Release notes for update package 1845-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Thursday March 06, 2025
MD5 CHECKSUM:     4d2b6fbd0ae88b269eca2c236616da0e
SHA1 CHECKSUM:     f552aa1db2134b1b10f100f54a913a4f3817093e
SHA256 CHECKSUM:     762f9e545aee761143dc313e068e44c94c2f41a89731f23e21905c6583207ffa


UPDATE CRITICALITY:    MODERATE

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS


Updated detected attacks:

OLE File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Microsoft-Publisher-Invalid-Pointer-CVE-2011-3411 CVE-2011-3411 File-OLE_Microsoft-Publisher-Invalid-Pointer-CVE-2011-3411 Potential Compromise
Description has changed

PNG File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Mozilla-Firefox-Animated-PNG-Processing-Integer-Overflow CVE-2008-4064 File-PNG_Mozilla-Firefox-Animated-PNG-Processing-Integer-Overflow Potential Compromise
Fingerprint regexp changed
High Microsoft-Windows-Gdiplus-PNG-Processing-Integer-Overflow CVE-2009-3126 File-PNG_Microsoft-Windows-Gdiplus-PNG-Processing-Integer-Overflow Potential Compromise
Fingerprint regexp changed
High Microsoft-GDI-Vulnerability-CVE-2009-2501 CVE-2009-2501 File-PNG_Microsoft-Multiple-Products-Buffer-Overflow Potential Compromise
Detection mechanism updated
High PNG-GD-Graphics-Library-Rowbytes-And-Height-BOF CVE-2004-0990 File-PNG_PNG-Image-With-Large-Height-Or-Width-Value Potential Compromise
Fingerprint regexp changed
High Libpng-PNG-Decompress-Chunk-Integer-Overflow CVE-2011-3026 File-PNG_Libpng-PNG-Decompress-Chunk-Integer-Overflow Potential Compromise
Fingerprint regexp changed
High Adobe-Photoshop-PNG-Image-Processing-Buffer-Overflow CVE-2012-4170 File-PNG_Adobe-Photoshop-PNG-Image-Processing-Buffer-Overflow Suspected Compromise
Fingerprint regexp changed
High Microsoft-Ie-PNG-Parsing-Vulnerability-CVE-2015-0080 CVE-2015-0080 File-PNG_Microsoft-Ie-PNG-Parsing-Vulnerability-CVE-2015-0080 Potential Compromise
Detection mechanism updated
High Foxit-Multiple-Products-PNG-To-PDF-Conversion-Heap-Buffer-Overflow No CVE/CAN File-PNG_Foxit-Multiple-Products-PNG-To-PDF-Conversion-Heap-Buffer-Overflow Suspected Compromise
Fingerprint regexp changed
High Microsoft-Windows-Image-ICC-Profile-Code-Execution CVE-2018-8475 File-PNG_Microsoft-Windows-Image-ICC-Profile-Code-Execution Suspected Compromise
Detection mechanism updated
High Stegosploit No CVE/CAN File-PNG_HTML-Inside-PNG-File Suspected Compromise
Fingerprint regexp changed
High Stegosploit No CVE/CAN File-PNG_Script-Inside-PNG-File Suspected Compromise
Fingerprint regexp changed
High Imagemagick-PNG-Text-Profile-Arbitrary-File-Read CVE-2022-44268 File-PNG_Imagemagick-PNG-Text-Profile-Arbitrary-File-Read Potential Compromise
Fingerprint regexp changed
High Imagemagick-PNG-Text-Profile-Denial-Of-Service CVE-2022-44267 File-PNG_Imagemagick-PNG-Text-Profile-Denial-Of-Service Suspected Compromise
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Situation File-PNG_Shared-Variables

Updated objects:

