Project

General

Profile

Actions

Bug #3631

closed

FTP response buffering against TCP stream

Added by Philippe Antoine over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport to 4.1, Needs backport to 5.0

Description

Now, Suricata parses FTP response packets as if they are always complete.
This is not the TCP logic of streaming.
We have to keep buffering until the response is complete, and we can parse multiple responses in one TCP stream in one time.

Found by running suricata-verify tests while doing TCP stream splitting

Fix proposed https://github.com/OISF/suricata/pull/4789


Related issues 2 (0 open2 closed)

Copied to Bug #3650: FTP response buffering against TCP streamClosedVictor JulienActions
Copied to Bug #3651: FTP response buffering against TCP streamClosedJeff LucovskyActions
Actions #1

Updated by Victor Julien over 2 years ago

  • Status changed from New to In Review
  • Assignee set to Philippe Antoine
  • Target version set to 6.0.0beta1
Actions #3

Updated by Jeff Lucovsky over 2 years ago

  • Copied to Bug #3650: FTP response buffering against TCP stream added
Actions #4

Updated by Jeff Lucovsky over 2 years ago

  • Target version changed from 5.0.3 to 6.0.0beta1
  • Affected Versions 4.1.6, 5.0.1 added
  • Affected Versions deleted (5.0.2)
  • Label deleted (Needs backport)
Actions #5

Updated by Jeff Lucovsky over 2 years ago

  • Copied to Bug #3651: FTP response buffering against TCP stream added
Actions #6

Updated by Victor Julien over 2 years ago

  • Status changed from In Review to Closed

Both PRs merged, thanks Philippe.

Actions

Also available in: Atom PDF