Release date:
Updated on:
Affected Systems:
Sourceforge mod-security 2.x
Description:
--------------------------------------------------------------------------------
ModSecurity for Apache is a plug-in for the Apache Web server platform.
A security vulnerability exists in versions earlier than ModSecurity 2.70. when parsing multiple requests, malicious users can bypass certain filter rules.
<* Source: Bernhard Mueller (research@sec-consult.com)
Link: http://secunia.com/advisories/49853/
Http://archives.neohapsis.com/archives/fulldisclosure/2012-10/0114.html
Http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sourceforge
-----------
Sourceforge has released a Security Bulletin and corresponding patches for this purpose:
Http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES
Link: http://mod-security.svn.sourceforge.net/