ubuntu · CVE-2024-46292

Quick triage

Priority: medium 公開: 2024-10-09 16:15:00 UTC Updated: 2025-07-11 07:59:16 UTC

参照: Official ubuntu advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2024-46292 medium priority: Ubuntu including 1 source packages (modsecurity), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): needs-triage 5, ignored 2.

Description:

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

cvelogic Threat Intelligence