CVE-2013-2765: Opensuse
Medium severity, CVSS 5.0. EPSS: 13.7% chance of exploitation in the next 30 days.
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
Affected products
- Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
- Trustwave Modsecurity: before 2.7.4 (fixed in 2.7.4)
Published 2013-07-15. Last modified 2026-06-16.