まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Trend Micro Deep Security 11.0 Update 18 公開のお知らせ:サポート情報 : トレンドマイクロ@ 複数の脆弱性対応と累積修正っぽい

Trend Micro Deep Security 11.0 Update 18 公開のお知らせ:サポート情報 : トレンドマイクロ

Deep Security 11.0 Update 18 のモジュールを公開いたしました。
■ 公開開始日

2019 年 12 月 18 日 (水)

■ 対象モジュール

Deep Security Manager
Linux 版 Deep Security Agent
Unix 版 Deep Security Agent
Windows 版 Deep Security Agent
Windows 版 Deep Security Notifier
■ 追加機能/修正内容

追加機能や修正内容は付属の Readme をご覧ください。
※日本語のReadmeは一か月以内を目安に公開いたします。


■ 入手方法

Deep Securityヘルプセンターからダウンロードできます。

DeepSecurityヘルプセンター
また、以下の製品 Q&A も合わせてご参照ください。
Update プログラムとは

サポート情報 : トレンドマイクロ

Deep Security Manager 11.0 Update 18

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   The following enhancement(s) are included in this release:

   Enhancement 1: [SF02434919/SEG-61331/DSSEG-4903]
                  Added a progress bar to the Administrator Role page to 
                  indicate when the page is still loading.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


   2.2 Resolved Known Issues
   =====================================================================
   The following issue(s) were resolved in this release:

   Issue 1:       [DSSEG-4907]
                  The "Activity Overview" widget sometime displayed the 
                  incorrect database size.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 2:       [SF02578797/SEG-63560/DSSEG-4866]
                  When sorting the "Alert Configuration" page by the 
                  "ON" column, the number of alerts was sometimes 
                  incorrect.

   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 3:       [DSSEG-4930]
                  Memory threshold alerts were raised despite the system 
                  having memory available.

   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 4:       [SEG-57660/DSSEG-4776]
                  Packet data was not included in the exported firewall 
                  event CSV file.

   Solution 4:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 5:       [SF02531971/SEG-62740/DSSEG-4823]
                  The computers list did not search for "Software Update 
                  Status" correctly. This affected the computers list 
                  and the "out-of-date" computer reports and widgets 
                  that used it for displaying affected computers.  

   Solution 5:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   2.3 Security Updates
   =====================================================================
   [DSSEG-4880]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.
   - Updated JRE to the latest Bundled Patch Release (8.0.232/8.42.0.14).

Deep Security Agent 11.0 Update 18 for Linux

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   The following enhancements are included in this release:

   Enhancement 1: [SF02650803/SEG-65127/DSSEG-4960]
                  Excluded AWS Lustre from file system kernel hooking to 
                  prevent kernel panic.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-4813/02321128/SEG-62785]
                  Deep Security Virtual Appliance took too long to
                  release file descriptors after a VM vMotion.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 2:       [SF02689631/SEG-65408/DSSEG-4975]
                  When the Anti-Malware real-time scans configuration 
                  was re-deployed, it sometimes caused kernel-mode stack 
                  overflow if there was a third-party kernel hooking module.

   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 3:       [DSSEG-4932/SEG-55479/02588698/02200526]
                  Deep Security Agent stopped unexpectedly because of
                  invalid memory access.
   
   Solution 3:    This issue is fixed in this release
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 4:       [SF02592363/SEG-63785/DSSEG-4902]
                  The ds_agent process in Deep Security Virtual Appliance 
                  sometimes crashed during vMotion due to a race condition.

   Solution 4:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   2.3 Security Updates
   =====================================================================
   [DSSEG-4909]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.
   - Updated to curl 7.67.0.
   - Updated to openssl-1.0.2t.       

Deep Security Agent 11.0 Update 18 for Windows

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   The following issue(s) were resolved in this release:

   Issue 1:       [SEG-60169/DSSEG-4942]
                  When Application Control was enabled, there were too 
                  many software changes due to distributed file system 
                  replication.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 2:       [SF02200526/SF02588698/SEG-55479/DSSEG-4932]
                  Deep Security Agent stopped unexpectedly because of 
                  invalid memory access.

   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 3:       [SF2435069/SEG-60528/DSSEG-4658]
                  When Application Control was enabled with certain Java 
                  or Python based software, a high-volume of file events 
                  were created which caused high CPU usage.

   Solution 3:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                  
   Issue 4:       [DSSEG-4932/SEG-55479/02588698/02200526]
                  Deep Security Agent stopped unexpectedly because of
                  invalid memory access.
   
   Solution 4:    This issue is fixed in this release
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~                  

   2.3 Security Updates
   =====================================================================
   [DSSEG-4909]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.
   - Updated to curl 7.67.0.
   - Updated to openssl-1.0.2t.    

Deep Security Agent 11.0 Update 18 for Unix

2. What's New
========================================================================
   
   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-4932/SEG-55479/02588698/02200526]
                  Deep Security Agent stopped unexpectedly because of
                  invalid memory access.
   
   Solution 1:    This issue is fixed in this release
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~