security fixes in latest release

Bug #602947 reported by Skout23
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libapache-mod-security (Ubuntu)
Confirmed
Undecided
Unassigned
Nominated for Lucid by Amr Muhammad

Bug Description

Binary package hint: libapache-mod-security

As suggested I am filing a bug.

Lucid package is ModSecurity v2.5.11 based, however v2.5.12 was released on Feb 4, 2010, with the following note.

"ModSecurity v2.5.12 (change log) has been released. This release fixes several important issues to help prevent a detection bypass and denial of service attacks against ModSecurity. "

I see a package on Maverick, however have no desire to switch away from LTS at this time. Is there a projected timeline for a Lucid update to 2.5.12?

Thanks,
Scott

Tags: dos
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

visibility: private → public
Changed in libapache-mod-security (Ubuntu):
status: New → Confirmed
Revision history for this message
Arunas Pranckevicius (apranckevicius) wrote :

Hello,

The latest mod_security rules break library version 2.5.11-1 with error when restarting Apache:
"Error creating rule: Unknown variable: REQBODY_ERROR"

Also mod_security has stable version 2.6.x which includes new configuration options:
http://comments.gmane.org/gmane.comp.apache.mod-security.owasp-crs/396

When we can expect stable update in Ubuntu 10.04.3 LTS ?

Cheers,
Arunas

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.