Project

General

Profile

Actions

Bug #8715

open
JI JI

smtp: subsequent helo/ehlo should be treated like a rset

Bug #8715: smtp: subsequent helo/ehlo should be treated like a rset

Added by Jason Ish 24 days ago. Updated 2 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

RFC 5321 states that a mid-session EHLO must be treated just like an RSET:

An EHLO command MAY be issued by a client later in the session. If
it is issued after the session begins and the EHLO command is
acceptable to the SMTP server, the SMTP server MUST clear all buffers
and reset the state exactly as if a RSET command had been issued. In
other words, the sequence of RSET followed immediately by EHLO is
redundant, but not harmful other than in the performance cost of
executing unnecessary commands.

Currently Suricata more or less just ignores it.


Subtasks


Related issues 1 (1 open0 closed)

Related to Suricata - Feature #8393: firewall: support SMTP hook states for firewall rule evaluationResolvedJason IshActions

OT Updated by OISF Ticketbot 24 days ago Actions #1

  • Subtask #8716 added

OT Updated by OISF Ticketbot 24 days ago Actions #2

  • Label deleted (Needs backport to 8.0)

JI Updated by Jason Ish 23 days ago Actions #3

  • Private changed from Yes to No

JI Updated by Jason Ish 23 days ago Actions #4

  • Related to Feature #8393: firewall: support SMTP hook states for firewall rule evaluation added

JI Updated by Jason Ish 23 days ago Actions #5

  • Description updated (diff)

JI Updated by Jason Ish 23 days ago Actions #6

  • Status changed from In Progress to In Review

JI Updated by Jason Ish 19 days ago Actions #7

  • Status changed from In Review to Assigned

JI Updated by Jason Ish 2 days ago Actions #8

  • Status changed from Assigned to In Review
Actions

Also available in: PDF Atom