ModSecurity x-www-form-urlencoded security bypass
| modsecurity-formurlencoded-security-bypass (32872) |
Description:
ModSecurity could allow a remote attacker to bypass security restrictions, caused by improper validation of POST requests. By adding NULL bytes to the application/x-www-form-urlencoded content type, a remote attacker could exploit this vulnerability to bypass security restrictions.
Platforms Affected:
- Breach Security, ModSecurity 2.1.0 and prior
- Gentoo, Linux
- Oracle, Application Server 10.1.2.2.0 R2
- Oracle, Application Server 10.1.2.3.0 R2
- Oracle, Application Server 10.1.3.0.0 R3
- Oracle, Application Server 10.1.3.1.0 R3
Remedy:
For Gentoo Linux (mod_security):
Refer to GLSA 200705-17 for patch, upgrade, or suggested workaround information. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Bypass Security
References:
- ModSecurity Web site, ModSecurity at http://www.modsecurity.org/.
- MOPB BONUS-12-2007, mod_security POST Rules Bypass Vulnerability at http://www.php-security.org/MOPB/BONUS-12-2007.html.
- Oracle Critical Patch Update - July 2008, Oracle Critical Patch Update Advisory - July 2008 at http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html.
- BID-22831: Mod_Security ASCIIZ Byte POST Bypass Vulnerability
- BID-30177: Oracle July 2008 Critical Patch Update Multiple Vulnerabilities
- CVE-2007-1359: Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.
- GLSA-200705-17: Apache mod_security: Rule bypass
- OSVDB ID: 32778: ModSecurity POST Data Null Byte Filter Bypass
- SA24373: ModSecurity POST Data NULL Byte Rule Bypass
- SA31087: Oracle Products Multiple Vulnerabilities
- SA31113: HP Oracle for OpenView Multiple Vulnerabilities
- VUPEN/ADV-2007-0868: ModSecurity (mod_security) x-www-form-urlencoded Data Security Bypass Vulnerability
- VUPEN/ADV-2008-2109: Oracle Products Multiple Code Execution and Security Bypass Issues
- VUPEN/ADV-2008-2115: HP Oracle for OpenView Code Execution and Security Bypass Issues
Reported:
Mar 06, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
