oss-sec mailing list archives

CVE Request -- ModSecurity - v2.5.12


From: Jan Lieskovsky <jlieskov () redhat com>
Date: Wed, 10 Feb 2010 11:37:38 +0100

Hi Steve, vendors,

  multiple security flaws, which might lead to bypass of intended
security restrictions and denial of service, have been reported
and corrected in latest v2.5.12 version of ModSecurity.

References:
[1] http://sourceforge.net/projects/mod-security/files/modsecurity-apache/2.5.12/CHANGES_2.5.12.txt/download
[2] https://bugzilla.redhat.com/show_bug.cgi?id=563455
[3] http://secunia.com/advisories/38460/
[4] http://freshmeat.net/projects/modsecurity/releases/312017
[5] http://www.modsecurity.org/

Could you allocate CVE ids for these?

Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


Current thread: