Cisco IPS Active Update Bulletin

March 26, 2009

Greetings! This bulletin describes updates to the Cisco IPS product line. As always, please feel free to e-mail us if you have any comments or questions (ips-...@cisco.com). We also encourage you to participate in the Cisco IPS User’s Forum at: http://www.cisco.com/discuss/security.

IN THIS ISSUE:

  1. Announcing the S388 Signature Update for IPS

  2. Announcing End-of-Life (EOL) for new signature updates in 4.x format for Cisco IOS IPS feature

  3. Cisco IPS Signature correlation available in the Cisco Security IntelliShield Alert Manager Service

  4. Subscribe to the Product Alert Tool for IPS Related Field Issues

  5. Subscription Information

 

1. Announcing the S388 Signature Update for IPS

The S388 signature update contains the following new signatures:

PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED
5.x,6.x 6085.0 IE Table Column Record Handling string-tcp high false
5.x,6.x 6108.0 FreeRADIUS Denial of Service atomic-ip medium false
5.x,6.x 6106.0 Cisco Secure ACS EAP-TLS Authentication Bypass string-udp medium false
5.x,6.x 6135.0 Sun Solaris in.rwhod Buffer Overflow string-udp high false
5.x,6.x 6732.0 CA BrightStor ARCServe Backup LGServer Password Buffer Overflow string-tcp high true
5.x,6.x 6734.0 CA ARCserve Backup LGServer Multiple Buffer Overflows string-tcp high false
5.x,6.x 6719.0 MySQL COM_TABLE_DUMP Function Stack Overflow string-tcp high false
5.x,6.x 6720.0 MySQL Login Handshake Information Disclosure string-tcp high false
5.x,6.x 6721.0 OpenBSD ISAKMP Message Handling Denial Of Service atomic-ip low false
5.x,6.x 6723.0 Sun Directory Server LDAP Denial of Service Details string-tcp medium false
5.x,6.x 3791.1 Solaris Printd Unlink File Deletion string-tcp medium false
5.x,6.x 6735.0 Microsoft Internet Explorer HHCtrl.ocx Image Property Heap Corruption multi-string medium false
5.x,6.x 6736.0 Apple QuickTime FLIC Animation File Buffer Overflow Details string-tcp medium false
5.x,6.x 6737.0 OpenSSL SSL_get_shared_ciphers Function Buffer Overflow string-tcp high false
5.x,6.x 6739.0 Novell GroupWise Messenger HTTP POST Request Invalid Memory Access string-tcp low false
5.x,6.x 6740.0 Trend Micro OfficeScan Atxconsole ActiveX Control Format String string-tcp medium false
5.x,6.x 6742.0 Microsoft PowerPoint Malformed Record Code Execution string-tcp medium false
5.x,6.x 15133.0 XML Race Condition in Internet Explorer string-tcp high false
5.x,6.x 7246.1 Microsoft Excel Spreadsheet Buffer Overflow string-tcp high false
5.x,6.x 15954.0 CA Multiple Products Console Server Buffer Overflow string-tcp high false
5.x,6.x 16013.0 Borland Interbase Integer Overflow Vulnerability string-tcp high true

The S388 signature update contains the following modified signatures:

PLATFORM SIGID SIGNAME ENGINE SEVERITY ENABLED
5.x,6.x 5569.0 MDaemon Imap Authentication Overflow string-tcp high true
5.x,6.x 5602.0 Windows System32 Directory File Access service-smb-advanced medium true
5.x,6.x 3003.0 TCP Frag SYN Port Sweep sweep high true
5.x,6.x 3180.1 BakBone NetVault Remote Heap Overflow string-tcp high false
5.x,6.x 3408.0 Telnet Client LINEMODE SLC Option Overflow string-tcp high false
5.x,6.x 5463.0 Computer Associates License Software GETCONFIG Buffer Overflow string-tcp high false
5.x,6.x 3157.0 FTP PASV Port Spoof service-ftp high true
5.x,6.x 3251.0 TCP Hijack Simplex Mode normalizer high false
5.x,6.x 6008.0 First 4 Internet XCP Uninstallation ActiveX Control string-tcp high false
5.x,6.x 3534.0 IMAP Long AUTHENTICATE Command string-tcp high true

Modified  signature details:  SFR has been increased for the following sigs: 3003-0 TCP Frag SYN Port Sweep 3157-0 FTP PASV Port Spoof 3534-0 IMAP Long AUTHENTICATE Command The following sigs have been retired: 3180-1 BakBone NetVault Remote Heap Overflow 3251-0 TCP Hijack Simplex Mode 3408-0 Telnet Client LINEMODE SLC Option Overflow 5463-0 Computer Associates License Software GETCONFIG Buffer Overflow 6008-0 First 4 Internet XCP Uninstallation ActiveX Control The following sigs have been modified to increase fidelity: 5569-0 MDaemon Imap Authentication Overflow 5602-0 Windows System32 Directory File Access

