Actions
Bug #1238
closedPossible evasion in stream-tcp-reassemble.c
Affected Versions:
Effort:
Difficulty:
Label:
Description
Hello,
A possible evasion exist in Suricata.
The client can send a fake ACK whith a very low window size, to flag the stream as STREAMTCP_STREAM_FLAG_GAP.
This will be more clear with the PoC in attachement.
Files
Actions