ALT-PU-2016-1556-1
Package apache2-mod_security updated to version 2.9.1-alt1 for branch p8 in task 165162.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2009-5031
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.html
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.html
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1342
- openSUSE-SU-2013:1342
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGES
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGES
- 49576
- 49576
- [oss-security] 20120621 mod_security CVE request
- [oss-security] 20120621 mod_security CVE request
- [oss-security] 20120621 Re: mod_security CVE request
- [oss-security] 20120621 Re: mod_security CVE request
- 54156
- 54156
- http://www.suspekt.org/downloads/POC2009-ShockingNewsInPHPExploitation.pdf
- http://www.suspekt.org/downloads/POC2009-ShockingNewsInPHPExploitation.pdf
- https://www.modsecurity.org/fisheye/browse/modsecurity/m2/branches/2.5.x/apache2/msc_multipart.c?r2=1419&r1=1366
- https://www.modsecurity.org/fisheye/browse/modsecurity/m2/branches/2.5.x/apache2/msc_multipart.c?r2=1419&r1=1366
Modified: 2024-11-21
CVE-2012-2751
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.html
- http://blog.ivanristic.com/2012/06/modsecurity-and-modsecurity-core-rule-set-multipart-bypasses.html
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1342
- openSUSE-SU-2013:1342
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGES
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGES
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?r1=1918&r2=1917&pathrev=1918
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?r1=1918&r2=1917&pathrev=1918
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/CHANGES?r1=1920&r2=1919&pathrev=1920
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/CHANGES?r1=1920&r2=1919&pathrev=1920
- 49576
- 49576
- 49782
- 49782
- DSA-2506
- DSA-2506
- MDVSA-2012:118
- MDVSA-2012:118
- MDVSA-2013:150
- MDVSA-2013:150
- [oss-security] 20120621 mod_security CVE request
- [oss-security] 20120621 mod_security CVE request
- [oss-security] 20120621 Re: mod_security CVE request
- [oss-security] 20120621 Re: mod_security CVE request
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
- 54156
- 54156
Modified: 2024-11-21
CVE-2012-4528
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
- FEDORA-2012-18278
- FEDORA-2012-18278
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1342
- openSUSE-SU-2013:1342
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?sortby=date&r1=2081&r2=2080&pathrev=2081
- http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/trunk/apache2/msc_multipart.c?sortby=date&r1=2081&r2=2080&pathrev=2081
- http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=revision&sortby=date&revision=2081
- http://mod-security.svn.sourceforge.net/viewvc/mod-security?view=revision&sortby=date&revision=2081
- 20121017 SEC Consult SA-20121017-0 :: ModSecurity multipart/invalid part ruleset bypass
- 20121017 SEC Consult SA-20121017-0 :: ModSecurity multipart/invalid part ruleset bypass
- [oss-security] 20121018 Re: CVE request: Fwd: [Full-disclosure] SEC Consult SA-20121017-0 :: ModSecurity multipart/invalid part ruleset bypass
- [oss-security] 20121018 Re: CVE request: Fwd: [Full-disclosure] SEC Consult SA-20121017-0 :: ModSecurity multipart/invalid part ruleset bypass
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20121017-0_mod_security_ruleset_bypass.txt
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20121017-0_mod_security_ruleset_bypass.txt
Modified: 2024-11-21
CVE-2013-1915
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.
- FEDORA-2013-4834
- FEDORA-2013-4834
- FEDORA-2013-4831
- FEDORA-2013-4831
- FEDORA-2013-4908
- FEDORA-2013-4908
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1331
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1336
- openSUSE-SU-2013:1342
- openSUSE-SU-2013:1342
- 52847
- 52847
- 52977
- 52977
- DSA-2659
- DSA-2659
- MDVSA-2013:156
- MDVSA-2013:156
- [oss-security] 20130403 Re: CVE Request -- ModSecurity (X < 2.7.3): Vulnerable to XXE attacks
- [oss-security] 20130403 Re: CVE Request -- ModSecurity (X < 2.7.3): Vulnerable to XXE attacks
- 58810
- 58810
- https://bugzilla.redhat.com/show_bug.cgi?id=947842
- https://bugzilla.redhat.com/show_bug.cgi?id=947842
- https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES
- https://github.com/SpiderLabs/ModSecurity/blob/master/CHANGES
- https://github.com/SpiderLabs/ModSecurity/commit/d4d80b38aa85eccb26e3c61b04d16e8ca5de76fe
- https://github.com/SpiderLabs/ModSecurity/commit/d4d80b38aa85eccb26e3c61b04d16e8ca5de76fe
Modified: 2024-11-21
CVE-2013-5705
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.