]> git.ipfire.org Git - thirdparty/suricata.git/commit
tls: improve record checks
authorVictor Julien <vjulien@oisf.net>
Wed, 7 Sep 2022 06:32:05 +0000 (08:32 +0200)
committerVictor Julien <vjulien@oisf.net>
Fri, 13 Jan 2023 11:33:03 +0000 (12:33 +0100)
commit29740e1c0c5414c9b893844aa3b5358135fea9f6
tree0ddccb92fa4ce3104deca7788c70493822ee04f6
parentdfc332fe49d44047ab1055c4e37ec15d7be9fd57
tls: improve record checks

Improve unknown record handling. Inspired by Wireshark 'unknown record'
handling, we take a best effort approach for records with unknown content
types in TLS versions 1.0, 1.1 and 1.2.

Improve record length check and set 'invalid_record_length' event instead
of 'invalid_tls_header'.

(cherry picked from commit 69be41b241bc7fd1a5b7f3988b51f5859ab27d57)
src/app-layer-ssl.c