#VU79793 Improper handling of exceptional conditions in ModSecurity - CVE-2019-25043
Published: August 21, 2023
ModSecurity
Trustwave
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of errors while parsing key-value pair. A remote attacker can send a specially crafted header to the server and perform a denial of service (DoS) attack, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.