Type Name Changes
Report Template Weekly Vulnerability Summary
Report Template Network Application Usage
Report Template Threat Summary
Report Template GDPR Data Subject Summary
Report Template Weekly SD-WAN Summary
Certificate Authority AC Firmaprofesional - Secure Web 2022
Marked for removal
Situation URL_List-DNS-Over-HTTPS
Detection mechanism updated
IPList Iraq
IPList Saudi Arabia
IPList Iran
IPList Cyprus
IPList Armenia
IPList Kenya
IPList Seychelles
IPList Jordan
IPList Lebanon
IPList Kuwait
IPList Oman
IPList Qatar
IPList Bahrain
IPList United Arab Emirates
IPList Israel
IPList Türkiye
IPList Egypt
IPList Greece
IPList Estonia
IPList Latvia
IPList Azerbaijan
IPList Lithuania
IPList Georgia
IPList Moldova
IPList Finland
IPList Ukraine
IPList Hungary
IPList Bulgaria
IPList Albania
IPList Poland
IPList Romania
IPList Kosovo
IPList Zimbabwe
IPList Zambia
IPList Botswana
IPList Mauritius
IPList Réunion
IPList South Africa
IPList Mayotte
IPList Mozambique
IPList Madagascar
IPList Pakistan
IPList Bangladesh
IPList Sri Lanka
IPList India
IPList Nepal
IPList Myanmar
IPList Uzbekistan
IPList Kazakhstan
IPList Kyrgyzstan
IPList French Southern Territories
IPList Cocos (Keeling) Islands
IPList Vietnam
IPList Thailand
IPList Indonesia
IPList Taiwan
IPList Philippines
IPList Malaysia
IPList China
IPList Hong Kong
IPList Brunei
IPList Macao
IPList Cambodia
IPList South Korea
IPList Japan
IPList North Korea
IPList Singapore
IPList Cook Islands
IPList Russia
IPList Mongolia
IPList Australia
IPList Papua New Guinea
IPList Solomon Islands
IPList New Caledonia
IPList Norfolk Island
IPList New Zealand
IPList Libya
IPList Senegal
IPList Portugal
IPList Liberia
IPList Ivory Coast
IPList Burkina Faso
IPList Sierra Leone
IPList Gambia
IPList Tunisia
IPList Spain
IPList Morocco
IPList Algeria
IPList Denmark
IPList Iceland
IPList United Kingdom
IPList Switzerland
IPList Sweden
IPList The Netherlands
IPList Austria
IPList Belgium
IPList Germany
IPList Luxembourg
IPList Ireland
IPList France
IPList Isle of Man
IPList Guernsey
IPList Slovakia
IPList Czechia
IPList Norway
IPList Italy
IPList Slovenia
IPList Croatia
IPList Bosnia and Herzegovina
IPList Angola
IPList Namibia
IPList Barbados
IPList Guyana
IPList French Guiana
IPList Suriname
IPList Paraguay
IPList Uruguay
IPList Brazil
IPList Jamaica
IPList Dominican Republic
IPList Martinique
IPList Bahamas
IPList Anguilla
IPList Trinidad and Tobago
IPList St Kitts and Nevis
IPList Dominica
IPList Antigua and Barbuda
IPList Saint Lucia
IPList Turks and Caicos Islands
IPList Aruba
IPList St Vincent and Grenadines
IPList Montserrat
IPList Saint Martin
IPList Guadeloupe
IPList Grenada
IPList Cayman Islands
IPList Belize
IPList El Salvador
IPList Guatemala
IPList Honduras
IPList Costa Rica
IPList Venezuela
IPList Ecuador
IPList Colombia
IPList Panama
IPList Haiti
IPList Argentina
IPList Chile
IPList Bolivia
IPList Peru
IPList Mexico
IPList Niue
IPList Guam
IPList Puerto Rico
IPList U.S. Virgin Islands
IPList Canada
IPList United States
IPList Palestine
IPList Serbia
IPList Antarctica
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList TOR relay nodes IP Address List
IPList Amazon AMAZON af-south-1
IPList Amazon EC2 af-south-1
IPList Amazon AMAZON ap-northeast-1
IPList Amazon EC2 ap-northeast-1
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList NordVPN Servers IP Address List
IPList Amazon AMAZON eu-west-2
IPList Amazon EC2 eu-west-2
IPList Amazon AMAZON us-east-1
IPList Amazon AMAZON eusc-de-east-1
IPList Forcepoint Drop IP Address List
IPList Amazon AMAZON us-west-2
IPList Zoom
IPList Google Cloud IP Address List for asia-south2
IPList Google Cloud IP Address List for australia-southeast1
IPList Google Cloud IP Address List for europe-west8
IPList Google Cloud IP Address List for southamerica-west1
Overview Template Security Engine Details
Overview Template Security Engine Overview
Overview Template SD-WAN Branch Details
Report Top Security Engine Connection States
Report Security Engine Traffic Trends (Counters)
Report Security Engine Summary (Counters)
Report Link Selections (Counters)
Report Link Selection Trends (Counters)
Situation LDAP_SS-Shared-Variables-For-Server-Stream-Context
Situation HTTP_PSU-Shared-Variables
Fingerprint regexp changed
Situation File-PNG_HTML-After-PNG-File-In-Same-Response
Category tag situation Obsolete added
Category tag os Any Operating System removed
Category tag hardware Any Hardware removed
Category tag os_not_specific Any Operating System not specific removed
Category tag situation Protocol Violations removed
Category tag group Anomalies removed
Fingerprint regexp changed
Situation File-PNG_Script-After-IEND-Chunk
Name: File-PNG_Script-After-PNG-File-In-Same-Response->File-PNG_Script-After-IEND-Chunk
Severity: 2->7
Comment has changed
Description has changed
Category tag situation Potential Compromise added
Category tag group Severity over 4 Correlation Dependency Group added
Category tag situation Protocol Violations removed
Category tag group Anomalies removed
Fingerprint regexp changed
Application Zoom
Application TOR
Application DNS-Over-HTTPS
Application NordVPN

DISCLAIMER AND COPYRIGHT

Copyright © 2025 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.