Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Gentoo: GLSA-200705-17 Low: mod_security Remote Rule Bypass

gentoo
Calendar Grey May 17, 2007
Scroller Gentoo
A distant adversary may circumvent mod_security protocols in Apache. Update promptly to resolve the issue. Discover additional details here.
A vulnerability has been discovered in mod_security, allowing a remote attacker to bypass rules.

Summary

Gentoo Linux Security Advisory GLSA 200705-17 https://security.gentoo.org/ Severity: Low Title: Apache mod_security: Rule bypass Date: May 17, 2007 Bugs: #169778 ID: 200705-17

Synopsis ======= A vulnerability has been discovered in mod_security, allowing a remote attacker to bypass rules.
Background ========= mod_security is an Apache module designed for enhancing the security of the Apache web server.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-www/mod_security < 2.1.1 >= 2.1.1
========== Stefan Esser discovered that mod_security processes NULL characters as terminators in POST requests using the application/x-www-form-urlencoded encoding type, whi...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
low
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround