Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 240946 (CVE-2008-5676) - www-apache/mod_security <2.5.6 "SecCacheTransformations" Vulnerability (CVE-2008-5676)
Summary: www-apache/mod_security <2.5.6 "SecCacheTransformations" Vulnerability (CVE-2...
Status: RESOLVED FIXED
Alias: CVE-2008-5676
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://secunia.com/Advisories/32146/
Whiteboard: ~3? [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-10 00:03 UTC by Robert Buchholz (RETIRED)
Modified: 2009-01-02 13:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-10-10 00:03:22 UTC
Secunia wrote:
A vulnerability has been reported in ModSecurity, which potentially
can be exploited by malicious people to bypass certain security
restrictions.

The vulnerability is caused due to an error within the transformation
caching, which may be exploited to evade ModSecurity under certain
unspecified circumstances.

Successful exploitation requires that "SecCacheTransformations" is
enabled.

Note: It was also reported that this option is unstable and may crash
the web server.

The vulnerability is reported in version 2.5.0 through 2.5.5.

SOLUTION:
Update to version 2.5.6.

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
http://blog.modsecurity.org/2008/08/transformation.html
http://freshmeat.net/projects/modsecurity/?branch_id=34901&release_id=282329
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-11-28 17:56:40 UTC
ping, apache herd please bump.
Comment 2 Bruno Buss 2008-12-22 21:24:10 UTC
CVE-2008-5676:
Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."

Link:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-5676
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2008-12-24 16:14:52 UTC
*ping*
Comment 4 Benedikt Böhm (RETIRED) gentoo-dev 2009-01-01 14:11:32 UTC
2.5.6 in cvs
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2009-01-02 13:45:23 UTC
Thanks, closing since this only affected ~arch.