Project

General

Profile

Actions

Bug #458

closed

ClamAV fires on Suricata binary if unittests are enabled

Added by Victor Julien about 12 years ago. Updated almost 12 years ago.

Status:
Closed
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

It appears that some of the unittests use metasploit payloads which are detected by ClamAV:

src/app-layer-dcerpc.o: Exploit.Fnstenv_mov-1 FOUND
src/detect-engine-dcepayload.o: Exploit.Fnstenv_mov-1 FOUND

Disabling unittests resolves the issue.

Please rewrite or remove the affected unittests.


Files

Actions

Also available in: Atom PDF