Re: CRS security releases covering several CVEs

Peter Kreuser <[email protected]> Tue, 27 Sep 2022 09:54:32 +0200
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
--===============3310563250852165829==
Content-Type: multipart/alternative;
 boundary=Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4
Content-Transfer-Encoding: 7bit


--Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi,

=EF=BB=BFMay I ask why Debian rates them as

"[bullseye] - modsecurity-crs <no-dsa> (Minor issues; will be fixed in point=
 release)"

see for example https://security-tracker.debian.org/tracker/CVE-2022-39958=20=


No updates so far available.... @Ervin Hegedues???

Best regards

Peter

> Am 21.09.2022 um 07:59 schrieb Christian Folini <[email protected]=
om>:
>=20
> =EF=BB=BFDear all,
>=20
> Following ModSecurity's security releases earlier this month, we have foll=
owed
> suite and updated the stable CRS v3.2 and CRS v3.3 release branches as wel=
l.
>=20
> https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-seve=
ral-cves/
>=20
> (Unfortunately, we also released a bug, so we had to followup with 3.3.4 a=
nd
> 3.2.3 immediately. Details in the blog.)
>=20
> These two updates cover for several partial rule set bypasses:
>=20
> CVE-2022-39955 =E2=80=93 Multiple charsets defined in Content-Type header
> CVE-2022-39956 =E2=80=93 Content-Type or Content-Transfer-Encoding MIME he=
ader abuse
> CVE-2022-39957 =E2=80=93 Charset accept header field resulting in resp rul=
e set bypass
> CVE-2022-39958 =E2=80=93 Small range header leading to response rule set b=
ypass
>=20
> Outside of these CVE-worthy fixes, there are a handful of security fixes t=
hat
> are of slightly lower severity.
>=20
> Please be aware that the fix to CVE-2022-39956 depends on the update of
> ModSecurity to the versions 2.9.6 or 3.0.8.
>=20
> Best regards,
>=20
> Christian Folini, OWASP ModSecurity Core Rule Set co-lead
>=20
>=20
> --=20
> Ultimately, motivation gets us started,=20
> but discipline and habit are what enable us to finish.
> -- Matthew Helmke
>=20
>=20
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/

--Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><span style=3D"-webkit-text-size-adjust: au=
to;">Hi,</span><br><div dir=3D"ltr"><div dir=3D"ltr" class=3D"" style=3D"-we=
bkit-text-size-adjust: auto;"><br class=3D""></div><div dir=3D"ltr" class=3D=
"" style=3D"-webkit-text-size-adjust: auto;">=EF=BB=BFMay I ask why Debian r=
ates them as</div><div dir=3D"ltr" class=3D"" style=3D"-webkit-text-size-adj=
ust: auto;"><br class=3D""><div class=3D"">"<span class=3D"" style=3D"caret-=
color: rgb(51, 51, 51); color: rgb(51, 51, 51); font-size: 14px;">[bullseye]=
 - modsecurity-crs &lt;no-dsa&gt; (Minor issues; will be fixed in point rele=
ase)"</span></div><div class=3D""><font color=3D"#333333" class=3D""><span c=
lass=3D"" style=3D"font-size: 14px;"><br class=3D""></span></font></div><div=
 class=3D""><font color=3D"#333333" class=3D""><span class=3D"" style=3D"fon=
t-size: 14px;">see for example</span></font>&nbsp;<a href=3D"https://securit=
y-tracker.debian.org/tracker/CVE-2022-39958" class=3D"">https://security-tra=
cker.debian.org/tracker/CVE-2022-39958</a>&nbsp;</div><div class=3D""><br cl=
ass=3D""></div><div class=3D"">No updates so far available.... @Ervin Hegedu=
es???</div><div class=3D""><br class=3D""></div><div class=3D"">Best regards=
</div><div class=3D""><br class=3D""></div><div class=3D"">Peter</div></div>=
</div><div dir=3D"ltr"><br><blockquote type=3D"cite">Am 21.09.2022 um 07:59 s=
chrieb Christian Folini &lt;[email protected]&gt;:<br><br></blockq=
uote></div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<span>Dear al=
l,</span><br><span></span><br><span>Following ModSecurity's security release=
s earlier this month, we have followed</span><br><span>suite and updated the=
 stable CRS v3.2 and CRS v3.3 release branches as well.</span><br><span></sp=
an><br><span>https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-co=
vering-several-cves/</span><br><span></span><br><span>(Unfortunately, we als=
o released a bug, so we had to followup with 3.3.4 and</span><br><span>3.2.3=
 immediately. Details in the blog.)</span><br><span></span><br><span>These t=
wo updates cover for several partial rule set bypasses:</span><br><span></sp=
an><br><span>CVE-2022-39955 =E2=80=93 Multiple charsets defined in Content-T=
ype header</span><br><span>CVE-2022-39956 =E2=80=93 Content-Type or Content-=
Transfer-Encoding MIME header abuse</span><br><span>CVE-2022-39957 =E2=80=93=
 Charset accept header field resulting in resp rule set bypass</span><br><sp=
an>CVE-2022-39958 =E2=80=93 Small range header leading to response rule set b=
ypass</span><br><span></span><br><span>Outside of these CVE-worthy fixes, th=
ere are a handful of security fixes that</span><br><span>are of slightly low=
er severity.</span><br><span></span><br><span>Please be aware that the fix t=
o CVE-2022-39956 depends on the update of</span><br><span>ModSecurity to the=
 versions 2.9.6 or 3.0.8.</span><br><span></span><br><span>Best regards,</sp=
an><br><span></span><br><span>Christian Folini, OWASP ModSecurity Core Rule S=
et co-lead</span><br><span></span><br><span></span><br><span>-- </span><br><=
span>Ultimately, motivation gets us started, </span><br><span>but discipline=
 and habit are what enable us to finish.</span><br><span>-- Matthew Helmke</=
span><br><span></span><br><span></span><br><span>___________________________=
____________________</span><br><span>mod-security-users mailing list</span><=
br><span>[email protected]</span><br><span>https://li=
sts.sourceforge.net/lists/listinfo/mod-security-users</span><br><span>Commer=
cial ModSecurity Rules and Support from Trustwave's SpiderLabs:</span><br><s=
pan>http://www.modsecurity.org/projects/commercial/rules/</span><br><span>ht=
tp://www.modsecurity.org/projects/commercial/support/</span><br></div></bloc=
kquote></body></html>=

--Apple-Mail-DF08DF73-E14B-4149-B67C-1D809544F7C4--


--===============3310563250852165829==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============3310563250852165829==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============3310563250852165829==--