Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-5705

Опубликовано: 15 апр. 2014
Источник: debian
EPSS Низкий

Описание

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
modsecurity-apachefixed2.7.7-1package
libapache-mod-securityremovedpackage
libapache-mod-securityfixed2.5.12-1+squeeze4squeezepackage

Примечания

  • Upstream commit: https://github.com/SpiderLabs/ModSecurity/commit/f8d441cd25172fdfe5b613442fedfc0da3cc333d

  • http://martin.swende.se/blog/HTTPChunked.html

EPSS

Процентиль: 74%
0.00842
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

redhat
почти 12 лет назад

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

nvd
почти 12 лет назад

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

github
больше 3 лет назад

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

EPSS

Процентиль: 74%
0.00842
Низкий