Guest

Cisco Security

Cisco Security

Potentially Vulnerable Browser Extension Download

 
Signature ID: 4141/0
Original Release:S743
Release:S743 (download)
Original Release Date:2013 September 23
Latest Release Date:2013 September 23
Default Enabled:False
Default Retired:True
Alarm Severity:Informational
Fidelity:80 

Description

This signature detects attempts at downloading PDF documents. While not a vulnerability in and of itself, some environments may wish to enforce a policy of not allowing PDF documents, or they may wish to temporarily disallow PDF documents due to new vulnerabilities being announced, or other concerns like this. Great care must be used in determining if this signature meets corporate guidance, and if this will negatively affect the end users or not.

Recommended Filter

There are no suggested filters.

Benign Triggers

This signature detects HTTP download requests for PDF files, which can be entirely legitimate behaviour. The sensor can not determine if the file will be handled by a vulnerable browser extension or reader at all. It is entirely possible that end users have legitimate requirements to be able to download PDF Documents, and this should be strongly considered before enabling this signature and using it to block traffic.

IntelliShield Alerts

IntelliShield ID Headline VersionCVSS ScoreLast Published
30495Disabling Web Browser Plug-Ins12013 August 26 11:56 GMT

Download

To download this and other IPS update files, please go to Cisco Secure Software Download.

LEGAL DISCLAIMER
THE INFORMATION ON THIS PAGE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION CONTAINED HEREIN, OR MATERIALS LINKED FROM THE DOCUMENT, IS AT YOUR OWN RISK. INFORMATION IN THIS DOCUMENT AND ANY RELATED COMMUNICATIONS IS BASED ON OUR KNOWLEDGE AT THE TIME OF PUBLICATION AND IS SUBJECT TO CHANGE WITHOUT NOTICE. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
Powered by  IntelliShield