Update to 3.0.14 and fix CVE-2025-27110. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-06e326a6f5 2025-06-04 03:33:52.001796+00:00 -------------------------------------------------------------------------------- Name : libmodsecurity Product : Fedora 41 Version : 3.0.14 Release : 1.fc41 URL : https://github.com/owasp-modsecurity/ModSecurity Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. -------------------------------------------------------------------------------- Update Information: Update to 3.0.14 and fix CVE-2025-27110 -------------------------------------------------------------------------------- ChangeLog: * Mon May 26 2025 Mikel Olasagasti Uranga - 3.0.14-1 - Update to 3.0.14 - Closes rhbz#2347612 rhbz#2340755 CVE-2025-27110 * Fri Jan 17 2025 Fedora Release Engineering - 3.0.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Fri Oct 25 2024 Mikel Olasagasti Uranga - 3.0.13-1 - Update to 3.0.13 - Closes rhbz#2309459 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-06e326a6f5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 3.0.14 and fix CVE-2025-27110. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-108d6a9f25 2025-06-04 02:09:45.733076+00:00 -------------------------------------------------------------------------------- Name : libmodsecurity Product : Fedora 42 Version : 3.0.14 Release : 1.fc42 URL : https://github.com/owasp-modsecurity/ModSecurity Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. -------------------------------------------------------------------------------- Update Information: Update to 3.0.14 and fix CVE-2025-27110 -------------------------------------------------------------------------------- ChangeLog: * Mon May 26 2025 Mikel Olasagasti Uranga - 3.0.14-1 - Update to 3.0.14 - Closes rhbz#2347612 rhbz#2340755 CVE-2025-27110 * Fri Jan 17 2025 Fedora Release Engineering - 3.0.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-108d6a9f25' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # libmodsecurity3-3.0.14-1.1 on GA media Announcement ID: openSUSE-SU-2025:14946-1 Rating: moderate Cross-References: * CVE-2025-27110 CVSS scores: * CVE-2025-27110 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2025-27110 ( SUSE ): 7.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the libmodsecurity3-3.0.14-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libmodsecurity3 3.0.14-1.1 * modsecurity 3.0.14-1.1 * modsecurity-devel 3.0.14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27110.html . Tackling a minor vulnerability in libmodsecurity3-3.0.14-1.1 for openSUSE to bolster system security.. libmodsecurity3, openSUSE Tumbleweed, security update. . LinuxSecurity.com Team
Update to 3.0.12 Security fix for CVE-2024-1019. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-698e541c52 2024-02-20 01:36:45.526505 -------------------------------------------------------------------------------- Name : libmodsecurity Product : Fedora 38 Version : 3.0.12 Release : 1.fc38 URL : https://github.com/owasp-modsecurity/ModSecurity Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. -------------------------------------------------------------------------------- Update Information: Update to 3.0.12 Security fix for CVE-2024-1019 -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 11 2024 Mikel Olasagasti Uranga - 3.0.12-1 - Update to 3.0.12 rhbz#2253518 - Fix CVE-2024-1019 rhbz#2262017 rhbz#2262018 rhbz#2262019 * Thu Jan 25 2024 Fedora Release Engineering - 3.0.10-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 3.0.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2262018 - CVE-2024-1019 libmodsecurity: WAF bypass for path-based payloads [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2262018 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2024-698e541c52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to maintenance release 3.0.8. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-90453044f3 2022-11-10 22:04:44.630774 --------------------------------------------------------------------------------Name : libmodsecurity Product : Fedora 37 Version : 3.0.8 Release : 1.fc37 URL : https://modsecurity.org/ Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. --------------------------------------------------------------------------------Update Information: Update to maintenance release 3.0.8 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Othman Madjoudj - 3.0.8-1 - Update to maintenance release 3.0.8 * Thu Jul 21 2022 Fedora Release Engineering - 3.0.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2021301 - CVE-2021-35368 libmodsecurity: request body bypass via a trailing pathname [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2021301 [ 2 ] Bug #2113484 - libmodsecurity: FTBFS in Fedora rawhide/f37 https://bugzilla.redhat.com/show_bug.cgi?id=2113484 [ 3 ] Bug #2129200 - is libmodsecurity pkg still being maintained? https://bugzilla.redhat.com/show_bug.cgi?id=2129200 [ 4 ] Bug #2129515 - Non-responsive maintainer check for athmane https://bugzilla.redhat.com/show_bug.cgi?id=2129515 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-90453044f3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to maintenance release 3.0.8. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-afa1e7b6c4 2022-10-24 14:08:49.147106 --------------------------------------------------------------------------------Name : libmodsecurity Product : Fedora 36 Version : 3.0.8 Release : 1.fc36 URL : https://modsecurity.org/ Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. --------------------------------------------------------------------------------Update Information: Update to maintenance release 3.0.8 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 15 2022 Othman Madjoudj - 3.0.8-1 - Update to maintenance release 3.0.8 * Thu Jul 21 2022 Fedora Release Engineering - 3.0.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2021301 - CVE-2021-35368 libmodsecurity: request body bypass via a trailing pathname [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2021301 [ 2 ] Bug #2113484 - libmodsecurity: FTBFS in Fedora rawhide/f37 https://bugzilla.redhat.com/show_bug.cgi?id=2113484 [ 3 ] Bug #2129200 - is libmodsecurity pkg still being maintained? https://bugzilla.redhat.com/show_bug.cgi?id=2129200 [ 4 ] Bug #2129515 - Non-responsive maintainer check for athmane https://bugzilla.redhat.com/show_bug.cgi?id=2129515 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-afa1e7b6c4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-dc9aee5510 2020-03-30 01:49:08.331314 --------------------------------------------------------------------------------Name : libmodsecurity Product : Fedora 31 Version : 3.0.3 Release : 6.fc31 URL : https://modsecurity.org/ Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. --------------------------------------------------------------------------------Update Information: Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719) --------------------------------------------------------------------------------ChangeLog: * Sat Mar 21 2020 Othman Madjoudj - 3.0.3-6 - Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719) * Wed Jan 29 2020 Fedora Release Engineering - 3.0.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1801719 - CVE-2019-19886 libmodsecurity: denial of service in Transaction::addRequestHeader in transaction.cc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1801719 [ 2 ] Bug #1801720 - CVE-2019-19886 libmodsecurity: denial of service in Transaction::addRequestHeader in transaction.cc [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1801720 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-dc9aee5510' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f7ba0ac7a4 2020-03-30 01:33:56.481524 --------------------------------------------------------------------------------Name : libmodsecurity Product : Fedora 30 Version : 3.0.2 Release : 6.fc30 URL : https://modsecurity.org/ Summary : A library that loads/interprets rules written in the ModSecurity SecRules Description : Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to ModSecurity Connectors taking in web traffic and applying traditional ModSecurity processing. In general, it provides the capability to load/interpret rules written in the ModSecurity SecRules format and apply them to HTTP content provided by your application via Connectors. --------------------------------------------------------------------------------Update Information: Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719) --------------------------------------------------------------------------------ChangeLog: * Sat Mar 21 2020 Othman Madjoudj - 3.0.2-6 - Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719) --------------------------------------------------------------------------------References: [ 1 ] Bug #1801719 - CVE-2019-19886 libmodsecurity: denial of service in Transaction::addRequestHeader in transaction.cc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1801719 [ 2 ] Bug #1801720 - CVE-2019-19886 libmodsecurity: denial of service in Transaction::addRequestHeader in transaction.cc [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1801720 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f7ba0ac7a4' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.