[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2659-1 libapache-mod-security -- XML external entity processing vulnerability

ID: oval:org.secpod.oval:def:601004Date: (C)2013-04-15   (M)2022-10-10
Class: PATCHFamily: unix




Timur Yunusov and Alexey Osipov from Positive Technologies discovered that the XML files parser of ModSecurity, an Apache module whose purpose is to tighten the Web application security, is vulnerable to XML external entities attacks. A specially-crafted XML file provided by a remote attacker, could lead to local file disclosure or excessive resources consumption when processed. This update introduces a SecXmlExternalEntity option which is "Off" by default. This will disable the ability of libxml2 to load external entities.

Platform:
Debian 6.0
Product:
libapache-mod-security
Reference:
DSA-2659-1
CVE-2013-1915
CVE    1
CVE-2013-1915
CPE    2
cpe:/a:cpe:/a:apache:libapache-mod-security
cpe:/o:debian:debian_linux:6.0

© SecPod Technologies