MGASA-2021-0576
Dashboard / Vulnerabilities / MGASA-2021-0576
Summary: Updated apache-mod_security packages fix security vulnerability
Details: Updated apache-mod_security packages fix security vulnerability: ModSecurity mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine (CVE-2021-42717).
References: https://advisories.mageia.org/MGASA-2021-0576.html, https://bugs.mageia.org/show_bug.cgi?id=29787
Affected packages
Package
Name: apache-mod_security
Purl: pkg:rpm/mageia/apache-mod_security?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
