MGASA-2014-0180
Dashboard / Vulnerabilities / MGASA-2014-0180
Summary: Updated apache-mod_security packages fix security vulnerability
Details: Updated apache-mod_security packages fix security vulnerability: Martin Holst Swende discovered a flaw in the way mod_security handled chunked requests. A remote attacker could use this flaw to bypass intended mod_security restrictions, allowing them to send requests containing content that should have been removed by mod_security (CVE-2013-5705).
References: https://advisories.mageia.org/MGASA-2014-0180.html, https://lists.fedoraproject.org/pipermail/package-announce/2014-April/131375.html, https://bugs.mageia.org/show_bug.cgi?id=13215
Affected packages
Package
Name: apache-mod_security
Purl: pkg:rpm/mageia/apache-mod_security?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
