PT-2008-6728 · Trustwave · Modsecurity
Publicado
2008-12-18
·
Atualizado
2017-08-08
·
CVE-2008-5676
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ModSecurity module versions 2.5.0 through 2.5.5
Description
The issue is related to "transformation caching" when SecCacheTransformations is enabled, allowing remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors.
Recommendations
For ModSecurity module versions 2.5.0 through 2.5.5, consider disabling the SecCacheTransformations feature as a temporary workaround to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Modsecurity