まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Trend Micro Deep Security 10.0 Update 20 公開のお知らせ:サポート情報 : トレンドマイクロ@ Tbimdsaの不具合修正対応かな。Deep Security Manager 10.0 Update 20のセキュリティアップデートが含まれてるらしい

Trend Micro Deep Security 10.0 Update 20 公開のお知らせ:サポート情報 : トレンドマイクロ

Deep Security 10.0 Update 20 のモジュールを公開いたしました。
■公開開始日
2019 年 7 月 5 日 (金)

■対象モジュール
Deep Security Manager
Linux 版 Deep Security Agent
Unix 版 Deep Security Agent
Windows 版 Deep Security Agent
Windows 版 Deep Security Notifier
■追加機能/修正内容
追加機能や修正内容は付属の Readme をご覧ください。
※日本語のReadmeは一か月以内を目安に公開いたします。

サポート情報 : トレンドマイクロ

Deep Security Manager

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements included in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-3745/SEG-48936/SF01775616]
                  The Event API did not handle NULL severity values
                  gracefully.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 2:       [DSSEG-3694]
                  On the primary tenant, unsigned and self-signed
                  software packages can no longer be imported to Deep
                  Security Manager.
   
   Solution 2:    This issue is fixed in this release
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 3:       [DSSEG-3692]
                  Deep Security Rule Updates must now be signed before
                  being imported or applied
   
   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
   2.3 Security Updates
   =====================================================================
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.

Linux 版 Deep Security Agent

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-4026/SEG-52195/SF01954511]
                  The heartbeat thread crashed due to a SQLite exception
                  when getting Log Inspection events.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 2:       [DSSEG-3946/SEG-50709/SF01990859]
                  In some cases, the Tbimdsa driver did not correctly
                  release spinlock, causing the system to hang.
   
   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 3:       [DSSEG-3926/02023336/SEG-51309]
                  The files under system paths (e.g., "/sys" or
                  "/dev") were caught by Anti-Malware real-time scans
                  for file scanning. However, by design, those files
                  should not be scanned because they are basically
                  system files, and most of them are unchangeable and
                  unreadable.
   
   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 4:       [DSSEG-3898/01903269/SEG-48538]
                  The logs under /var/opt/ds_agent/diag/dsva/ on Deep
                  Security Virtual Appliance were not rotated.
   
   Solution 4:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 5:       [DSSEG-3886]
                  A security update was triggered every time a
                  policy was sent to Deep Security Virtual Appliance.
   
   Solution 5:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 6:       [DSSEG-3738/SF01775560/SEG-49866]
                  The agent operating system would sometimes crash when
                  Firewall interface ignores were set.
   
   Solution 6:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 7:       [DSSEG-3520/SEG-42919/SF01415702]
                  When multiple Smart Protection Servers were
                  configured, the Deep Security Agent process would
                  sometimes crash due to an invalid sps_index.
   
   Solution 7:    The issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Unix 版 Deep Security Agent

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-3946/SEG-50709/SF01990859]
                  In some cases, the Tbimdsa driver did not correctly
                  release spinlock, causing the system to hang.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 2:       [DSSEG-3898/01903269/SEG-48538]
                  The logs under /var/opt/ds_agent/diag/dsva/ on Deep
                  Security Virtual Appliance were not rotated.
   
   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 3:       [DSSEG-3892/SEG-50228/01967095]
                  Deep Security Agent failed to cleanly terminate some
                  threads when it exits.
   
   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 4:       [DSSEG-3886]
                  A security update was triggered every time a
                  policy was sent to Deep Security Virtual Appliance.
   
   Solution 4:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 5:       [DSSEG-3520/SEG-42919/SF01415702]
                  When multiple Smart Protection Servers were
                  configured, the Deep Security Agent process would
                  sometimes crash due to an invalid sps_index.
   
   Solution 5:    The issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Windows 版 Deep Security Agent
Windows 版 Deep Security Notifier

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-3946/SEG-50709/SF01990859]
                  In some cases, the Tbimdsa driver did not correctly
                  release spinlock, causing the system to hang.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 2:       [DSSEG-3898/01903269/SEG-48538]
                  The logs under /var/opt/ds_agent/diag/dsva/ on Deep
                  Security Virtual Appliance were not rotated.
   
   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 3:       [DSSEG-3886]
                  A security update was triggered every time a
                  policy was sent to Deep Security Virtual Appliance.
   
   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 4:       [DSSEG-3520/SEG-42919/SF01415702]
                  When multiple Smart Protection Servers were
                  configured, the Deep Security Agent process would
                  sometimes crash due to an invalid sps_index.
   
   Solution 4:    The issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~