CVE-2008-5676

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/12/2008
Last modified:
09/04/2025

Description

Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:breach:modsecurity:*:*:*:*:*:*:*:* 2.5.0 (including)
cpe:2.3:a:breach:modsecurity:*:*:*:*:*:*:*:* 2.5.5 (including)
cpe:2.3:a:breach:modsecurity:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:breach:modsecurity:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:breach:modsecurity:2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:breach:modsecurity:2.5.4:*:*:*:*:*:*:*