension Browsers 3 0208 Information Disclosure II BROWSER-IE Microsoft Edge CVE-2017-0208 CVE-2017- Browsers 3 repeat Sign Extension 0208 Information Disclosure I BROWSER-IE Microsoft CVE-2017- Edge CVE-2017-8652 Browsers 1 8652 Use After Free BROWSER-IE Microsoft Edge CVE-2017-8656 CVE-2017- PreVisitCatch Browsers 2 8656 Uninitialized Memory Use II BROWSER-IE Microsoft CVE-2017- Browsers 2 Edge CVE-2017-8656 8656 PreVisitCatch January 2020 Page 5 of 54 IPS Signature Update Uninitialized Memory Use I BROWSER-IE Microsoft Edge CVE-2017-8671 CVE-2017- Browsers 2 Chakra Arguments Off 8671 By One I BROWSER-IE Microsoft Internet CVE-2015-2425 CVE-2015- Explorer Browsers 2 2425 MutationObserver use after free attempt BROWSER-IE Microsoft Internet Explorer and CVE-2010- SharePoint Services Browsers 3 3324 HTML Sanitization Cross-Site Scripting BROWSER-IE Microsoft Internet Explorer CVE-2012- Browsers 1 Asynchronous NULL 2521 Memory Corruption BROWSER-IE Microsoft CVE-2005- Internet Explorer CDF Browsers 3 0056 Cross Domain Scripting BROWSER-IE Microsoft Internet Explorer CVE-2006- Browsers 1 createTextRange Code 1359 Execution BROWSER-IE Microsoft Internet Explorer CVE-2016- Browsers 2 CTravelEntry Memory 0113 Corruption BROWSER-IE Microsoft CVE-2012- Browsers 2 Internet Explorer CVE- 0010 2012-0010 Copy And January 2020 Page 6 of 54 IPS Signature Update Paste Information Disclosure BROWSER-IE Microsoft Internet Explorer CVE- CVE-2012- 2012-4792 Browsers 2 4792 applyElement Use After Free (Published Exploit) BROWSER-IE Microsoft Internet Explorer CVE- CVE-2014- Browsers 1 2014-0305 pastHTML 0305 Use After Free II BROWSER-IE Microsoft Internet Explorer CVE- CVE-2014- Browsers 1 2014-2782 Use After 2782 Free (Published Exploit) BROWSER-IE Microsoft Internet Explorer CVE- CVE-2015- Browsers 1 2015-0046 Type 0046 Confusion BROWSER-IE Microsoft Internet Explorer CVE- CVE-2015- 2015-2419 JSON Browsers 1 2419 Stringify Double Free Attempt BROWSER-IE Microsoft Internet Explorer CVE- CVE-2016- Browsers 1 2016-0186 Uninitialized 0186 Pointer Attempt II BROWSER-IE Microsoft Internet Explorer daxctle.ocx Spline Browsers 1 Method Buffer Overflow BROWSER-IE Microsoft CVE-2005- Browsers 3 January 2020 Page 7 of 54 IPS Signature Update Internet Explorer 0553 DHTML Object Memory Corruption BROWSER-IE Microsoft Internet Explorer CVE-2004- Browsers 2 execCommand File Type 1331 Spoofing BROWSER-IE Microsoft Internet Explorer File Browsers 1 Download Extension Spoofing BROWSER-IE Microsoft Internet Explorer FTP CVE-2004- Client Directory Browsers 1 1376 Traversal (Published Exploit) BROWSER-IE Microsoft Internet Explorer HTML CVE-2008- Browsers 1 Attribute Handling 3476 Memory Corruption BROWSER-IE Microsoft Internet Explorer HTML CVE-2006- Browsers 2 Tag Memory Corruption 1188 (Published Exploit) BROWSER-IE Microsoft Internet Explorer Print CVE-2013- Browsers 3 Preview Information 3908 Disclosure BROWSER-IE Microsoft Internet Explorer CVE-2016- Browsers 2 PROPERTYDESC Double 0111 Free CVE-2010- BROWSER-IE Microsoft Browsers 1 Internet Explorer Select 3345 January 2020 Page 8 of 54 IPS Signature Update Element Memory Corruption BROWSER-IE Microsoft Internet Explorer CVE-2013- Browsers 1 textNode Use After Free 1311 (Published