ModSecurity Multiple Remote Denial of Service Vulnerabilities
BID:34096
Info
ModSecurity Multiple Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 34096 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-1902 CVE-2009-1903 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2009 12:00AM |
| Updated: | Apr 13 2015 09:46PM |
| Credit: | Juan Galiana Lara of Internet Security Auditors and Steve Grubb |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Breach Security ModSecurity 2.5.8 Breach Security ModSecurity 2.5.6 Breach Security ModSecurity 2.5.5 |
| Not Vulnerable: |
Breach Security ModSecurity 2.5.9 |
Discussion
ModSecurity Multiple Remote Denial of Service Vulnerabilities
ModSecurity is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to crash the Apache webserver and deny service to legitimate users.
These issues affect versions prior to ModSecurity 2.5.9.
ModSecurity is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to crash the Apache webserver and deny service to legitimate users.
These issues affect versions prior to ModSecurity 2.5.9.
Exploit / POC
ModSecurity Multiple Remote Denial of Service Vulnerabilities
An attacker may exploit this issue using readily available network tools.
The following example HTTP request is available:
An attacker may exploit this issue using readily available network tools.
The following example HTTP request is available:
Solution / Fix
ModSecurity Multiple Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Corporate Server 4.0
MandrakeSoft Enterprise Server 5
Breach Security ModSecurity 2.5.5
Breach Security ModSecurity 2.5.6
Breach Security ModSecurity 2.5.8
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva apache-mod_security-2.5.9-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.9-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva apache-mod_security-2.5.9-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.9-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_security-2.5.9-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.9-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Breach Security ModSecurity 2.5.5
-
Breach Security modsecurity-apache_2.5.9.tar.gz
http://downloads.sourceforge.net/mod-security/modsecurity-apache_2.5.9 .tar.gz?use_mirror=jaist
Breach Security ModSecurity 2.5.6
-
Breach Security modsecurity-apache_2.5.9.tar.gz
http://downloads.sourceforge.net/mod-security/modsecurity-apache_2.5.9 .tar.gz?use_mirror=jaist
Breach Security ModSecurity 2.5.8
-
Breach Security modsecurity-apache_2.5.9.tar.gz
http://downloads.sourceforge.net/mod-security/modsecurity-apache_2.5.9 .tar.gz?use_mirror=jaist
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva apache-mod_security-2.5.9-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.9-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
ModSecurity Multiple Remote Denial of Service Vulnerabilities
References:
References:
- ModSecurity Homepage (Trustwave)
- Release Name: 2.5.8 (ModSecurity)
- Release Name: 2.5.9 (ModSecurity)
- [ISecAuditors Security Advisories] ModSecurity < 2.5.9 remote Denial of Service (ISecAuditors Security Advisories
)