This update for modsecurity fixes the following issues:
Update to version 3.0.10:
* Security impacting issue (fix boo#1213702, CVE-2023-38285)
- Fix: worst-case time in implementation of four transformations
- Additional information on this issue is available at
s-vulnerability-in-four-transformations-cve-2023-38285/
* Enhancements and bug fixes
- Add TX synonym for MSC_PCRE_LIMITS_EXCEEDED
- Make MULTIPART_PART_HEADERS accessible to lua
- Fix: Lua scripts cannot read whole collection at once
- Fix: quoted Include config with wildcard
- Support isolated PCRE match limits
- Fix: meta actions not applied if multiMatch in first rule of chain
- Fix: audit log may omit tags when multiMatch
- Exclude CRLF from MULTIPART_PART_HEADER value
- Configure: use AS_ECHO_N instead echo -n
- Adjust position of memset from 2890
Update to version 3.0.9:
* Add some member variable inits in Transaction class...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP5:
zypper in -t patch openSUSE-2023-257=1
- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):
libmodsecurity3-3.0.10-bp155.3.3.1
modsecurity-3.0.10-bp155.3.3.1
modsecurity-devel-3.0.10-bp155.3.3.1
- openSUSE Backports SLE-15-SP5 (aarch64_ilp32):
libmodsecurity3-64bit-3.0.10-bp155.3.3.1
- openSUSE Backports SLE-15-SP5 (x86_64):
libmodsecurity3-32bit-3.0.10-bp155.3.3.1
https://www.suse.com/security/cve/CVE-2020-15598.html
https://www.suse.com/security/cve/CVE-2021-42717.html
https://www.suse.com/security/cve/CVE-2023-28882.html
https://www.suse.com/security/cve/CVE-2023-38285.html
https://bugzilla.suse.com/1210993
https://bugzilla.suse.com/1213702
Get the latest Linux and open source security news straight to your inbox.