Project

General

Profile

Actions

Bug #6889

closed
PA PA

detect: slowdown in rule parsing

Bug #6889: detect: slowdown in rule parsing

Added by Philippe Antoine about 2 years ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Found by oss-fuzz, with quadfuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67561

Found with byte_extract. keyword but I suspect other variants

I would say severity is not critical, as this is not network)based but rule-based...
What is your assessment ?


Subtasks

OT Updated by OISF Ticketbot about 2 years ago Actions #1

  • Subtask #6890 added

OT Updated by OISF Ticketbot about 2 years ago Actions #2

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine about 2 years ago Actions #3

  • Status changed from New to In Review

I do not think this is critical for 6

VJ Updated by Victor Julien about 2 years ago Actions #5

  • Severity changed from MODERATE to HIGH

VJ Updated by Victor Julien about 2 years ago Actions #6

  • Label Needs backport to 6.0 added

OT Updated by OISF Ticketbot about 2 years ago Actions #7

  • Subtask #6898 added

OT Updated by OISF Ticketbot about 2 years ago Actions #8

  • Label deleted (Needs backport to 6.0)

VJ Updated by Victor Julien almost 2 years ago Actions #9

  • Subject changed from detect: timeout in rule parsing to detect: slowdown in rule parsing

VJ Updated by Victor Julien almost 2 years ago Actions #10

  • Tracker changed from Security to Bug
  • Severity deleted (HIGH)
  • Disclosure Date deleted (06/20/2024)

VJ Updated by Victor Julien almost 2 years ago Actions #11

  • Status changed from In Review to Closed

git hash 316cc528f784c86339d05907a4d6084cbe4d44e6

JI Updated by Jason Ish 9 months ago Actions #12

  • Private changed from Yes to No
Actions

Also available in: PDF Atom