Project

General

Profile

Actions

Bug #7552

closed

applayer: misdetection if response is seen first without request

Added by Alice da Silva Akaki about 1 month ago. Updated 14 days ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Transaction gets cleaned by AppLayerParserTransactionsCleanup before detection is run in the to_client direction when stream.midstream=true and first packet is to client dir.

Found in: https://github.com/OISF/suricata-verify/pull/2282

The next step is find a pcap to reproduce the bug


Subtasks 1 (0 open1 closed)

Bug #7553: applayer: misdetection if response is seen first without request (7.0.x backport)ClosedPhilippe AntoineActions
Actions #1

Updated by OISF Ticketbot about 1 month ago

  • Subtask #7553 added
Actions #2

Updated by OISF Ticketbot about 1 month ago

  • Label deleted (Needs backport to 7.0)
Actions #3

Updated by Alice da Silva Akaki about 1 month ago

  • Affected Versions 7.0.8, git master added
  • Label Needs backport to 7.0 added
Actions #4

Updated by OISF Ticketbot about 1 month ago

  • Label deleted (Needs backport to 7.0)
Actions #6

Updated by Shivani Bhardwaj about 1 month ago

  • Subject changed from detect: flags not set to client dir if midsteam==true and 1st packet to client to applayer: misdetection if response is seen first without request
Actions #7

Updated by Philippe Antoine 29 days ago

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Philippe Antoine
Actions #8

Updated by Philippe Antoine 19 days ago

  • Status changed from In Review to Resolved
Actions #9

Updated by Philippe Antoine 14 days ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF