Release date:
Updated on:
Affected Systems:
Modsecurity <2.7.6
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-5705
ModSecurity is a Web application server.
ModSecurity versions earlier than 2.7.6 are available in the "modsecurity_tx_init ()" function (apache2/modsecurity. c) there is an error in implementation. Malicious users can exploit this vulnerability to bypass HTTP request processing by using specially crafted requests in block encoding.
<* Source: Martin Holst Swende
Link: http://secunia.com/advisories/57444/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Modsecurity
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://sourceforge.net/projects/mod-security/
Refer:
ModSecurity:
Https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.7.6
Martin Holst Swende:
Http://martin.swende.se/blog/HTTPChunked.html