ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
BID:60182
Info
ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
| Bugtraq ID: | 60182 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-2765 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2013 12:00AM |
| Updated: | Apr 13 2015 08:48PM |
| Credit: | Younes JAAIDI |
| Vulnerable: |
SuSE openSUSE 11.4 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 |
| Not Vulnerable: | |
Discussion
ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
ModSecurity is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the Apache web server and deny service to legitimate users.
This issue affects versions prior to ModSecurity 2.7.4.
ModSecurity is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the Apache web server and deny service to legitimate users.
This issue affects versions prior to ModSecurity 2.7.4.
Exploit / POC
ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
Mandriva Business Server 1 X86 64
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5
-
Mandriva apache-mod_security-2.5.12-0.5mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.5.12-0.5mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva apache-mod_security-2.6.3-5.3.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.6.3-5.3.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva apache-mod_security-2.5.12-0.5mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva mlogc-2.5.12-0.5mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
ModSecurity CVE-2013-2765 NULL Pointer Dereference Remote Denial of Service Vulnerability
References:
References: