CVE-2024-46292: Buffer Overflow
A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46292?
CVE-2024-46292 is classified as a Denial of Service (DoS) vulnerability due to a buffer overflow in ModSecurity.
How do I fix CVE-2024-46292?
To mitigate CVE-2024-46292, update to the latest version of ModSecurity that addresses this vulnerability.
What software is affected by CVE-2024-46292?
CVE-2024-46292 affects ModSecurity version 3.0.12.
Can CVE-2024-46292 be exploited remotely?
Yes, CVE-2024-46292 allows attackers to exploit the vulnerability remotely through crafted input.
Is CVE-2024-46292 a confirmed vulnerability?
CVE-2024-46292 is disputed by the supplier, citing that the issue cannot be reproduced.