CVE-2013-5705
15.04.2014, 10:55
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.Enginsight
Vendor | Product | Version |
---|---|---|
trustwave | modsecurity | 𝑥 < 2.7.6 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libapache-mod-security |
| ||||||||||||||||||||||
modsecurity-apache |
|
References