Actions
Bug #6846
closed
PA
PA
eve/alerts: wrongly using tx id 0 when there is no tx
Bug #6846:
eve/alerts: wrongly using tx id 0 when there is no tx
Affected Versions:
Effort:
Difficulty:
Label:
Description
Found by oss-fuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=64345&q=label%3AProj-suricata&can=2
cf #6770
This leads to quadratic complexity arbitrary length value being logged an arbitrary number of times because we lof tx id 0 data when there is no data
PA Updated by Philippe Antoine about 2 years ago
- Related to Security #6770: log: arbitrary-length value can be logged added
OT Updated by OISF Ticketbot about 2 years ago
- Subtask #6847 added
OT Updated by OISF Ticketbot about 2 years ago
- Label deleted (
Needs backport to 6.0)
OT Updated by OISF Ticketbot about 2 years ago
- Subtask #6848 added
OT Updated by OISF Ticketbot about 2 years ago
- Label deleted (
Needs backport to 7.0)
PA Updated by Philippe Antoine about 2 years ago
- Status changed from New to In Review
Gitlab MR
VJ Updated by Victor Julien about 2 years ago
- Tracker changed from Security to Bug
- Severity deleted (
HIGH) - Disclosure Date deleted (
02/19/2024)
PA Updated by Philippe Antoine about 2 years ago
- Related to Security #6900: http2: timeout logging headers added
PA Updated by Philippe Antoine about 2 years ago
PA Updated by Philippe Antoine about 2 years ago
- Status changed from In Review to Resolved
PA Updated by Philippe Antoine about 2 years ago
PA Updated by Philippe Antoine about 2 years ago
Still https://github.com/OISF/suricata/pull/10924 to complete first merge
JF Updated by Juliana Fajardini Reichow about 2 years ago
- Related to Bug #6973: detect: log relevant frames app-layer metdata added
PA Updated by Philippe Antoine almost 2 years ago
- Status changed from Resolved to Closed
VJ Updated by Victor Julien almost 2 years ago
- Private changed from Yes to No
JI Updated by Jason Ish over 1 year ago
- Related to Task #7350: firewall usecase: log app-layer metadata for for catch-all drop rules added
VJ Updated by Victor Julien about 1 year ago
- Subject changed from alerts: wrongly using tx id 0 when there is no tx to eve/alerts: wrongly using tx id 0 when there is no tx
Actions