Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0431-1

Опубликовано: 15 фев. 2023
Источник: suse-cvrf

Описание

Security update for apache2-mod_security2

This update for apache2-mod_security2 fixes the following issues:

  • CVE-2023-24021: Fixed FILES_TMP_CONTENT missing complete content (bsc#1207379).

Список пакетов

SUSE Linux Enterprise Module for Server Applications 15 SP4
apache2-mod_security2-2.9.4-150400.3.6.1
openSUSE Leap 15.4
apache2-mod_security2-2.9.4-150400.3.6.1

Описание

Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP4:apache2-mod_security2-2.9.4-150400.3.6.1
openSUSE Leap 15.4:apache2-mod_security2-2.9.4-150400.3.6.1

Ссылки