CVE-2009-1902 describes a denial-of-service vulnerability in ModSecurity versions prior to 2.5.9, affecting products like Fedora and Trustwave ModSecurity. An unauthenticated remote attacker can crash the system by sending a specially crafted multipart form data post request that triggers a NULL pointer dereference. While the CVSS score is 5.0 (medium severity) due to its low impact (partial availability), its FAUCET Risk Score of 88/100 indicates a higher potential risk. Although there is no evidence of active exploitation or Metasploit/Nuclei modules, an exploit (EDB-8241) is publicly available, yet community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.9CPE matchmatch criteria | cpe:2.3:a:trustwave:modsecurity:*:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.