ModSecurity Security Bypass And Denial Of Service Vulnerabilities
BID:38156
Info
ModSecurity Security Bypass And Denial Of Service Vulnerabilities
| Bugtraq ID: | 38156 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2010 12:00AM |
| Updated: | Feb 26 2010 01:51PM |
| Credit: | Sogeti/ESEC R&D team |
| Vulnerable: |
Red Hat Fedora 12 Red Hat Fedora 11 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Breach Security ModSecurity 2.5.11 Breach Security ModSecurity 2.5.10 Breach Security ModSecurity 2.5.9 Breach Security ModSecurity 2.5.8 Breach Security ModSecurity 2.5.6 Breach Security ModSecurity 2.5.5 |
| Not Vulnerable: |
Breach Security ModSecurity 2.5.12 |
Discussion
ModSecurity Security Bypass And Denial Of Service Vulnerabilities
ModSecurity is prone to a security-bypass vulnerability and a denial-of-service vulnerability.
An attacker can exploit these issues to bypass certain security detection mechanisms and cause denial-of-service conditions.
These issues affect versions prior to ModSecurity 2.5.12.
ModSecurity is prone to a security-bypass vulnerability and a denial-of-service vulnerability.
An attacker can exploit these issues to bypass certain security detection mechanisms and cause denial-of-service conditions.
These issues affect versions prior to ModSecurity 2.5.12.
Exploit / POC
ModSecurity Security Bypass And Denial Of Service Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ModSecurity Security Bypass And Denial Of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_security-2.5.12-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.12-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva apache-mod_security-2.5.12-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.12-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva apache-mod_security-2.5.12-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.12-0.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva apache-mod_security-2.5.12-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva mlogc-2.5.12-0.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
ModSecurity Security Bypass And Denial Of Service Vulnerabilities
References:
References:
- ModSecurity Homepage (Breach Security)
- ModSecurity v2.5.12 Change Log (Breach Security)