MGASA-2013-0179
Dashboard / Vulnerabilities / MGASA-2013-0179
Summary: apache-mod_security new security issue CVE-2013-2765
Details: Updated apache-mod_security packages fix security vulnerability: When ModSecurity receives a request body with a size bigger than the value set by the "SecRequestBodyInMemoryLimit" and with a "Content-Type" that has no request body processor mapped to it, ModSecurity will systematically crash on every call to "forceRequestBodyVariable" (in phase 1) (CVE-2013-2765).
References: https://advisories.mageia.org/MGASA-2013-0179.html, http://www.shookalabs.com/#advisory-cve-2013-2765, https://lists.fedoraproject.org/pipermail/package-announce/2013-June/107848.html
Affected packages
Package
Name: apache-mod_security
Purl: pkg:rpm/mageia/apache-mod_security?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
