PT-2008-6728 · Trustwave · Modsecurity
Published
2008-12-18
·
Updated
2017-08-08
·
CVE-2008-5676
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ModSecurity module versions 2.5.0 through 2.5.5
Description
The issue is related to "transformation caching" when SecCacheTransformations is enabled, allowing remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors.
Recommendations
For ModSecurity module versions 2.5.0 through 2.5.5, consider disabling the SecCacheTransformations feature as a temporary workaround to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Modsecurity