[Snort-devel] Snort crash when reload rules with tag session

Carter Waxman (cwaxman) cwaxman at ...3461...
Thu May 29 13:44:00 EDT 2014


Could you please attach a backtrace from gdb?


From: נתנאל ממן <netanelmaman0 at ...2499...<mailto:netanelmaman0 at ...2499...>>
Date: Thursday, May 29, 2014 12:29 PM
To: "snort-devel at lists.sourceforge.net<mailto:snort-devel at lists.sourceforge.net>" <snort-devel at lists.sourceforge.net<mailto:snort-devel at lists.sourceforge.net>>
Subject: [Snort-devel] Snort crash when reload rules with tag session

Hello guys, please help me solve a stranger bug.

I have rules with tag session option.
When I'm reload conf via control socket the conf reload succesfully but crash one second after.
When i reload the same rule without tag option, snort reload successfully.
I think that snort free some important struct of tags, but i dont find which and where.

The version of Snort you're running:

Information on the rules you have enabled:
General local rule with "tag:session,100,seconds;"

How Snort was built:
configure --enable-control-socket

Did you build from source:

Platform information:
Centos 6.3 x86_64, kernel 2.6.32, intel 86

Any output that may be helpful:
gdb show that crash occur when call to log function after check tagging func in decode.c . Im faild to understand why.

Thanks about your amazing work,

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20140529/85f7a060/attachment.html>

More information about the Snort-devel mailing list