IMPORTANT NOTES:  All signature updates are cumulative. The S388 signature update contains all previously released signature updates.  You must have a valid Cisco Services for IPS contract per sensor to receive and use software upgrades including signature updates from Cisco.com.  A Cisco Services for IPS Services License is required for the installation of all signature updates. The Cisco Services for IPS Services License can be requested from http://www.cisco.com/go/license for all sensors covered by a maintenance contract.  To manage your maintenance contracts use the Service Contract Center:  http://www.cisco.com/cgi-bin/front.x/scccibdispatch?AppName=ContractAgent
  SUPPORTED PLATFORMS:  The S388 signature update can ONLY be applied to E3 sensors.  IPS S388 Software Update Files:  Sensor appliances, IDSM2, NM-CIDS, ASA-SSM-AIP modules: click here 
 IOS IPS in 12.4(11)T or later T-Train Releases: http://www.cisco.com/pcgi-bin/tablebuild.pl/ios-v5sigup Note: Posting of signature release files for IOS IPS may take a few additional days.
    CISCO SECURITY MANAGER (CSM) NOTICE:
Note 1:  You can only apply the IPS-CS-MGR-sig-S388-req-E3.zip signature update file to CSM 3.0 or later and IPS MC version 2.2 or later. The E3 Engine Update packages for sensors are deployed automatically the first time a signature set that requires E3 is deployed by CSM. E3 updates are not listed or available for selection in the Apply Update Wizard and cannot be applied independently by CSM. To ensure that the E3 update is applied to your sensors, please ensure that you push the S366 package to your sensors.  
 

2. Announcing End-of-Life (EOL) for new signature updates in 4.x format for Cisco IOS IPS feature

IMPORTANT ANNOUNCEMENT:
Cisco announces the End-of-Life (EOL) for new signature updates in Cisco IPS version 4.x format for Cisco IOS IPS feature.
No new signature releases in 4.x format and no new updates to the pre-built Basic or Advanced signature sets (128MB.sdf
and 256MB.sdf files) will be posted at
http://www.cisco.com/pcgi-bin/tablebuild.pl/ios-sigup after this time. IOS-S351.zip file
posted on August 20, 2008 is the final signature release and Version 10 of the recommended Basic and Advanced signature
sets posted on August 11, 2008 are the final recommended sets in 4.x format
for IOS IPS. Customers using IOS IPS feature
with
IOS Mainline and T-Train Releases prior to 12.4(11)T Release that work only with 4.x format IPS signatures are
strongly encouraged to upgrade their routers to run IOS 12.4(15)T7 or 12.4(20)T release as soon as possible.
 

 

3. Cisco IPS Signature correlation available in the Cisco. Security IntelliShield Alert Manager Service Search Access Feature

The Cisco IPS Team is pleased to announce the correlation of Cisco IPS Signature information within the IntelliShield Alert Manager Search Access Feature. Cisco Services for IPS clients that subscribe to the service now have access to perform targeted searches to display Cisco IPS Signatures associated with different alerts to ensure they have the most up to date intelligence. Subscribers can view a new IPS Signature list page that is searchable and will display Cisco IPS Signatures associated with IntelliShield Alerts. IntelliShield Alerts also contain the associated Cisco IPS Signature information within each alert.

The IntelliShield Alert Manager Search Access Feature provides clients with access to one of the most extensive collections of vendor-neutral security intelligence alerts in the industry. Clients can access a fully indexed and searchable database that extends back over six years and contains more than 1700 vendors, 5500 products, and 20,000 distinct versions of applications.

To obtain access to the IntelliShield Alert Manager Search Access Feature, each user is required to provide either a valid IPS License File or a valid IPS Serial Number to authorize the creation of this user account. Only one user account is permitted for each IPS License File or IPS Serial Number. Please proceed to the registration page at the following link to obtain your access:

https://intellishield.cisco.com/security/alertmanager/intelliShieldSearch 

Email support is available for users of the Cisco Security IntelliShield Alert Manager Service Search Access Feature at  intellishieldsearch-support@cisco.com . Support is provided by Cisco during the hours of 7:00 a.m. and 7:00 p.m. Eastern Time.

 

4. Subscribe to the Product Alert Tool for IPS Related Field Issues

Interested in knowing the latest on field notices, product alerts, and end-of-sale information relating to your IDS and IPS hardware? We have recently updated the Cisco Product Alert Tool to include IDS and IPS appliances.

Simply visit: http://tools.cisco.com/Support/PAT/do/ViewMyProfiles.do  and follow these steps:

- Select Create a new Alert Profile.
- Name your profile anything you would like.
- Under Select Your Product, select: Intrusion Prevention System
- Click Add so that “Intrusion Prevention System” is added to the “Products in your profile” list
- Select the message types you wish to receive
- Confirm your email address
- Click Submit.

You will be kept up to date with the latest news on your IPS hardware appliances.

 

5. Subscription Information

If you wish to receive this bulletin, you can subscribe now.

Your opinions are important to us. If you have feedback about the Active Update Bulletin, please contact us at ips-news@cisco.com. For technical support, sales or other issues, please contact your authorized Cisco reseller or Cisco TAC. Please note that technical support or sales questions sent to this address will not be answered or redirected.
 

Additional Information
 
Links

  • Software Center – Download the latest Cisco IPS software.
  • User Forum – Participate in the IPS Forum, part of our Networking Professionals Connection.
  • Home Page – Visit our Cisco IPS home page for product literature, news, and awards.
  • Cisco Security Center- Visit the Cisco Security Center site for information on emerging threats and the Cisco network IPS signatures available to protect your network..
  • CRMS – Cisco Remote Managed Services for Security
  • Training – Learn about available IPS training courses and Cisco Security Certifications.
  • IPS Technical Documentation – Visit our Cisco IPS Technical Documentation site for configuration guides, maintenance guides, release and installation notes and more
  • IntelliShield Alert Manager Search Access Feature – Search through an extensive collection of security intelligence reports. Registration required.

Leave a Reply

SEO Powered by Platinum SEO from Techblissonline