FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

ModSecurity -- XML External Entity Processing Vulnerability

Affected packages
2.* < mod_security < 2.7.3

Details

VuXML ID 2070c79a-8e1e-11e2-b34d-000c2957946c
Discovery 2013-04-02
Entry 2013-04-16

Positive Technologies has reported a vulnerability in ModSecurity, which can be exploited by malicious people to disclose potentially sensitive information or cause a DoS (Denial Of Serice).

The vulnerability is caused due to an error when parsing external XML entities and can be exploited to e.g. disclose local files or cause excessive memory and CPU consumption.

.

References

CVE Name CVE-2013-1915
URL https://bugs.gentoo.org/show_bug.cgi?id=464188
URL https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1915
URL https://secunia.com/advisories/52847/