Snort 3.2.1.0 is available to download now

"Brendan Bell \(brebell\) via Snort-users" <[email protected]> Tue, 21 May 2024 17:12:05 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <PH7PR11MB86008927E082B4CE8E352B99B2EA2@PH7PR11MB8600.namprd11.prod.outlook.com>
Hello,

Snort 3.2.1.0 is available to download now.
https://snort.org/downloads

Dependencies:

  *   If you are using rules from snort.org, please use latest Talos_lightSPD package from version 2024-05-15-003 onward.

Changes in this release since 3.2.0.0:

  *   framework: supply directories to system headers to plug_gen.sh
  *   main: updates for types used by Alpine.
  *   memory: fix unit test

Changes in this release since 3.1.85.0:

  *   actions: add action counters and aggregate them under ips_actions
  *   active, host_tracker, profiler, stats, stream: refactor installed headers to exclude implementation like counts and perf stats
  *   api: refactor base API
  *   build: eliminate SO_PUBLIC THREAD_LOCALs
  *   build: fix cppcheck warnings
  *   build: fix coverity warnings
  *   build: fix LTO ODR issues with anonymous namespaces
  *   codecs: PacketManager::max_layers is not THREAD_LOCAL
  *   detection: introduce re-evaluation of ips content in next packet
  *   detection: refactor detection_util.*
  *   detection: refactor headers
  *   doc: add versioning information to the developer guide
  *   event_filter, suppress: keep antiquated dynamic array support private (use std::vector instead)
  *   extract: move extract methods to detection
  *   file: do not install internal headers
  *   flow: move StreamFlowIntf to stream_flow.h
  *   flow: split ExpectFlow into a separate header
  *   framework: bump api version to 18
  *   framework: bump api version tp 19
  *   framework: bump api version to 20
  *   framework: expand decode flags
  *   framework: generate preprocessor output for validation
  *   framework: improve exported header comments
  *   host_cache: do not install private header
  *   inspector: eval override is optional for passive inspectors
  *   inspectors: remove redundant slot variable
  *   inspector: use thread local slot for best perf on Linux
  *   ips_options: fix dynamic build of some options
  *   ips: tweak check for offload enable
  *   log: refactor out app implementation stuff into log_errors.h
  *   mpse: add modules for pegs and perf profiling; remove _search
  *   numa: do not install implementation (private) header
  *   packet_tracer: eliminate SO_PUBLIC THREAD_LOCALs
  *   pig_pen: use Module::usage directly
  *   plugins: add missing error messages when an so fails to load
  *   plugins: add warning for invalid plugin types
  *   plugins: bump base API and all plugin API version numbers
  *   profiler: eliminate SO_PUBLIC THREAD_LOCALs for _WIN64
  *   profiler: move implementation class to profiler_impl.h
  *   protocols: defensive fix for malformed packets, discard log
  *   reputation: move private defines out of installed header
  *   rna: refactor headers for better encapsulation
  *   snort: remove deprecated features:
** string binder[].when.zones: deprecated alias for groups
** string binder[].when.src_zone: deprecated alias for src_groups
** string binder[].when.dst_zone: deprecated alias for dst_groups
** enum dce_smb.smb_file_inspection: deprecated (not used): file inspection controlled by smb_file_depth { 'off' | 'on' | 'only' }
  *   ssl: support dynamic build of inspector and ips options
  *   stats: change shutdown Mbits/sec from mebibits to megabits
  *   stats: stats.h is for internal use only, do not install
  *   stream: delete obsolete / unused methods
  *   style: miscellaneous cleanup
  *   style: remove trailing spaces
  *   tag: tweak enable toggle
  *   tcp: move SEQ_* macros to tcp header
  *   thread: move THREAD_LOCAL definition to snort_types.h
  *   utils: refactor out non-public code

Changes in this release since 3.1.84.0:

  *   anaylzer, framework: add a data bus method to publish to all network policies and use it for idle
  *   appid: add http url regex patterns
  *   appid: appid CPU Profiler Table and CLI
  *   appid: disable appid cpu profiler
  *   detection: clear inspector data before flow_data
  *   detection: fix postponed rule evaluation with recall presence
  *   file_api: fix incorrect data size being passed to IPS engine for file type detection
  *   flow: connection profiling feature
  *   flow: fix unit test for debian
  *   main: update usage of a deprecated hwloc macro. Thanks to teicors for reporting the issue!
  *   stream_tcp: add reassembler class for missed_3whs
  *   stream_tcp: change drop reason issuer to stream
  *   stream_tcp: drop packet with invalid sequence number if inspection policy is inline and fix sequence number comparisons
  *   stream_tcp: implement an asymmetric flow (one-way traffic) mode for reassembly that purges flushed segments immediately (no waiting for ack that will never come)
  *   stream_tcp: support for asymmetric normalization
  *   stream_tcp: track offset into data buffer due to overlaps with state variable on the TCP segment node
  *   utils: move file specific functions from perfmonitor to utils

If you have questions or would like to connect with other Snort users, please join our Discord:
https://discord.gg/H2dY8mB4

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette