Re: CRS security releases covering several CVEs
Peter Kreuser <[email protected]> Tue, 27 Sep 2022 09:54:32 +0200
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <[email protected]> |
--===============3310563250852165829== Content-Type: multipart/alternative; boundary=Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4 Content-Transfer-Encoding: 7bit --Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi, =EF=BB=BFMay I ask why Debian rates them as "[bullseye] - modsecurity-crs <no-dsa> (Minor issues; will be fixed in point= release)" see for example https://security-tracker.debian.org/tracker/CVE-2022-39958=20= No updates so far available.... @Ervin Hegedues??? Best regards Peter > Am 21.09.2022 um 07:59 schrieb Christian Folini <[email protected]= om>: >=20 > =EF=BB=BFDear all, >=20 > Following ModSecurity's security releases earlier this month, we have foll= owed > suite and updated the stable CRS v3.2 and CRS v3.3 release branches as wel= l. >=20 > https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-seve= ral-cves/ >=20 > (Unfortunately, we also released a bug, so we had to followup with 3.3.4 a= nd > 3.2.3 immediately. Details in the blog.) >=20 > These two updates cover for several partial rule set bypasses: >=20 > CVE-2022-39955 =E2=80=93 Multiple charsets defined in Content-Type header > CVE-2022-39956 =E2=80=93 Content-Type or Content-Transfer-Encoding MIME he= ader abuse > CVE-2022-39957 =E2=80=93 Charset accept header field resulting in resp rul= e set bypass > CVE-2022-39958 =E2=80=93 Small range header leading to response rule set b= ypass >=20 > Outside of these CVE-worthy fixes, there are a handful of security fixes t= hat > are of slightly lower severity. >=20 > Please be aware that the fix to CVE-2022-39956 depends on the update of > ModSecurity to the versions 2.9.6 or 3.0.8. >=20 > Best regards, >=20 > Christian Folini, OWASP ModSecurity Core Rule Set co-lead >=20 >=20 > --=20 > Ultimately, motivation gets us started,=20 > but discipline and habit are what enable us to finish. > -- Matthew Helmke >=20 >=20 > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ --Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><span style=3D"-webkit-text-size-adjust: au= to;">Hi,</span><br><div dir=3D"ltr"><div dir=3D"ltr" class=3D"" style=3D"-we= bkit-text-size-adjust: auto;"><br class=3D""></div><div dir=3D"ltr" class=3D= "" style=3D"-webkit-text-size-adjust: auto;">=EF=BB=BFMay I ask why Debian r= ates them as</div><div dir=3D"ltr" class=3D"" style=3D"-webkit-text-size-adj= ust: auto;"><br class=3D""><div class=3D"">"<span class=3D"" style=3D"caret-= color: rgb(51, 51, 51); color: rgb(51, 51, 51); font-size: 14px;">[bullseye]= - modsecurity-crs <no-dsa> (Minor issues; will be fixed in point rele= ase)"</span></div><div class=3D""><font color=3D"#333333" class=3D""><span c= lass=3D"" style=3D"font-size: 14px;"><br class=3D""></span></font></div><div= class=3D""><font color=3D"#333333" class=3D""><span class=3D"" style=3D"fon= t-size: 14px;">see for example</span></font> <a href=3D"https://securit= y-tracker.debian.org/tracker/CVE-2022-39958" class=3D"">https://security-tra= cker.debian.org/tracker/CVE-2022-39958</a> </div><div class=3D""><br cl= ass=3D""></div><div class=3D"">No updates so far available.... @Ervin Hegedu= es???</div><div class=3D""><br class=3D""></div><div class=3D"">Best regards= </div><div class=3D""><br class=3D""></div><div class=3D"">Peter</div></div>= </div><div dir=3D"ltr"><br><blockquote type=3D"cite">Am 21.09.2022 um 07:59 s= chrieb Christian Folini <[email protected]>:<br><br></blockq= uote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<span>Dear al= l,</span><br><span></span><br><span>Following ModSecurity's security release= s earlier this month, we have followed</span><br><span>suite and updated the= stable CRS v3.2 and CRS v3.3 release branches as well.</span><br><span></sp= an><br><span>https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-co= vering-several-cves/</span><br><span></span><br><span>(Unfortunately, we als= o released a bug, so we had to followup with 3.3.4 and</span><br><span>3.2.3= immediately. Details in the blog.)</span><br><span></span><br><span>These t= wo updates cover for several partial rule set bypasses:</span><br><span></sp= an><br><span>CVE-2022-39955 =E2=80=93 Multiple charsets defined in Content-T= ype header</span><br><span>CVE-2022-39956 =E2=80=93 Content-Type or Content-= Transfer-Encoding MIME header abuse</span><br><span>CVE-2022-39957 =E2=80=93= Charset accept header field resulting in resp rule set bypass</span><br><sp= an>CVE-2022-39958 =E2=80=93 Small range header leading to response rule set b= ypass</span><br><span></span><br><span>Outside of these CVE-worthy fixes, th= ere are a handful of security fixes that</span><br><span>are of slightly low= er severity.</span><br><span></span><br><span>Please be aware that the fix t= o CVE-2022-39956 depends on the update of</span><br><span>ModSecurity to the= versions 2.9.6 or 3.0.8.</span><br><span></span><br><span>Best regards,</sp= an><br><span></span><br><span>Christian Folini, OWASP ModSecurity Core Rule S= et co-lead</span><br><span></span><br><span></span><br><span>-- </span><br><= span>Ultimately, motivation gets us started, </span><br><span>but discipline= and habit are what enable us to finish.</span><br><span>-- Matthew Helmke</= span><br><span></span><br><span></span><br><span>___________________________= ____________________</span><br><span>mod-security-users mailing list</span><= br><span>[email protected]</span><br><span>https://li= sts.sourceforge.net/lists/listinfo/mod-security-users</span><br><span>Commer= cial ModSecurity Rules and Support from Trustwave's SpiderLabs:</span><br><s= pan>http://www.modsecurity.org/projects/commercial/rules/</span><br><span>ht= tp://www.modsecurity.org/projects/commercial/support/</span><br></div></bloc= kquote></body></html>= --Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4-- --===============3310563250852165829== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3310563250852165829== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ --===============3310563250852165829==--