mirror of https://github.com/OISF/suricata
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Ticket: 8289
If stream.reassembly.depth is unlimited,
an attacker controlling the 2 sides of a communication going through Suricata
can send a transition with an infinite number of headers, until suricata OOMs
Solution is to offer a configuration option to bound the number
of HTTP2 frames we store in a HTTP2 transaction, and produce an
anomaly if this bound is crossed
(cherry picked from commit
|
1 month ago | |
|---|---|---|
| .. | ||
| .cargo | 2 years ago | |
| derive | 11 months ago | |
| htp | 3 months ago | |
| src | 1 month ago | |
| suricatactl | 11 months ago | |
| suricatasc | 10 months ago | |
| sys | 1 month ago | |
| .gitignore | 2 years ago | |
| Cargo.lock.in | 1 month ago | |
| Cargo.toml.in | 1 month ago | |
| Makefile.am | 8 months ago | |
| cbindgen.toml | 10 months ago | |
| rustfmt.toml | ||