CVE-2019-13464
CVE-2019-13464, security advisory, novell, suse linux, suse, security, cve

CVE-2019-13464

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2019-13464 at MITRE

Description

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having low severity.

SUSE Bugzilla entry: 1140969 [NEW]

No SUSE Security Announcements cross referenced.