Actions
Bug #437
closedfilemagic / libmagic inconsistent between releases
Affected Versions:
Effort:
Difficulty:
Label:
Description
See http://permalink.gmane.org/gmane.comp.security.ids.snort.emerging-sigs/15224
The issue is that the installed libmagic versions can return different results for the same file. This doesn't make libmagic/filemagic useless, but it does make it very hard to use for a ruleset like ET.
Possible solutions:
- ship/integrate libmagic so we always use the right version
- ship our own set of definitions for each libmagic version
- write our own file identify code (http://www.garykessler.net/library/file_sigs.html)
Actions