New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Backports 5.0.x V1 Batched backports of 6 issues, 1 undisclosed. #4718
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
When a TCP DNS flow would start with a GAP on the TS side, the successful protocol detection on the TC side would trigger 'opposing side' reassembly and app-layer processing. In this case the stream flags would indicate the wrong direction and the wrong parser would be called. (cherry picked from commit efee458)
Suricata generates an error on unrecognised ERF types. Suricata should ignore ERF 'Provenance' records with ERF_TYPE_META. (cherry picked from commit 47082dd)
This commit places restrictions on the length of the file name specified in attachments (`name=` or `filename=`) to `NAME_MAX`. Names exceeding these limits will be truncated and processing will continue with the truncated name. (cherry picked from commit d0d20bd)
(cherry picked from commit 130b8d2)
(cherry picked from commit 9a33b5d)
(cherry picked from commit c92975e)
(cherry picked from commit bcea730)
(cherry picked from commit 6d94b09)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 6c35039)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit 9fe51a8)
This commit replaces usages of pcre_get_substring with pcre_copy_substring to avoid leaking memory on error conditions. (cherry picked from commit c2071e1)
Corrects misplaced backticks preventing proper formatting of `mpm-algo` section. (cherry picked from commit 8c132c0)
For the backport, ERSPAN TypeI decode is 1. Disabled by default 2. Configurable: `decoder.erspan_typeI.enabled` (cherry picked from commit ae6beed)
Switch to isspace() as well. (cherry picked from commit 52970d8)
This was referenced Mar 22, 2020
jlucovsky
changed the title
Backports 5.x/1
Backports 5.0.x V1 Batched backports of 6 issues, 1 undisclosed.
Mar 22, 2020
This was referenced Mar 22, 2020
Not sure I agree with using 'undisclosed' for 'missing ticket' :) |
Continued in #4725 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Continuation of #4620, #4625, #4635, #4658, #4694, #4703
Backports of: