Release notes for update package 1791-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Monday October 21, 2024
MD5 CHECKSUM:     fc43d498ea122461e70825984373be2e
SHA1 CHECKSUM:     0aff12985096cb5b95e0e76350db79c88d57cdba
SHA256 CHECKSUM:     3c11a5e9bb0788e5490187038499eeefacd95d28e7738ea46e870b31e8549328


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Apport detected     CVE-2016-9949     Apport-Remote-Code-Execution-Via-CrashDB-Field-CVE-2016-9949

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Apport-Remote-Code-Execution-Via-CrashDB-Field-CVE-2016-9949 CVE-2016-9949 File-Text_Apport-Remote-Code-Execution-Via-CrashDB-Field-CVE-2016-9949 Suspected Compromise

Updated detected attacks:

Other Binary File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High CUPS-Remote-Command-Execution-Via-FoomaticRIPCommandLine-CVE-2024-47177 CVE-2024-47177 File-Binary_CUPS-Remote-Command-Execution-Via-FoomaticRIPCommandLine-CVE-2024-47177 Suspected Compromise
Description has changed
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Category Apport
Certificate Authority SecureSign Root CA12
Certificate Authority SecureSign Root CA14
Certificate Authority SecureSign Root CA15
Certificate Authority TWCA CYBER Root CA
Certificate Authority TWCA Global Root CA G2
Certificate Authority Certum Trusted Root CA (1)
Certificate Authority SSL Secure Site CA
Certificate Authority JoySSL DV TLS G2 R33 CA
Certificate Authority Shoper DV TLS G2 R34 CA
Certificate Authority XinChaCha Trust EV TLS G2 R34 CA
Certificate Authority DigiCert Assured ID TLS RSA4096 SHA256 2022 CA1
Certificate Authority GandiCert
Certificate Authority TrustAsia TLS RSA CA G8
Certificate Authority DigiCert Secure Site Pro G3 TLS CN ECC P-384 SHA384 2022 CA1
Certificate Authority Microsoft Azure ECC TLS Issuing CA 08
Certificate Authority Entrust Root Certification Authority - G2 (1)
Certificate Authority GlobalSign Atlas R3 AlphaSSL CA 2024 Q3
Certificate Authority GlobalSign Atlas R3 DV TLS CA 2024 Q4
Certificate Authority Keysec GR3 OV TLS CA 2024
Certificate Authority NAVER Secure Certification Authority 1
Certificate Authority Sectigo Public Server Authentication Root E46 (1)
Certificate Authority Sectigo Public Server Authentication Root R46 (1)
Certificate Authority Sectigo SHA-256 OV Secure Server CA
Certificate Authority SSL.com TLS Transit RSA CA R2
Certificate Authority Apple Public Server ECC CA 11 - G1
Certificate Authority cPanel ECC Domain Validation Secure Server CA 3
Certificate Authority cPanel RSA Domain Validation Secure Server CA 3
Certificate Authority Sectigo Public Server Authentication Root E46 (2)
Certificate Authority TrustAsia ECC OV TLS CA G3
Certificate Authority CloudSecure RSA Extended Validation Secure Server CA 2
Certificate Authority Valid Certificadora RSA EV SSL CA
Certificate Authority XinChaCha Trust DV CA
Certificate Authority 纳网 RSA Domain Validation Secure Server CA
Certificate Authority 纳网 RSA Organization Validation Secure Server CA
Certificate Authority SHECA DV Server CA G5
Certificate Authority SSL.com TLS RSA Root CA 2022 (1)
Certificate Authority Domain The Net Technologies Ltd CA for TLS R3
Certificate Authority Entrust OV TLS Issuing RSA CA 1
Certificate Authority Leocert TLS Issuing RSA CA 1
Certificate Authority Telia RSA TLS Root CA v3

Updated objects:

Type Name Changes
Situation URL_List-DNS-Over-HTTPS
Detection mechanism updated
Situation URL_List-Common_Global_CRL
Detection mechanism updated
Situation URL_List-Common_Global_OCSP
Detection mechanism updated
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList TOR relay nodes IP Address List
IPList Zscaler IP Address List
IPList Amazon ROUTE53_HEALTHCHECKS_PUBLISHING
IPList Malicious Site IP Address List
IPList Amazon AMAZON ap-southeast-6
IPList Amazon EC2 ap-southeast-6
IPList NordVPN Servers IP Address List
IPList Amazon AMAZON ap-southeast-5
IPList Amazon EC2 ap-southeast-5
IPList Amazon AMAZON me-south-1
IPList Amazon EC2 me-south-1
IPList Forcepoint Drop IP Address List
IPList Amazon AMAZON us-west-2
IPList Amazon EC2 us-west-2
Situation File-Name_Shared-Variables
Application TOR
Application DNS-Over-HTTPS
Application NordVPN
Situation URL_List-Common_Global_CRL
Detection mechanism updated
Situation URL_List-Common_Global_OCSP
Detection mechanism updated

DISCLAIMER AND COPYRIGHT

Copyright © 2024 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.