IT

Tracker / CVE-2009-2299

CVE-2009-2299

Medium 5.0

The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.

Affected products and versions

hyperguard_web_application_firewall_project hyperguard_web_application_firewall · … → 2.5.5-11635
hyperguard_web_application_firewall_project hyperguard_web_application_firewall · 3.0 → 3.0.3-11636
hyperguard_web_application_firewall_project hyperguard_web_application_firewall · 3.1 → 3.1.1-11637

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References