Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800626
Kategorie:Web Servers
Titel:ModSecurity Multiple Remote Denial of Service Vulnerabilities
Zusammenfassung:ModSecurity is prone to Denial of Service Vulnerabilities.
Beschreibung:Summary:
ModSecurity is prone to Denial of Service Vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An error in the PDF XSS protection implementation which can be exploited
to cause a crash via a specially crafted HTTP request.

- NULL pointer dereference error when parsing multipart requests can be
exploited to cause a crash via multipart content with a missing part header
name.

Vulnerability Impact:
Successful exploitation could allow remote attackers to cause denial of
service.

Affected Software/OS:
ModSecurity version prior to 2.5.9 on Linux.

Solution:
Upgrade to version 2.5.9 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-1902
BugTraq ID: 34096
http://www.securityfocus.com/bid/34096
Bugtraq: 20090319 [ISecAuditors Security Advisories] ModSecurity < 2.5.9 remote Denial of Service (Google Search)
http://www.securityfocus.com/archive/1/501968
https://www.exploit-db.com/exploits/8241
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00487.html
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00529.html
http://security.gentoo.org/glsa/glsa-200907-02.xml
http://www.osvdb.org/52553
http://secunia.com/advisories/34256
http://secunia.com/advisories/34311
http://secunia.com/advisories/35687
SuSE Security Announcement: SUSE-SR:2009:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
http://www.vupen.com/english/advisories/2009/0703
XForce ISS Database: modsecurity-multipart-dos(49212)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49212
Common Vulnerability Exposure (CVE) ID: CVE-2009-1903
http://www.osvdb.org/52552
XForce ISS Database: modsecurity-pdfxss-dos(49211)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49211
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.