drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Rechteprüfung in mod_security
Name: |
Mangelnde Rechteprüfung in mod_security |
|
ID: |
FEDORA-2012-18315 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 17 |
|
Datum: |
Sa, 1. Dezember 2012, 11:16 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4528 |
|
Applikationen: |
ModSecurity |
|
Originalnachricht |
Name : mod_security Product : Fedora 17 Version : 2.7.1 Release : 3.fc17 URL : http://www.modsecurity.org/ Summary : Security module for the Apache HTTP Server Description : ModSecurity is an open source intrusion detection and prevention engine for web applications. It operates embedded into the web server, acting as a powerful umbrella - shielding web applications from attacks.
------------------------------------------------------------------------------- - Update Information:
- Update to 2.7.1
- Update Core rules set to 2.2.6
- Fix build against libxml2 >= 2.9 (upstreamed)
- Add some missing directives RHBZ #569360
- Fix multipart/invalid part ruleset bypass issue (CVE-2012-4528) (RHBZ #867424, #867773, #867774) ------------------------------------------------------------------------------- - ChangeLog:
* Thu Nov 15 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.7.1-3 - Add some missing directives RHBZ #569360 - Fix multipart/invalid part ruleset bypass issue (CVE-2012-4528) (RHBZ #867424, #867773, #867774) * Thu Nov 15 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.7.1-2 - Fix mod_security.conf * Thu Nov 15 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.7.1-1 - Update to 2.7.1 - Remove libxml2 build patch (upstreamed) - Update spec since upstream moved to github * Thu Oct 18 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.7.0-2 - Add a patch to fix failed build against libxml2 >= 2.9.0 * Wed Oct 17 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.7.0-1 - Update to 2.7.0 * Fri Sep 28 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.6.8-1 - Update to 2.6.8 * Wed Sep 12 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.6.7-2 - Re-add mlogc sub-package for epel (#856525) * Sat Aug 25 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.6.7-1 - Update to 2.6.7 * Sat Aug 25 2012 Athmane Madjoudj <athmane@fedoraproject.org> 2.6.7-1 - Update to 2.6.7 * Fri Jul 20 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.6.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Fri Jun 22 2012 Peter Vrabec <pvrabec@redhat.com> - 2.6.6-2 - mlogc subpackage is not provided on RHEL * Thu Jun 21 2012 Peter Vrabec <pvrabec@redhat.com> - 2.6.6-1 - upgrade * Mon May 7 2012 Joe Orton <jorton@redhat.com> - 2.6.5-3 - packaging fixes * Fri Apr 27 2012 Peter Vrabec <pvrabec@redhat.com> 2.6.5-2 - fix license tag * Thu Apr 5 2012 Peter Vrabec <pvrabec@redhat.com> 2.6.5-1 - upgrade & move rules into new package mod_security_crs * Fri Feb 10 2012 Petr Pisar <ppisar@redhat.com> - 2.5.13-3 - Rebuild against PCRE 8.30 - Do not install non-existing files * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.5.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild * Tue May 3 2011 Michael Fleming <mfleming+rpm@thatfleminggent.com> - 2.5.13-1 - Newer upstream version ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #867424 - CVE-2012-4528 mod_security: multipart/invalid part ruleset bypass https://bugzilla.redhat.com/show_bug.cgi?id=867424 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update mod_security' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|