From 94f934d474bdd508d6feb718caedc7d103339ab3 Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Tue, 28 Nov 2017 10:28:07 +0100 Subject: [PATCH] detect/depth: reject rules with depth smaller than content --- src/detect-depth.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/detect-depth.c b/src/detect-depth.c index b65821bb41..3c8af60462 100644 --- a/src/detect-depth.c +++ b/src/detect-depth.c @@ -113,6 +113,12 @@ static int DetectDepthSetup (DetectEngineCtx *de_ctx, Signature *s, const char * "invalid value for depth: %s", str); goto end; } + + if (cd->depth < cd->content_len) { + SCLogError(SC_ERR_INVALID_SIGNATURE, "depth:%u smaller than " + "content of len %u", cd->depth, cd->content_len); + return -1; + } /* Now update the real limit, as depth is relative to the offset */ cd->depth += cd->offset; } -- 2.47.2