Project

General

Profile

Actions

Bug #7814

open

detect/entropy: entropy values can be overwritten

Added by Jeff Lucovsky about 2 months ago. Updated 17 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Entropy values are stored as flow variables with a name formed from the anchoring sticky buffer. When multiple rules use entropy with the same sticky buffer, values will be stored in a single variable (only one value is stored).

Unique names should be used to avoid overwriting values by combining a per-rule value with the sticky buffer, such as the signature id.

Actions #1

Updated by Philippe Antoine about 1 month ago

  • Affected Versions 8.0.0 added
  • Affected Versions deleted (8.0.1)
Actions #2

Updated by Victor Julien 17 days ago

  • Status changed from New to In Review
Actions

Also available in: Atom PDF