-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-9518 2013-05-29 00:21:59 --------------------------------------------------------------------------------
Name : mod_security Product : Fedora 17 Version : 2.7.3 Release : 2.fc17 URL : http://www.modsecurity.org/ Summary : Security module for the Apache HTTP Server Description : ModSecurity is an open source intrusion detection and prevention engine for web applications. It operates embedded into the web server, acting as a powerful umbrella - shielding web applications from attacks. -------------------------------------------------------------------------------- Update Information: Fix NULL pointer dereference (DoS, crash) (CVE-2013-2765) and a possible memory leak. -------------------------------------------------------------------------------- ChangeLog: * Tue May 28 2013 Athmane Madjoudj <[email protected]> 2.7.3-2 - Fix NULL pointer dereference (DoS, crash) (CVE-2013-2765) (RHBZ #967615) - Fix a possible memory leak. * Sat Mar 30 2013 Athmane Madjoudj <[email protected]> 2.7.3-1 - Update to 2.7.3 * Fri Jan 25 2013 Athmane Madjoudj <[email protected]> 2.7.2-1 - Update to 2.7.2 - Update source url in the spec. * Thu Nov 22 2012 Athmane Madjoudj <[email protected]> 2.7.1-5 - Use conditional for loading mod_unique_id (rhbz #879264) - Fix syntax errors on httpd 2.4.x by using IncludeOptional (rhbz #879264, comment #2) * Mon Nov 19 2012 Peter Vrabec <[email protected]> 2.7.1-4 - mlogc subpackage is not provided on RHEL7 * Thu Nov 15 2012 Athmane Madjoudj <[email protected]> 2.7.1-3 - Add some missing directives RHBZ #569360 - Fix multipart/invalid part ruleset bypass issue (CVE-2012-4528) (RHBZ #867424, #867773, #867774) * Thu Nov 15 2012 Athmane Madjoudj <[email protected]> 2.7.1-2 - Fix mod_security.conf * Thu Nov 15 2012 Athmane Madjoudj <[email protected]> 2.7.1-1 - Update to 2.7.1 - Remove libxml2 build patch (upstreamed) - Update spec since upstream moved to github * Thu Oct 18 2012 Athmane Madjoudj <[email protected]> 2.7.0-2 - Add a patch to fix failed build against libxml2 >= 2.9.0 * Wed Oct 17 2012 Athmane Madjoudj <[email protected]> 2.7.0-1 - Update to 2.7.0 * Fri Sep 28 2012 Athmane Madjoudj <[email protected]> 2.6.8-1 - Update to 2.6.8 * Wed Sep 12 2012 Athmane Madjoudj <[email protected]> 2.6.7-2 - Re-add mlogc sub-package for epel (#856525) * Sat Aug 25 2012 Athmane Madjoudj <[email protected]> 2.6.7-1 - Update to 2.6.7 * Sat Aug 25 2012 Athmane Madjoudj <[email protected]> 2.6.7-1 - Update to 2.6.7 * Fri Jul 20 2012 Fedora Release Engineering <[email protected]> - 2.6.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Fri Jun 22 2012 Peter Vrabec <[email protected]> - 2.6.6-2 - mlogc subpackage is not provided on RHEL * Thu Jun 21 2012 Peter Vrabec <[email protected]> - 2.6.6-1 - upgrade * Mon May 7 2012 Joe Orton <[email protected]> - 2.6.5-3 - packaging fixes * Fri Apr 27 2012 Peter Vrabec <[email protected]> 2.6.5-2 - fix license tag * Thu Apr 5 2012 Peter Vrabec <[email protected]> 2.6.5-1 - upgrade & move rules into new package mod_security_crs * Fri Feb 10 2012 Petr Pisar <[email protected]> - 2.5.13-3 - Rebuild against PCRE 8.30 - Do not install non-existing files * Fri Jan 13 2012 Fedora Release Engineering <[email protected]> - 2.5.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild * Tue May 3 2011 Michael Fleming <[email protected]> - 2.5.13-1 - Newer upstream version -------------------------------------------------------------------------------- References: [ 1 ] Bug #967615 - mod_security: NULL pointer dereference (DoS, crash) when forceRequestBodyVariable action triggered and unknown Content-Type was used https://bugzilla.redhat.com/show_bug.cgi?id=967615 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mod_security' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
