Upstream information

CVE-2009-5031 at MITRE

Description

ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.30
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entry: 768293 [CLOSED / WONTFIX]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP2
  • apache2-mod_security2 >= 2.7.1-0.2.12.1
Builds
SAT Patch Nr: 7606
openSUSE 12.3
  • apache2-mod_security2 >= 2.7.5-2.4.1
  • apache2-mod_security2-debuginfo >= 2.7.5-2.4.1
  • apache2-mod_security2-debugsource >= 2.7.5-2.4.1
Patchnames:
openSUSE-2013-641
openSUSE Evergreen 11.4
  • apache2-mod_security2 >= 2.7.5-12.1
  • apache2-mod_security2-debuginfo >= 2.7.5-12.1
  • apache2-mod_security2-debugsource >= 2.7.5-12.1
Patchnames:
2013-125