vendor:
ModSecurity
by:
Younes JAAIDI
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: ModSecurity
Affected Version From: Prior to 2.7.4
Affected Version To: 2.7.4
Patch Exists: YES
Related CWE: CVE-2013-2765
CPE: a:modsecurity:mod_security
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
ModSecurity DOS Check
When ModSecurity receives a request body with a size bigger than the value set by the 'SecRequestBodyInMemoryLimit' and with a 'Content-Type' that has no request body processor mapped to it, ModSecurity will systematically crash on every call to 'forceRequestBodyVariable' (in phase 1).
Mitigation:
Upgrade to ModSecurity version 2.7.4 or later.