Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 10: 2009-2686 Moderate: Mod_Security DoS Protection

fedora
Calendar Grey March 13, 2009
Dist Fedora Esm H88
Updates in mod_security 2.5.9 for Fedora 10 resolve possible Denial of Service vulnerabilities linked to PDF XSS handling and multipart transmissions.
Security fixes for potential denials of service when using PDF XSS protection as well as when parsing multipart requests.

Summary

ModSecurity is an open source intrusion detection and prevention engine

for web applications. It operates embedded into the web server, acting

as a powerful umbrella - shielding web applications from attacks.

Security fixes for potential denials of service when using PDF XSS protection as

well as when parsing multipart requests.

;group_id=68846

* Thu Mar 12 2009 Michael Fleming 2.5.9-1

- Update to upstream release 2.5.9

- Fixes potential DoS' in multipart request and PDF XSS handling

* Mon Dec 29 2008 Michael Fleming 2.5.7-1

- Update to upstream 2.5.7

- Reinstate mlogc

su -c 'yum update mod_security' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 10
Version: 2.5.9
Release: 1.fc10
Summary: Security module for the Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here