UBUNTU-CVE-2019-11390
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11390
UBUNTU-CVE-2019-11390
Summary:
Details: ** DISPUTED ** An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf allows remote attackers to cause a denial of service (ReDOS) by entering a specially crafted string with set_error_handler# at the beginning and nested repetition operators. NOTE: the software maintainer disputes that this is a vulnerability because the issue cannot be exploited via ModSecurity.
References: https://ubuntu.com/security/CVE-2019-11390, https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1358, https://www.cve.org/CVERecord?id=CVE-2019-11390
Affected packages
Package
Name: modsecurity-crs
Purl: pkg:deb/ubuntu/modsecurity-crs
Affected ranges
Type: ECOSYSTEM
Events:
