Lucene search

K
mageiaGentoo FoundationMGASA-2013-0179
HistoryJun 26, 2013 - 10:00 p.m.

apache-mod_security new security issue CVE-2013-2765

2013-06-2622:00:30
Gentoo Foundation
advisories.mageia.org
9

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.018 Low

EPSS

Percentile

88.3%

Updated apache-mod_security packages fix security vulnerability: When ModSecurity receives a request body with a size bigger than the value set by the β€œSecRequestBodyInMemoryLimit” and with a β€œContent-Type” that has no request body processor mapped to it, ModSecurity will systematically crash on every call to β€œforceRequestBodyVariable” (in phase 1) (CVE-2013-2765).

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.018 Low

EPSS

Percentile

88.3%