<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trigger for Sig 33439 - IE Memory Corruption Vulnerability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735106#M56271</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I'll open a service request with TAC and to see if I can get any clarification or more information.&amp;nbsp; I'll let y'all know what I find out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Sep 2011 13:22:45 GMT</pubDate>
    <dc:creator>Jonathan Grant</dc:creator>
    <dc:date>2011-09-16T13:22:45Z</dc:date>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735101#M56266</link>
      <description>&lt;P&gt;Hello all!&amp;nbsp; Sig 33439 was modified in S592 and I'm seeing a lot more alerts from this signature since we pushed S592.&amp;nbsp; Does anyone know what changed and what the trigger is that causes the signature to fire?&amp;nbsp; I have capture files and have not been able to identify anything malicious, nor what is causing it to fire.&amp;nbsp; If anyone can help me understand what the trigger is, I'm hoping I'll be able to identify what in the packets are causing the possible false-positives.&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735101#M56266</guid>
      <dc:creator>Jonathan Grant</dc:creator>
      <dc:date>2019-03-10T12:28:38Z</dc:date>
    </item>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735102#M56267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I've noticed this as well. As long as all machines running IE have the necessary patches, it shouldn't be a real problem but would be nice to know what's causing all the noise since S592 came out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 22:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735102#M56267</guid>
      <dc:creator>mark.barrett</dc:creator>
      <dc:date>2011-09-14T22:29:09Z</dc:date>
    </item>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735103#M56268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're working on this signature already and will update it shortly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin &lt;/P&gt;&lt;P&gt;IPS Signature Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 09:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735103#M56268</guid>
      <dc:creator>mzeiser</dc:creator>
      <dc:date>2011-09-15T09:41:18Z</dc:date>
    </item>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735104#M56269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm, are you saying the current signature is misconfigured and it will be corrected in a future release?&amp;nbsp; Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2011 13:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735104#M56269</guid>
      <dc:creator>Jonathan Grant</dc:creator>
      <dc:date>2011-09-15T13:17:22Z</dc:date>
    </item>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735105#M56270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the same issue here with several customers during the last two weeks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We waited for signatures updates if it was fixed but no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We disabled the signature in some customers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hugo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 12:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735105#M56270</guid>
      <dc:creator>Hugo Caye</dc:creator>
      <dc:date>2011-09-16T12:58:15Z</dc:date>
    </item>
    <item>
      <title>Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735106#M56271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I'll open a service request with TAC and to see if I can get any clarification or more information.&amp;nbsp; I'll let y'all know what I find out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 13:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735106#M56271</guid>
      <dc:creator>Jonathan Grant</dc:creator>
      <dc:date>2011-09-16T13:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735107#M56272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2011 13:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735107#M56272</guid>
      <dc:creator>Hugo Caye</dc:creator>
      <dc:date>2011-09-16T13:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735108#M56273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jonathan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any input from TAC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Sep 2011 12:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735108#M56273</guid>
      <dc:creator>Hugo Caye</dc:creator>
      <dc:date>2011-09-17T12:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735109#M56274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hugo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened an SR Friday morning, I received confirmation, but have not heard anything back since.&amp;nbsp; Cisco isn't being very responsive with this query at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2011 13:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735109#M56274</guid>
      <dc:creator>Jonathan Grant</dc:creator>
      <dc:date>2011-09-19T13:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735110#M56275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jonathan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We’re evaluating to disable this signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hugo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 01:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735110#M56275</guid>
      <dc:creator>Hugo Caye</dc:creator>
      <dc:date>2011-09-20T01:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735111#M56276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've had the same uptick in alerts on this signature, and now it's affecting a website that one of our users needs to access. Our systems are patched so I will likely just disable it for now, but I'll definitely watch this thread to see if Cisco updates with any information about a potential re-release of this sig.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Sep 2011 13:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735111#M56276</guid>
      <dc:creator>Daniel Barr</dc:creator>
      <dc:date>2011-09-20T13:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger for Sig 33439 - IE Memory Corruption Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735112#M56277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Signature &lt;STRONG&gt;S597&lt;/STRONG&gt; (just released) has retired this signature. I ended up disabling it on our systems anyway.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 21:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trigger-for-sig-33439-ie-memory-corruption-vulnerability/m-p/1735112#M56277</guid>
      <dc:creator>Daniel Barr</dc:creator>
      <dc:date>2011-09-22T21:56:08Z</dc:date>
    </item>
  </channel>
</rss>

