LWN.net Logo

mod_security: denial of service

Package(s):mod_security CVE #(s):CVE-2013-2765
Created:June 6, 2013 Updated:July 2, 2013
Description:

From the Red Hat Bugzilla entry:

Fixed Remote Null Pointer DeReference (CVE-2013-2765). When forceRequestBodyVariable action is triggered and a unknown Content-Type is used, mod_security will crash trying to manipulate msr->msc_reqbody_chunks->elts however msr->msc_reqbody_chunks is NULL. (Thanks Younes JAAIDI)

Alerts:
Fedora FEDORA-2013-9518 2013-06-06
Fedora FEDORA-2013-9519 2013-06-06
Mageia MGASA-2013-0179 2013-06-26
Mandriva MDVSA-2013:187 2013-07-02
openSUSE openSUSE-SU-2013:1331-1 2013-08-14
openSUSE openSUSE-SU-2013:1336-1 2013-08-14
openSUSE openSUSE-SU-2013:1342-1 2013-08-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds