ModSecurity Quote Parsing Security Bypass Vulnerability
BID:54156
Info
ModSecurity Quote Parsing Security Bypass Vulnerability
| Bugtraq ID: | 54156 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-5031 CVE-2012-2751 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2012 12:00AM |
| Updated: | Aug 05 2014 02:09AM |
| Credit: | Qualys Vulnerability & Malware Research Labs (VMRL) |
| Vulnerable: |
SuSE openSUSE 11.4 Oracle Oracle HTTP Server 9.2 .8 Oracle Oracle HTTP Server 9.2 .0 Oracle Oracle HTTP Server 9.1 Oracle Oracle HTTP Server 9.0.3 .1 Oracle Oracle HTTP Server 9.0.2 .3 Oracle Oracle HTTP Server 9.0.2 Oracle Oracle HTTP Server 9.0.1 Oracle Oracle HTTP Server 8.1.7 Oracle Oracle HTTP Server 1.0.2 .2 Roll up 2 Oracle Oracle HTTP Server 1.0.2 .2 Oracle Oracle HTTP Server 1.0.2 .1 Oracle Oracle HTTP Server 1.0.2 .0 Oracle Oracle HTTP Server 11.1.1.5 Oracle Oracle HTTP Server 11.1.1.4 Oracle Oracle HTTP Server 11.1.1.3 Oracle Oracle HTTP Server 10.1.3.5 Oracle Oracle HTTP Server 10.1.2.3 Oracle HTTP Server for Server 9.2 Oracle HTTP Server for Server 9.0.1 Oracle HTTP Server for Server 8.1.7 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
ModSecurity Quote Parsing Security Bypass Vulnerability
ModSecurity is prone to a security-bypass vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits can allow attackers to bypass filtering rules; this may aid in further attacks.
ModSecurity versions prior to 2.6.6 are vulnerable.
ModSecurity is prone to a security-bypass vulnerability because it fails to sufficiently sanitize user-supplied input.
Successful exploits can allow attackers to bypass filtering rules; this may aid in further attacks.
ModSecurity versions prior to 2.6.6 are vulnerable.
Exploit / POC
ModSecurity Quote Parsing Security Bypass Vulnerability
An attacker can exploit this issue using standard tools.
An attacker can exploit this issue using standard tools.
Solution / Fix
ModSecurity Quote Parsing Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
ModSecurity Quote Parsing Security Bypass Vulnerability
References:
References:
- ModSecurity Homepage (Breach Security)