ruleUpdate
18-035 (28 de июня de 2018)
Publish Date: 28 de июня de 2018
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption
CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution
FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow
HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow
LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow
Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service
RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability
Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability
Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)
Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability
Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption
CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution
FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow
HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow
LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow
Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service
RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability
Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability
Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)
Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability
Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.