Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 224993 - net-analyzer/snort-2.6.1.4 - /etc/snort/rules/web-misc.rules Line 452 => unable to parse pcre regex
Summary: net-analyzer/snort-2.6.1.4 - /etc/snort/rules/web-misc.rules Line 452 => unab...
Status: RESOLVED TEST-REQUEST
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Netmon project
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-06-05 14:55 UTC by Stefan Behte (RETIRED)
Modified: 2009-04-18 15:02 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-06-05 14:55:16 UTC
There is an error in /etc/snort/rules/web-misc.rules, line 452

Jun  5 16:49:26 s363 snort[5100]: FATAL ERROR: ERROR /etc/snort/rules/web-misc.rules Line 452 => unable to parse pcre regex "fn=Eye\d{4}_\d{2}.log/Rmsi"

After removing the line, it works.

No emerge --info needed.
Comment 1 bschnzl 2009-04-02 23:57:46 UTC
Mine loads.  No commenting out.  It seems that more data is needed.  That or close this bug.

(In reply to comment #0)
> There is an error in /etc/snort/rules/web-misc.rules, line 452
> 
> Jun  5 16:49:26 s363 snort[5100]: FATAL ERROR: ERROR
> /etc/snort/rules/web-misc.rules Line 452 => unable to parse pcre regex
> "fn=Eye\d{4}_\d{2}.log/Rmsi"
> 
> After removing the line, it works.
> 
> No emerge --info needed.

> 

Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-04-10 01:59:23 UTC
It's still there, if you use  /etc/snort/snort.conf.distrib.
Comment 3 Jason Wallace 2009-04-15 18:48:20 UTC
There is a new ebuild for snort-2.8.4 at the following bug...

bug#266288

This ebuild resolves this issue. Make sure you update your rules.
Comment 4 Patrick Lauer gentoo-dev 2009-04-18 15:02:59 UTC
Still an issue with 2.8.4-r1 ?