Project

General

Profile

Actions

Bug #437

closed

filemagic / libmagic inconsistent between releases

Added by Victor Julien over 12 years ago. Updated over 1 year ago.

Status:
Rejected
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

See http://permalink.gmane.org/gmane.comp.security.ids.snort.emerging-sigs/15224

The issue is that the installed libmagic versions can return different results for the same file. This doesn't make libmagic/filemagic useless, but it does make it very hard to use for a ruleset like ET.

Possible solutions:
- ship/integrate libmagic so we always use the right version
- ship our own set of definitions for each libmagic version
- write our own file identify code (http://www.garykessler.net/library/file_sigs.html)


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #886: bromagic supportClosedActions
Related to Suricata - Feature #5894: file: file classification keywordFeedbackVictor JulienActions
Actions

Also available in: Atom PDF