Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-46292

Опубликовано: 09 окт. 2024
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

A flaw was found in ModSecurity. In certain configurations, an attacker may be able to use a specially-crafted request to trigger a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7mod_securityNot affected
Red Hat Enterprise Linux 8mod_securityNot affected
Red Hat Enterprise Linux 9mod_securityNot affected
Red Hat JBoss Core Servicesmod_securityNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2317621mod_security: denial of service via name paramter

EPSS

Процентиль: 55%
0.00818
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVSS3: 7.5
nvd
почти 2 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVSS3: 7.5
debian
почти 2 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a D ...

CVSS3: 7.5
github
почти 2 года назад

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter.

EPSS

Процентиль: 55%
0.00818
Низкий

3.7 Low

CVSS3