ModSecurity versions 2.5.8 and 2.5.9 have been released to fix two vulnerabilities which could be used to cause a denial of service (DoS). The first vulnerability is fixed in version 2.5.8 and the second (as it was disclosed after version 2.5.8 was already frozen) is fixed in version 2.5.9. Because of this, the 2.5.8 release should be disregarded in favor of 2.5.9. Both vulnerabilities, however, have workarounds until ModSecurity can be upgraded/patched.
read also...
- Crash in nsTextFrame::ClearTextRun() – Firefox 3.0.9 (0)
- Fixed in Firefox 3.0.11 (several security issues) (0)
- Fixed in Firefox 3.0.12 (security issues) (0)
- Fixed in Firefox 3.5.2 (security issues) (0)
- 15 Rules to follow for safer web applications (3)
- Joomla/Mambo – PDF Indexer Module (7)
- Hotlinking, Bandwidth Theft and mod_rewrite (0)
- WordPress permalinks with Greek/Russian/Arabic characters (11)
- Athens StartUp Weekend 2 (0)
- Firefox 3.0.9 fixes several security and stability issues (0)


0 Comments.