Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-4766-1 Moderate: Nginx Security Flaw Addressed

debian
Calendar Grey September 18, 2020
Debian Logo
A concerning vulnerability was discovered by Ervin Hegedues in ModSecurity v3, leading to potential denial of service. Users are advised to update immediately.
Ervin Hegedues discovered that ModSecurity v3 enabled global regular expression matching which could result in denial of service

Summary

Ervin Hegedues discovered that ModSecurity v3 enabled global regular
expression matching which could result in denial of service. For
additional information please refer to
https://coreruleset.org/20200914/cve-2020-15598/

For the stable distribution (buster), this problem has been fixed in
version 3.0.3-1+deb10u2.

We recommend that you upgrade your modsecurity packages.

For the detailed security status of modsecurity please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/modsecurity

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: modsecurity
CVE ID: CVE-2020-15598

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here