CVE-2013-5705: Medium severity Trustwave ModSecurity vulnerability
Published Apr 15, 2014
·Updated
apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.
Affected Software
3 affected components
Trustwave ModSecurity<2.7.6
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Event History
Apr 15, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-5705?
CVE-2013-5705 has a medium severity rating, allowing attackers to bypass security rules.
2
How do I fix CVE-2013-5705?
To fix CVE-2013-5705, update ModSecurity to version 2.7.6 or later.
3
Who is affected by CVE-2013-5705?
CVE-2013-5705 affects users of ModSecurity versions prior to 2.7.6 on Apache servers.
4
What types of attacks exploit CVE-2013-5705?
CVE-2013-5705 is exploited through crafted HTTP requests using chunked transfer coding.
5
Is CVE-2013-5705 related to any specific operating systems?
CVE-2013-5705 is particularly relevant to Debian Linux 7.0 and 8.0 with ModSecurity.