oss-sec mailing list archives

Re: CVE request: denial of service in suricata


From: Pierre Schweitzer <pierre () reactos org>
Date: Fri, 12 Dec 2014 15:33:24 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 12/12/2014 02:58 PM, Victor Julien wrote:

Btw, 2 other fixes directly in suri are somewhat related:

https://github.com/inliniac/suricata/commit/4eff27c108ecbcd4fc61453590f0a3d3bcf9105d


https://github.com/inliniac/suricata/commit/2c9ce634a9667ba89b22d953e3102d35badd1912

What is the policy of crashing when out of memory? On most systems
this will likely be an effective DoS even w/o crash. If you can
force your IDS to go into swap it's pretty much ineffective.

Not sure about that one...

Especially with Out-Of-Memory killer which is on most servers and that
will actually kill your daemons before they can crash due to the lack
of memory.

Or you can even disable your server swap abilities (vm.swappiness) to
always keep all your applications in memory, which will trigger OOM
killer even faster.
- -- 
Pierre Schweitzer <pierre () reactos org>
System & Network Administrator
Senior Kernel Developer
ReactOS Deutschland e.V.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUivy0AAoJEHVFVWw9WFsLjasP/06zTGgC6gAmfHCQJAWYV3cD
IK5HEwbbeTR7/J/FhYF+hdKBvEJ0LJ+dUQ5VOvGbP+l2KtKQ3twPnmzdZxGbsIUQ
5spdu1ci83QUgjvTQenYPquJW3bTI8bqytQYoMjQmtxMrYCycvduKRU9zGDItO8P
ew4JVaJSkofLSheM7WNRmkCk/vxifrxLMh2QKsqK5kwFLZgCOUvdTDxqpE5KEDN0
PDXngToNj5ua6oDX3TsOey7Cpp528RKj9YDiG9lnhySwvL8/TsB+deWMUOGdKs5Q
3O+5fQCJ9loFgbYGtwndOv8ML3oRrzNmPxCLOrWekNyyfHA8njvoCXLZhRAbSp58
qcv14HOvg4wT5ORjgMeHngrcXnl39ykHIGQTTTTbhFIfVioT4ehnoEEm+iML71H/
G3DadE2enh4tXWH4eYAJbabUEALD9ZdtDbtUUv04jhGjaRx3CKnlZCq1t14hwfLZ
sFgtWanbQQQooqGpXCQuXC1IgdDIljnc02rBtZsNqASKbz6fr0rP485cRQyNsHZm
AbZUzG8SuQxDG8zM08t2T21HUOHCqFWMwM5mFfhtup8VSW4BVo/zqEJGw9DZ67EF
/Xu1r6HoF/hkxMxVrNHNHEs1/h2prGk5b/REpNueLgVPZRKYpMQC1QnkAElmMD4X
w9PzbIdC0i52kBvRIL7+
=mYid
-----END PGP SIGNATURE-----


Current thread: