Snort mailing list archives

Sourcefire VRT Certified Snort Rules Update 2012-10-09


From: Research <research () sourcefire com>
Date: Tue, 9 Oct 2012 11:40:33 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Sourcefire VRT Certified Snort Rules Update

Synopsis:
The Sourcefire VRT is aware of multiple vulnerabilities affecting
products from Microsoft Corporation.

Details:
Microsoft Security Bulletin MS12-064:
Microsoft Word contains programming errors that may allow a remote
attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 24353, 24354, 24357
and 24358.

Microsoft Security Bulletin MS12-065:
Microsoft Works contains programming errors that may allow a remote
attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 24351 and 24352.

Microsoft Security Bulletin MS12-066:
A vulnerability in the Microsoft HTML santization component may allow
an attacker to elevate privileges.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 23136 and 23137.

Microsoft Security Bulletin MS12-069:
The Microsoft implementation of Kerberos may allow a remote attacker to
cause a Denial of Service (DoS) against an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 24360.

Microsoft Security Bulletin MS12-070:
A vulnerability in Microsoft SQL Server may allow a remote attacker to
elevate privileges.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 24355 and 24356.

For a complete list of new and modified rules please see:

http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-10-09.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFQdEOYaBoqZBVJfwMRAknSAJ4xNXtzouBBGqCYIpuUZV6neWhgOgCgmgvg
3QCMS3idHuP9JtsBkOVq7/c=
=2iW0
-----END PGP SIGNATURE-----


------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!


Current thread: