|
|
| |
|
| |
mod_security: denial of service
| Package(s): | mod_security |
CVE #(s): | CVE-2013-2765
|
| Created: | June 6, 2013 |
Updated: | July 2, 2013 |
| Description: |
From the Red Hat Bugzilla entry:
Fixed Remote Null Pointer DeReference (CVE-2013-2765). When forceRequestBodyVariable action is triggered and a unknown Content-Type is used,
mod_security will crash trying to manipulate msr->msc_reqbody_chunks->elts however msr->msc_reqbody_chunks is NULL. (Thanks Younes JAAIDI) |
| Alerts: |
|
( Log in to post comments)
|
|
|