ModSecurity versions 2.5.8 and 2.5.9 have been released to fix two vulnerabilities which could be used to cause a denial of service (DoS). The first vulnerability is fixed in version 2.5.8 and the second (as it was disclosed after version 2.5.8 was already frozen) is fixed in version 2.5.9. Because of this, the 2.5.8 release should be disregarded in favor of 2.5.9. Both vulnerabilities, however, have workarounds until ModSecurity can be upgraded/patched.
read also...
- 06/08/2009 -- Fixed in Firefox 3.5.2 (security issues) (0)
- 22/07/2009 -- Fixed in Firefox 3.0.12 (security issues) (0)
- 12/06/2009 -- Fixed in Firefox 3.0.11 (several security issues) (0)
- 28/04/2009 -- Crash in nsTextFrame::ClearTextRun() – Firefox 3.0.9 (0)
- 31/01/2011 -- Wordpress permalinks with Greek/Russian/Arabic characters (10)
- 20/12/2009 -- 15 Rules to follow for safer web applications (3)
- 15/12/2009 -- Athens StartUp Weekend 2 (0)
- 17/05/2009 -- The Open Web Application Security Project (OWASP) (0)
- 06/05/2009 -- Joomla/Mambo – PDF Indexer Module (7)
- 01/05/2009 -- Hotlinking, Bandwidth Theft and mod_rewrite (0)
Recent Comments