LWN.net Logo

libapache-mod-security: cross-site scripting

Package(s):libapache-mod-security CVE #(s):CVE-2012-2751
Created:July 3, 2012 Updated:December 24, 2012
Description: From the Debian advisory:

Qualys Vulnerability & Malware Research Labs discovered a vulnerability in ModSecurity, a security module for the Apache webserver. In situations where both 'Content:Disposition: attachment' and 'Content-Type: multipart' were present in HTTP headers, the vulernability could allow an attacker to bypass policy and execute cross-site script (XSS) attacks through properly crafted HTML documents.

Alerts:
Debian DSA-2506-1 2012-07-02
Mageia MGASA-2012-0158: 2012-07-10
Mandriva MDVSA-2012:118 2012-07-27
Mandriva MDVSA-2012:182 2012-12-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds