Project

General

Profile

Actions

Bug #7887

open

detect/tls: zero characters in keywords such as alt name are mishandled

Added by Philippe Antoine 3 months ago. Updated 2 days ago.

Status:
In Review
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
medium
Label:

Description

See #7881 and SV test to come associated with it

Rust Cstring new fails and returns NULL ptr

solution would be to store the connp->cert0_sans_len length of each connp->cert0_sans


Subtasks 2 (0 open2 closed)

Bug #7996: tls: certificate SAN is freed in case of any errorClosedShivani BhardwajActions
Bug #8020: tls: certificate SAN is freed in case of any error (8.0.x backport)ClosedShivani BhardwajActions

Related issues 1 (0 open1 closed)

Copied from Suricata - Security #7881: detect/tls: keyword tls.subjectaltname leads to NULL Deref if tls.subjectaltname contains zeroClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine 3 months ago

  • Copied from Security #7881: detect/tls: keyword tls.subjectaltname leads to NULL Deref if tls.subjectaltname contains zero added
Actions #2

Updated by Philippe Antoine 3 months ago

  • Affected Versions 8.0.0 added
Actions #3

Updated by Shivani Bhardwaj 3 months ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Shivani Bhardwaj
Actions #4

Updated by Shivani Bhardwaj 3 months ago

  • Priority changed from Normal to High
  • Label Needs backport to 8.0 added
Actions #5

Updated by OISF Ticketbot 3 months ago

  • Subtask #7982 added
Actions #6

Updated by OISF Ticketbot 3 months ago

  • Label deleted (Needs backport to 8.0)
Actions #7

Updated by Shivani Bhardwaj 2 months ago

  • Subtask #7996 added
Actions #8

Updated by Shivani Bhardwaj about 2 months ago

  • Status changed from Assigned to In Progress
Actions #9

Updated by Shivani Bhardwaj about 2 months ago

  • Subject changed from detect/tls: handle zero characters in keywords such as alt name to detect/tls: zero characters in keywords such as alt name are mishandled
Actions #10

Updated by Philippe Antoine about 2 months ago

By the way, I am not sure they are logged properly (not only detection problem)

Actions #11

Updated by Shivani Bhardwaj about 2 months ago

Philippe Antoine wrote in #note-10:

By the way, I am not sure they are logged properly (not only detection problem)

Indeed the output is truncated at the nul byte

Actions #12

Updated by Shivani Bhardwaj 4 days ago

  • Private changed from Yes to No
Actions #13

Updated by Shivani Bhardwaj 4 days ago

  • Status changed from In Progress to In Review
Actions #14

Updated by Shivani Bhardwaj 2 days ago

  • Difficulty set to medium
Actions

Also available in: Atom PDF