Exploit) BROWSER-IE Microsoft Internet Explorer CVE-2011- Browsers 1 Uninitialized Object 0036 Memory Corruption BROWSER-OTHER Apple Safari WebKit CVE-2011- innerHTML Double Free Browsers 1 0221 Memory Corruption (Published Exploit) BROWSER-OTHER Apple Safari WebKit Selections CVE-2010- Browsers 3 Use After Free 1812 (Published Exploit) BROWSER-PLUGINS Adobe Download CVE-2009- Manager getPlus Browsers 1 3958 ActiveX Control Buffer Overflow BROWSER-PLUGINS Citrix Access Gateway CVE-2011- Plug-in for Windows Browsers 1 2592 nsepacom ActiveX Control Buffer Overflow BROWSER-PLUGINS EDB IBM Lotus Domino Web CVE-2007- Browsers 1 Access ActiveX Controls 4474 Buffer Overflow BROWSER-PLUGINS CVE-2011- Browsers 3 January 2020 Page 9 of 54 IPS Signature Update Flexera InstallShield 3174 ISGrid2.dll DoFindReplace Heap Buffer Overflows BROWSER-PLUGINS Google Apps Browsers 1 googleapps.url.mailto URI Argument Injection BROWSER-PLUGINS HP Application Lifecycle Management ActiveX Browsers 2 Control Insecure Method Exposure BROWSER-PLUGINS HP LoadRunner CVE-2013- lrFileIOService ActiveX Browsers 2 2370 Control Input Validation Error BROWSER-PLUGINS HP LoadRunner XUpload.ocx ActiveX Browsers 1 Control Arbitrary File Download BROWSER-PLUGINS HP Software Update CVE-2008- Browsers 3 HPeDiag ActiveX 0712 Control Buffer Overflow BROWSER-PLUGINS HP Sprinter CVE-2014-2638 CVE-2014- Tidestone Formula One Browsers 2 2638 DefaultFontName Buffer Overflow I BROWSER-PLUGINS IBM CVE-2012- Browsers 2 Lotus iNotes 2175 dwa85W.dll ActiveX January 2020 Page 10 of 54 IPS Signature Update Control Buffer Overflow BROWSER-PLUGINS IBM Lotus Quickr qp2.cab CVE-2012- Browsers 1 ActiveX Control Stack 2176 Buffer Overflow BROWSER-PLUGINS IBM Lotus Quickr qp2.cab CVE-2012- Browsers 2 ActiveX Control Stack 2176 Buffer Overflow BROWSER-PLUGINS IBM SPSS VsVIEW6.ocx CVE-2012- Browsers 1 ActiveX control Code 0189 Execution BROWSER-PLUGINS McAfee Virtual Technician Browsers 2 MVT.MVTControl ActiveX Control Insecure Method BROWSER-PLUGINS Microsoft Access Snapshot Viewer CVE-2008- Browsers 3 ActiveX Control 2463 snapview.ocx Code Execution BROWSER-PLUGINS Microsoft Internet CVE-2007- Explorer Pdwizard.ocx Browsers 1 3041 ActiveX Object Memory Corruption BROWSER-PLUGINS Microsoft Office MSODataSourceControl Browsers 1 ActiveX Control Denial of Service January 2020 Page 11 of 54 IPS Signature Update BROWSER-PLUGINS Microsoft Video ActiveX CVE-2008- Browsers 1 Control Stack Buffer 0015 Overflow BROWSER-PLUGINS Microsoft Windows CVE-2013- CVE-2013-1296 Remote Browsers 2 1296 Desktop Client ActiveX Control Use After Free BROWSER-PLUGINS MW6 Technologies CVE-2009- Browsers 1 Barcode.dll ActiveX 0298 Control Buffer Overflow BROWSER-PLUGINS NetIQ Security Solutions CVE-2015- for ISeries Browsers 3 0795 SafeShellExecute Stack Buffer Overflow BROWSER-PLUGINS Novell GroupWise CVE-2012- Client for Windows Browsers 1 0439 ActiveX Code Execution (Published Exploit) BROWSER-PLUGINS Novell iPrint Client Browsers 1 ActiveX Control Stack Buffer Overflow BROWSER-PLUGINS Novell iPrint Client Browsers 1 GetDriverSettings Stack Buffer Overflow BROWSER-PLUGINS Novell iPrint Client CVE-2009- Browsers 1 ienipp.ocx target-frame 1568 Stack Buffer Overflow January 2020 Page