Project

General

Profile

Actions

Bug #5072

closed

detect/ip_proto: inconsistent behavior when specifying protocol by string

Added by Victor Julien 8 months ago. Updated 7 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport to 5.0, Needs backport to 6.0

Description

ip_proto:TCP will use getprotobyname, which may not work depending on the OS. E.g. in a docker Alpine it fails. We should probably just use a built-in table.


Related issues 3 (0 open3 closed)

Related to Bug #4267: output: don't use /etc/protocolsClosedJeff LucovskyActions
Copied to Bug #5114: detect/ip_proto: inconsistent behavior when specifying protocol by stringClosedShivani BhardwajActions
Copied to Bug #5115: detect/ip_proto: inconsistent behavior when specifying protocol by stringClosedJeff LucovskyActions
Actions #1

Updated by Jeff Lucovsky 8 months ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jeff Lucovsky
Actions #2

Updated by Jeff Lucovsky 8 months ago

  • Related to Bug #4267: output: don't use /etc/protocols added
Actions #3

Updated by Jeff Lucovsky 8 months ago

  • Status changed from Assigned to In Review
Actions #4

Updated by Jeff Lucovsky 8 months ago

  • Copied to Bug #5114: detect/ip_proto: inconsistent behavior when specifying protocol by string added
Actions #5

Updated by Jeff Lucovsky 8 months ago

  • Copied to Bug #5115: detect/ip_proto: inconsistent behavior when specifying protocol by string added
Actions #6

Updated by Jeff Lucovsky 7 months ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF