| Summary: | PCRE limits seem broken with simple input | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | long | ||||
| Component: | mod_security | Assignee: | Othman Madjoudj <athmanem> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | el6 | CC: | athmanem, mfleming+rpm, redhat-bugs, stjepan.gros | ||||
| Target Milestone: | --- | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2012-09-11 03:12:55 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Attachments: |
|
||||||
|
Description
long
2012-01-11 22:53:52 UTC
This issue seems to exist in mod_security-2.5.12-3.el5.i386 as well. The issue is present also in mod_security 2.5.12-3.el5. Here is the POST request that triggers the bug: POST /ib/servlet HTTP/1.1 Content-Type: application/x-www-form-urlencoded Host: localhost Content-Length: 56 svrha=502%2C503%2C495%2C498%2C499-5+kom+-JAM%C4%8CEVINA I also reported this issue to upstream: https://www.modsecurity.org/tracker/browse/MODSEC-309 I got response to upgrade to the newest version. Is it possible to update mod_security to newest version, i.e. 2.6.6? Can check if this issue is still reproducible with the latest mod_security and mod_security_crs from epel-testing. I just tried with mod_security-2.6.7-1.el6.x86_64 from epel and the problem does not seem to happen any longer. |