09-18-2012 08:53 AM
Is there a signature for the new IE 0 day yet?
There is a metasploit module out so.. that means there a working exploit 'in the wild' to base a sig on...
Normally I find the CVE and then look it up in Threat Vault which will give me the threats version number (eg: 839-1155) that I can confirm is installed on my FW.
However this time, I cant find a CVE number so Im asking here.
Thanks
09-18-2012 11:47 PM
I have the same problem. But a lot crazier. We have one Cluster and one Device has the new 329 and one is still on 328. And when i perform a check the Box still say that 328 is the latest release. One Box performs the update at 1am (Version 329) and one at 2am (Version 328).
09-18-2012 11:54 PM
Could it be some issue with the update servers?
The ip was recently changed and perhaps the new (or old) server(s) didnt get the update as it should and by that customers (or support.paloaltonetworks.com for that case) doesnt see or have the latest update available?
Because at least I would expect that when the mail is sent (or arrived 🙂 the update should be available on the updateservers (and in support.paloaltonetworks.com).
09-18-2012 11:58 PM
Heard about the IP change of the update servers, but ignored it.
We've been using updates.paloaltonetworks.com in our PAs in the past as well as today.
If I had faced update problems, I would have spend some time on hardcoding update IPs.
P.S.: I don't see 329-1511 in Panorama at all, too. As mentioned before.
09-19-2012 12:04 AM
Content version 329-1511 had to be pulled due to a unexpected problems. An Emergency update containing the IE 0 day fix will be released soon.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!