Project

General

Profile

Bug #1880

icmpv4 error packets can lead to missed detection in tcp/udp

Added by Victor Julien over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
High
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:

Description

If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.

History

#1 Updated by Victor Julien over 2 years ago

  • Status changed from Assigned to Closed

Also available in: Atom PDF