Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2023.0175
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2023-0175)
Zusammenfassung:The remote host is missing an update for the 'apache-mod_security' package(s) announced via the MGASA-2023-0175 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'apache-mod_security' package(s) announced via the MGASA-2023-0175 advisory.

Vulnerability Insight:
HTTP multipart requests were incorrectly parsed and could bypass the Web
Application Firewall (CVE-2022-48279)
Incorrect handling of '\0' bytes in file uploads in ModSecurity may allow
for Web Application Firewall bypasses and buffer over-reads on the Web
Application Firewall when executing rules that read the FILES_TMP_CONTENT
collection. (CVE-2023-24021)

Affected Software/OS:
'apache-mod_security' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:C/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-48279
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/52TGCZCOHYBDCVWJYNN2PS4QLOHCXWTQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCH6JM4I4MD4YABYFHSBDDOUFDGIFJKL/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SYRTXTOQQI6SB2TLI5QXU76DURSLS4XI/
https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/
https://github.com/SpiderLabs/ModSecurity/pull/2795
https://github.com/SpiderLabs/ModSecurity/pull/2797
https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.6
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.8
https://lists.debian.org/debian-lts-announce/2023/01/msg00023.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-24021
https://github.com/SpiderLabs/ModSecurity/pull/2857
https://github.com/SpiderLabs/ModSecurity/pull/2857/commits/4324f0ac59f8225aa44bc5034df60dbeccd1d334
https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.7
CopyrightCopyright (C) 2023 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.