まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Trend Micro Deep Security 10.0 Update 24 公開のお知らせ:サポート情報 : トレンドマイクロ@ curlとopenSSLの脆弱性対応アップデート、その他累積修正

Trend Micro Deep Security 10.0 Update 24 公開のお知らせ:サポート情報 : トレンドマイクロ

Deep Security 10.0 Update 24 のモジュールを公開いたしました。
■ 公開開始日

2019 年 12 月 18 日 (水)

■ 対象モジュール

Deep Security Manager
Linux 版 Deep Security Agent
Unix 版 Deep Security Agent
Windows 版 Deep Security Agent
Windows 版 Deep Security Notifier
■ 追加機能/修正内容

追加機能や修正内容は付属の Readme をご覧ください。
※日本語のReadmeは一か月以内を目安に公開いたします。


■ 入手方法

Deep Securityヘルプセンターからダウンロードできます。

DeepSecurityヘルプセンター
また、以下の製品 Q&A も合わせてご参照ください。
Update プログラムとは

サポート情報 : トレンドマイクロ

Deep Security Agent 10.0 Update 24 for Linux

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   The following enhancement(s) are included in this release:
   
   Enhancement 1: [DSSEG-4886/SEG-50838]
                  Enhanced the Anti-Malware kernel level exclusion on
                  Linux. File events coming from remote file systems
                  won't be handled by Deep Security Agent anymore when
                  Network Directory Scan is disabled.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Enhancement 2: [DSSEG-4807/SEG-61584]
                  Increased the maximum size of the Log Inspection
                  database.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Enhancement 3: [SF02650803/DSSEG-4959/SEG-65127]
                  Excluded AWS Lustre from file system kernel hooking to
                  prevent kernel panic.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-4765/SEG-62073/02479683]
                  The "mq_getattr: Bad file descriptor" error occurred
                  while accessing the message queue when Deep Security
                  real-time Anti-Malware was enabled.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 2:       [DSSEG-4642/SEG-57527]
                  Anti-Malware did not quarantine some files as
                  expected.
   
   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   
   Issue 3:       [SF02689631/DSSEG-4981/SEG-65408]
                  When the Anti-Malware real-time scans configuration
                  was re-deployed, it sometimes caused kernel-mode stack
                  overflow if there was a third-party kernel hooking
                  module.
   
   Solution 3:    The issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                  
   2.3 Security Updates
   =====================================================================
   [DSSEG-4913]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.
   - Updated to curl 7.67.0.
   - Updated to openssl-1.0.2t.      

Deep Security Agent 10.0 Update 24 for Unix

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   There are no issues fixed in this release.

eep Security Agent 10.0 Update 24 for Windows, and Deep Security Notifier 10.0 Update 24 for Windows

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   The following enhancement(s) are included in this release:
   
   Enhancement 1: [DSSEG-4807/SEG-61584]
                  Increased the maximum size of the Log Inspection
                  database.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [DSSEG-4509]
                  An incorrect reboot request event sometimes occurred.
   
   Solution 1:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                  
   2.3 Security Updates
   =====================================================================
   [DSSEG-4913]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit 
   https://success.trendmicro.com/vulnerability-response.
   - Updated to curl 7.67.0.
   - Updated to openssl-1.0.2t.      

Deep Security Manager 10.0 Update 24

2. What's New
========================================================================

   2.1 Enhancements
   =====================================================================
   There are no enhancements in this release.
   

   2.2 Resolved Known Issues
   =====================================================================
   This release resolves the following issue(s):
   
   Issue 1:       [SF02386588/DSSEG-4604/SEG-59107]
                  Deep Security 10.0 (Simplified Chinese) uses a
                  Simplified Chinese version of the Smart Scan Agent
                  pattern, but it queried the English version of the
                  Smart Scan service, causing unexpected virus detection
                  results.
   
   Solution 1:    The URL for the Simplified Chinese version of the
                  Smart Scan service has been updated.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

   Issue 2:       [SF02449882/DSSEG-4888/SEG-63362]
                  The "Activity Overview" widget sometime displayed the
                  incorrect database size.
   
   Solution 2:    This issue is fixed in this release.
                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
                  
   2.3 Security Updates
   =====================================================================                  
   [DSSEG-4878]
   Security updates are included in this release. For more information 
   about how we protect against vulnerabilities, visit
   https://success.trendmicro.com/vulnerability-response
   - Updated JRE to the latest Bundled Patch Release (8.0.232/8.42.0.14)

経営者のための 情報セキュリティQ&A45

経営者のための 情報セキュリティQ&A45