ubuntu · CVE-2024-46292

Quick triage

Priority: medium Published: 2024-10-09 16:15:00 UTC Updated: 2025-07-11 07:59:16 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2024-46292 medium priority: Ubuntu including 1 source packages (modsecurity), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): needs-triage 5, ignored 2.

Description:

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

cvelogic Threat Intelligence