CVE-2013-5705
15.04.2014, 10:55
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.Enginsight
| Vendor | Product | Version |
|---|---|---|
| trustwave | modsecurity | 𝑥 < 2.7.6 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libapache-mod-security |
| ||||||||||||||||||||||
| modsecurity-apache |
|
References