Debian Security Advisory

DSA-2506-1 libapache-mod-security -- ModSecurity bypass

Date Reported:
02 Jul 2012
Affected Packages:
libapache-mod-security
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 678529.
In Mitre's CVE dictionary: CVE-2012-2751.
More information:

Qualys Vulnerability & Malware Research Labs discovered a vulnerability in ModSecurity, a security module for the Apache webserver. In situations where both Content:Disposition: attachment and Content-Type: multipart were present in HTTP headers, the vulnerability could allow an attacker to bypass policy and execute cross-site script (XSS) attacks through properly crafted HTML documents.

For the stable distribution (squeeze), this problem has been fixed in version 2.5.12-1+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in version 2.6.6-1.

For the unstable distribution (sid), this problem has been fixed in version 2.6.6-1.

In testing and unstable distribution, the source package has been renamed to modsecurity-apache.

We recommend that you upgrade your libapache-mod-security packages.