[Snort-devel] Core dump in build 139

Kreimendahl, Chad J Chad.Kreimendahl at ...1167...
Mon May 13 10:47:03 EDT 2002

./snort -o -c tmp.conf -i qfe0  
 (tmp.conf contains)

preprocessor frag2
preprocessor stream4: detect_scans, memcap 33554432, timeout 30
preprocessor stream4_reassemble: both, ports 21 23 25 53 80 110 111 143 513
preprocessor http_decode: 80 unicode iis_alt_unicode double_encode
iis_flip_slash full_whitespace
output database: alert, oracle,.....
config classif........

And 1 alert.

Not sure when IPv6 stuff was added... Will check docs to see if it's easy to
disable... Here's some info:
Breaks very quickly... (after first stream4 alert)

@(#) $Header: /tcpdump/master/libpcap/scanner.l,v 1.70 2000/10/28 10:18:40
guy Exp $ (LBL)
fatal flex scanner internal error--no action found
IPv6 address %s not supported
bogus ethernet address %s
illegal token: %s
illegal char '%c'
fatal flex scanner internal error--end of buffer missed
input in flex scanner failed
fatal error - scanner input buffer overflow
out of dynamic memory in yy_create_buffer()
out of dynamic memory in yy_scan_buffer()
out of dynamic memory in yy_scan_bytes()
bad buffer in yy_scan_bytes()
@(#) $Header: /tcpdump/master/libpcap/grammar.y,v 1.64 2000/10/28 10:18:40
guy Exp $ (LBL)
parse error
parser stack overflow
'ip6addr/prefixlen' not supported in this configuration
'ip6addr' not supported in this configuration
        $Revision: 1.3 $
        $Date: 2002/04/01 15:35:57 $
        $Author: andrewbaker $
        $Revision: 1.2 $
        $Date: 2002/04/01 15:35:57 $
        $Author: andrewbaker $
         (((((                  H

More information about the Snort-devel mailing list