まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security 11.0 update 28 (DS11U28)Manager/Agentリリース@ 各種累積修正と不具合修正対応

Deep Security Manager - 11.0 update 28

Deep Security Manager - 11.0 update 28
Release date: October 26, 2021
Build number: 11.0.454

Enhancements

  • Updated Deep Security Manager to increase the number of "Maximum TCP connections " (Computers > Computers > Details > Settings > Advanced) to 1000000 by default. DSSEG-6994

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. DSSEG-6998

  • Highest CVSS Score: 9.1
  • Highest Severity: High
What's new in Deep Security Manager? | Deep Security

Deep Security Linux Agent - 11.0 update 28

Deep Security Agent - 11.0 update 28
Release date: October 26, 2021
Build number: 11.0.0-2256

Enhancements

  • Updated Deep Security Agent to prevent agents upgraded from version 10.0 to 11.0 from losing their "NIC bypass" configuration (used for Bypassing a network interface).

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7215
  • A plugin version conflict sometimes prevented Deep Security Agent from retrieving KSP (Kernel Support Package) files from the relay. DSSEG-7243
  • Deep Security Agent sometimes crashed when it could not connect to Deep Security Manager. SEG-115702/DSSEG-7053
  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DSSEG-7040
  • Deep Security Agent upgrade (Administration > Updates > Software) sometimes failed if a previous (RPM package) upgrade was triggered using console commands. SF04586071/SEG-113583/DSSEG-7030
  • Deep Security Agent sometimes lost connectivity while trying to establish an SSL connection. SEG-107451/DSSEG-7017
  • With Web Reputation enabled, Deep Security Agent caused connectivity issues for some third party applications. SF04072723/SEG-97952/DSSEG-6977

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. DSSEG-7008/DSSEG-7239/DSSEG-7259

  • Highest CVSS: 9.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 11.0 update 28

Deep Security Agent - 11.0 update 28
Release date: October 26, 2021
Build number: 11.0.0-2256

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7215
  • A plugin version conflict sometimes prevented Deep Security Agent from retrieving KSP (Kernel Support Package) files from the relay. DSSEG-7243
  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DSSEG-7040
  • Deep Security Agent sometimes lost connectivity while trying to establish an SSL connection. SEG-107451/DSSEG-7017
  • With Web Reputation enabled, Deep Security Agent caused connectivity issues for some third party applications. SF04072723/SEG-97952/DSSEG-6977

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. DSSEG-7256/DSSEG-7008/DSSEG-7239

  • Highest CVSS: 9.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 11.0 update 28

Deep Security Agent - 11.0 update 28
Release date: October 26, 2021
Build number: 11.0.0-2256

Resolved issues

  • Deep Security Agent sometimes showed package signature errors during an upgrade because of a mismatched Certification Revocation List (CRL). DSSEG-7215
  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DSSEG-7040
  • Deep Security Agent sometimes lost connectivity while trying to establish an SSL connection. SEG-107451/DSSEG-7017
  • With Web Reputation enabled, Deep Security Agent caused connectivity issues for some third party applications. SF04072723/SEG-97952/DSSEG-6977

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. DSSEG-7008/DSSEG-7239

  • Highest CVSS: 9.8
  • Highest severity: High
What's new in Deep Security Agent? | Deep Security