Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators
Vulnerability Description
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.
CVSS Information
N/A
Vulnerability Type
整数下溢(超界折返)
Vulnerability Title
Modsecurity 数字错误漏洞
Vulnerability Description
Modsecurity是OWASP ModSecurity开源的一个Web流量安全处理库。 ModSecurity 3.0.0版本至3.0.15之前版本存在数字错误漏洞,该漏洞源于无符号整数下溢导致未处理异常,可能导致使用特定规则时崩溃。
CVSS Information
N/A
Vulnerability Type
N/A