CVE-2009-1903: XSS
Published Jun 3, 2009
·Updated
The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
Affected Software
3 affected components
Trustwave ModSecurity<2.5.8
Fedoraproject Fedora=10
Fedoraproject Fedora=9
Event History
Jun 3, 2009
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1903?
CVE-2009-1903 is classified as a moderate vulnerability due to its potential to cause denial of service.
2
How can CVE-2009-1903 impact my server?
CVE-2009-1903 can lead to an Apache httpd crash when a PDF file is requested without using the GET method.
3
How do I fix CVE-2009-1903?
To fix CVE-2009-1903, users should upgrade to ModSecurity version 2.5.8 or newer.
4
Which versions of ModSecurity are affected by CVE-2009-1903?
Versions of ModSecurity before 2.5.8 are affected by CVE-2009-1903.
5
Is CVE-2009-1903 specific to certain operating systems?
CVE-2009-1903 affects ModSecurity installations on various operating systems, including Fedora 9 and 10.