Rule Update
18-035 (June 28, 2018)
Publish date: June 28, 2018
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption
CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution
FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow
HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow
LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow
Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service
RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability
Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability
Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)
Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability
Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Backup Server IBM Tivoli Storage Manager
1003393* - IBM Tivoli Storage Manager Express Backup Heap Corruption
CA ARCserve D2D Administration Interface
1004564* - CA ARCserve D2D Axis2 Default Credentials Remote Code Execution
FTP Client Windows
1002732* - FlashGet FTP 'PWD' Response Remote Buffer Overflow
HP OpenView
1003948* - HP OpenView Storage Data Protector Cell Manager Heap Buffer Overflow
LANDesk Management Suite QIP Server
1002912* - LANDesk Management Suite QIP Service Heal Packet Buffer Overflow
Oracle Secure Backup
1003382* - Oracle Secure Backup NDMP Packet Handling Multiple Denial Of Service
RealPlayer RTSP Client
1004554* - RealNetworks RealPlayer 'GIF87a' File Parsing Heap Overflow Vulnerability
Sybase Open Server
1004771* - Sybase Adaptive Server Backup And Monitor Server NULL Write Remote Code Execution Vulnerability
Web Application Common
1009111* - ImageMagick 'DecodeLabImage' And 'EncodeLabImage' Denial Of Service Vulnerability (CVE-2018-9133) - 1
1009109* - ImageMagick 'IsWEBPImageLossless' Heap Buffer Over Read Vulnerability (CVE-2018-9135) - 1
1009118* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-8804) - 1
1008986* - ImageMagick 'load_tile' Denial Of Service Vulnerability (CVE-2017-13133) - 1
Web Application PHP Based
1008895* - PHP 'php_wddx_push_element' Function Out Of Bound Read Vulnerability (CVE-2016-7418)
1009168 - WordPress Authenticated Arbitrary File Deletion Vulnerability (CVE-2018-12895)
Web Client Internet Explorer/Edge
1002702* - Microsoft Uninitialized Memory Corruption Vulnerability
Web Server Apache
1009045* - Apache httpd 'mod_cache_socache' Denial Of Service Vulnerability (CVE-2018-1303)
Web Server Miscellaneous
1004628* - VLC Media Player Web Interface 'input' Parameter Remote Buffer Overflow Vulnerability
Web Server RealVNC
1004146* - RealVNC 'ClientCutText' Message Memory Corruption
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more
- A Closer Exploration of Residential Proxies and CAPTCHA-Breaking ServicesThis article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.Read more
- How Residential Proxies and CAPTCHA-Solving Services Become Agents of AbuseThis article, the first of a two-part series, provides insights on how abusers and cybercriminals use residential proxies and CAPTCHA-solving services to enable bots, scrapers, and stuffers, and proposes security countermeasures for organizations.Read more