Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-12838

Опубликовано: 05 авг. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-12838: mod_security security update (MODERATE)

[2.9.6-2.1]

  • Resolves: RHEL-100102 - CVE-2025-48866 mod_security: ModSecurity Denial of Service Vulnerability

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

mod_security

2.9.6-2.el9_6.1

mod_security-mlogc

2.9.6-2.el9_6.1

Oracle Linux x86_64

mod_security

2.9.6-2.el9_6.1

mod_security-mlogc

2.9.6-2.el9_6.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.

CVSS3: 5.9
redhat
2 месяца назад

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.

CVSS3: 7.5
nvd
2 месяца назад

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. Version 2.9.10 fixes the issue. As a workaround, avoid using rules that contain the `sanitiseArg` (or `sanitizeArg`) action.

CVSS3: 7.5
debian
2 месяца назад

ModSecurity is an open source, cross platform web application firewall ...

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость конфигурации sanitiseArg и sanitizeArg межсетевого экрана для защиты веб-приложений ModSecurity, позволяющая нарушителю вызвать отказ в обслуживании