Project

General

Profile

Actions

Bug #7552

closed
AD PA

app-layer: misdetection if response is seen first without request

Bug #7552: app-layer: misdetection if response is seen first without request

Added by Alice da Silva Akaki about 1 year ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Transaction gets cleaned by AppLayerParserTransactionsCleanup before detection is run in the to_client direction when stream.midstream=true and first packet is to client dir.

Found in: https://github.com/OISF/suricata-verify/pull/2282

The next step is find a pcap to reproduce the bug


Subtasks 1 (0 open1 closed)

Bug #7553: applayer: misdetection if response is seen first without request (7.0.x backport)ClosedPhilippe AntoineActions

OT Updated by OISF Ticketbot about 1 year ago Actions #1

  • Subtask #7553 added

OT Updated by OISF Ticketbot about 1 year ago Actions #2

  • Label deleted (Needs backport to 7.0)

AD Updated by Alice da Silva Akaki about 1 year ago Actions #3

  • Affected Versions 7.0.8, git main added
  • Label Needs backport to 7.0 added

OT Updated by OISF Ticketbot about 1 year ago Actions #4

  • Label deleted (Needs backport to 7.0)

AD Updated by Alice da Silva Akaki about 1 year ago Actions #5

SB Updated by Shivani Bhardwaj about 1 year ago Actions #6

  • Subject changed from detect: flags not set to client dir if midsteam==true and 1st packet to client to applayer: misdetection if response is seen first without request

PA Updated by Philippe Antoine about 1 year ago Actions #7

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Philippe Antoine

PA Updated by Philippe Antoine about 1 year ago Actions #8

  • Status changed from In Review to Resolved

PA Updated by Philippe Antoine about 1 year ago Actions #9

  • Status changed from Resolved to Closed

VJ Updated by Victor Julien about 1 year ago Actions #10

  • Subject changed from applayer: misdetection if response is seen first without request to app-layer: misdetection if response is seen first without request
Actions

Also available in: PDF Atom