IPS Signature Database Release Notes V 5.15.89
Total Page:16
File Type:pdf, Size:1020Kb
IPS Signature Database Version: 5.15.89 IPS Signature Database Release Notesth Version 5.15.89 -----------------------------------------------------------------------------------------------------------------------------Release Notes Date:14 May---------------, 2019 Release Information Upgrade Applicable on IPS Signature Release Version 5.15.87 Cyberoam Appliance Models CR35wi, CR35ia, CR25wi, CR25ia, CR25i, CR15wi, CR15i Upgrade Information Upgrade type: Auto upgrade for Cyberoam Appliances Compatibility Annotations: None Introduction The Release Note document for IPS Signature Database Version 5.15.89 includes support for the new signatures. The following sections describe the release in detail. New IPS Signatures The Cyberoam Intrusion Prevention System shields the network from known attacks by matching the network traffic against the signatures in the IPS Signature Database. These signatures are developed to significantly increase detection performance and reduce the false alarms. Report false positives at [email protected] along with the application details. This IPS Release includes Two Thousand Two Hundred And Forty Three(2243) signatures to address One Thousand One Hundred And Forty Five(1145) vulnerabilities. Page 1 of 81 Document Version – 1.0- 14/05/2019 © Copyright 2019 Cyberoam Technologies Pvt. Ltd. All Rights Reserved. IPS Signature Database Release Notes Version 5.15.89 ----------------------------------------------------------------------------------------------------------------------------- --------------- Name CVE–ID Rev No. Category Severity Applicable from Version 3CX Phone System Web VAD_Deploy.aspx Arbitrary NA 1 Services and 1 10.06.1 Build 631 File Upload Applications Adobe Acrobat and Reader CVE- AcroForm Encoding Code 2017- 1 Multimedia 2 10.06.1 Build 631 Execution 11263 Adobe Acrobat and Reader CVE- docID Stack Buffer Overflow 1 Office Tools 1 10.06.1 Build 631 2018-4901 CVE-2018-4901 Adobe Acrobat and Reader CVE- JPEG2000 Out of Bounds 1 Office Tools 2 10.06.1 Build 631 2017-2946 Read Adobe Acrobat and Reader CVE- JPEG2000 Parsing Heap- 1 Office Tools 1 10.06.1 Build 631 2017-3055 based Buffer Overflow Adobe Acrobat and Reader CVE- JPEG2000 Parsing Out of 2017- 1 Office Tools 1 10.06.1 Build 631 Bounds Read 16374 Adobe Acrobat and Reader CVE- JPEG2000 Parsing Out of 1 Office Tools 1 10.06.1 Build 631 2017-3045 Bounds Read Adobe Acrobat CVE- ImageConversion EMF 2017- 1 Office Tools 1 10.06.1 Build 631 EmfPlus Heap-based Buffer 16416 Overflow Adobe Acrobat Application ImageConversion EMF CVE- 1 and 2 10.06.1 Build 631 EmfPlus Heap-based Buffer 2018-4895 Software Overflow Adobe Acrobat ImageConversion EMF CVE- 1 Office Tools 2 10.06.1 Build 631 EMR_STRETCHBLT Out of 2018-4886 Bounds Read Adobe Acrobat CVE- ImageConversion EMF 2017- 1 Office Tools 1 10.06.1 Build 631 EMR_STRETCHDIBITS 16397 Heap-based Buffer Overflow Adobe Acrobat CVE- ImageConversion EMF 2017- 1 Office Tools 1 10.06.1 Build 631 Integer Overflow CVE-2017- 11308 11308 Adobe Acrobat CVE- ImageConversion EMF 2017- 1 Misc 2 10.06.1 Build 631 Parsing Integer Overflow 11227 Adobe Acrobat CVE- 1 Office Tools 1 10.06.1 Build 631 ImageConversion EMF 2017- Page 2 of 81 Document Version – 1.0- 14/05/2019 © Copyright 2019 Cyberoam Technologies Pvt. Ltd. All Rights Reserved. IPS Signature Database Release Notes Version 5.15.89 ----------------------------------------------------------------------------------------------------------------------------- --------------- Parsing Out-Of-Bounds 11249 Read Adobe Acrobat CVE- ImageConversion JPEG 1 Office Tools 1 10.06.1 Build 631 2017-2959 Heap-based Buffer Overflow Adobe Acrobat CVE- ImageConversion JPEG 1 Multimedia 1 10.06.1 Build 631 2017-2960 Out-of-Bounds Read Adobe Acrobat ImageConversion PCX CVE- 1 Office Tools 1 10.06.1 Build 631 Parsing Out-Of-Bounds 2017-3036 Write Adobe Acrobat CVE- ImageConversion TIFF 1 Office Tools 2 10.06.1 Build 631 2017-2966 Heap-based Buffer Overflow Adobe Acrobat Reader CVE- JPEG2000 Information 1 Office Tools 3 10.06.1 Build 631 2016-1078 Disclosure Adobe ColdFusion RMI CVE- Registry Insecure 2017- 1 Misc 1 10.06.1 Build 631 Deserialization 11284 Adobe Flash MP3 ID3 Heap CVE- 1 Multimedia 3 10.06.1 Build 631 Buffer Overflow 2015-8446 Adobe Flash Player LocaleID CVE- 1 Office Tools 1 10.06.1 Build 631 determinePreferredLocales 2017-3114 Out-Of-Bounds Access Adobe JPEG 2000 Processing CVE-2017-3046 CVE- 1 Office Tools 1 10.06.1 Build 631 Memory Corruption 2017-3046 Vulnerability Adobe PDF Processing CVE- CVE-2017-3037 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3037 Corruption Vulnerability Adobe PDF Reader CVE- 2016-6944 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6944 Vulnerability Adobe PDF Reader CVE- 2016-6945 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6945 Vulnerability Adobe PDF Reader CVE- 2016-6950 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6950 Vulnerability Adobe PDF Reader CVE- CVE- 1 Office Tools 1 10.06.1 Build 631 2016-6952 Use-After-Free 2016-6952 Page 3 of 81 Document Version – 1.0- 14/05/2019 © Copyright 2019 Cyberoam Technologies Pvt. Ltd. All Rights Reserved. IPS Signature Database Release Notes Version 5.15.89 ----------------------------------------------------------------------------------------------------------------------------- --------------- Remote Code Execution Vulnerability Adobe PDF Reader CVE- 2016-6953 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6953 Vulnerability Adobe PDF Reader CVE- 2016-6958 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6958 Vulnerability Adobe PDF Reader CVE- 2016-6972 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6972 Vulnerability Adobe PDF Reader CVE- 2016-6988 Use-After-Free CVE- 1 Office Tools 1 10.06.1 Build 631 Remote Code Execution 2016-6988 Vulnerability Adobe Reader and Acrobat CVE- XSLT function-available 1 Misc 1 10.06.1 Build 631 2017-2949 Buffer Overflow Adobe Reader DC CVE- JPEG2000 CVE-2016-7854 1 Multimedia 1 10.06.1 Build 631 2016-7854 Out-of-Bounds Read Adobe Reader PDF Engine CVE- CVE-2017-3014 Use-After- 1 Office Tools 1 10.06.1 Build 631 2017-3014 Free Vulnerability Adobe Reader PDF Engine CVE- CVE-2017-3017 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3017 Corruption Vulnerability Adobe Reader PDF Engine CVE- CVE-2017-3021 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3021 Corruption Vulnerability Adobe Reader PDF Engine CVE- CVE-2017-3023 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3023 Corruption Vulnerability Adobe Reader PDF Engine CVE- CVE-2017-3026 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3026 Corruption Vulnerability II Adobe Reader PDF Engine CVE- CVE-2017-3026 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3026 Corruption Vulnerability I Adobe Reader PDF Engine CVE- CVE-2017-3027 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3027 Corruption Vulnerability Adobe TIFF File Processing CVE- CVE-2017-3048 Memory 1 Office Tools 1 10.06.1 Build 631 2017-3048 Corruption Vulnerability Page 4 of 81 Document Version – 1.0- 14/05/2019 © Copyright 2019 Cyberoam Technologies Pvt. Ltd. All Rights Reserved. IPS Signature Database Release Notes Version 5.15.89 ----------------------------------------------------------------------------------------------------------------------------- --------------- Adobe TIFF File Processing CVE- CVE-2017-3049 Heap 1 Office Tools 1 10.06.1 Build 631 2017-3049 Overflow Vulnerability Adobe TIFF Pixel Processing CVE-2017-3028 CVE- 1 Office Tools 1 10.06.1 Build 631 Memory Corruption 2017-3028 Vulnerability Advantech WebAccess Application CVE- Dashboard openWidget 1 and 2 10.06.1 Build 631 2016-0855 Directory Traversal Software Advantech WebAccess Application CVE- Dashboard removeFile 1 and 1 10.06.1 Build 631 2016-0855 Directory Traversal Software Advantech WebAccess Application CVE- Dashboard removeFolder 1 and 3 10.06.1 Build 631 2016-0855 Directory Traversal Software Advantech WebAccess Application CVE- Dashboard uploadFile 1 and 2 10.06.1 Build 631 2016-0854 Arbitrary File Upload Software Advantech WebAccess Application Dashboard CVE- 1 and 1 10.06.1 Build 631 uploadImageCommon 2016-0854 Software Arbitrary File Upload Advantech WebAccess Application datacore Service Function CVE- 1 and 1 10.06.1 Build 631 0x5228 strcpy Heap Buffer 2016-0857 Software Overflow Advantech WebAccess Application datacore Service Function CVE- 1 and 2 10.06.1 Build 631 0x523a strcpy Buffer 2016-0856 Software Overflow Advantech WebAccess CVE- Apache Node chkLogin2 SQL 1 2 10.06.1 Build 631 2018-5443 HTTP Server Injection Advantech WebAccess CVE- Web rmTemplate.aspx SQL 2017- 1 Services and 2 10.06.1 Build 631 Injection 12710 Applications Advantech WebAccess Web SCADA certUpdate.asp CVE- 1 Services and 1 10.06.1 Build 631 filename Directory Traversal 2018-5445 Applications CVE-2018-5445 Advantech WebAccess CVE- Web SCADA gmicons.asp picfile 2017- 1 Services and 1 10.06.1 Build 631 Arbitrary File Upload CVE- 16736 Applications 2017-16736 Advantech WebAccess Web CVE- updateTemplate.aspx SQL 1 Services and 2 10.06.1 Build 631 2017-5154 Injection Applications Page 5 of 81 Document Version – 1.0- 14/05/2019 © Copyright 2019 Cyberoam Technologies Pvt. Ltd. All Rights Reserved. IPS Signature Database Release Notes Version 5.15.89 -----------------------------------------------------------------------------------------------------------------------------