CVE Vulnerabilities

CVE-2019-25043

Improper Handling of Exceptional Conditions

Published: May 06, 2021 | Modified: May 14, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a string index out of range error and worker-process crash for a Cookie: =abc header.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Modsecurity Trustwave 3.0.0 (including) 3.0.4 (excluding)
Modsecurity Ubuntu groovy *
Modsecurity Ubuntu hirsute *
Modsecurity Ubuntu impish *
Modsecurity Ubuntu kinetic *
Modsecurity Ubuntu lunar *
Modsecurity Ubuntu mantic *
Modsecurity Ubuntu trusty *
Modsecurity Ubuntu xenial *

References