CVE-2013-2765: Opensuse

Medium severity, CVSS 5.0. EPSS: 13.7% chance of exploitation in the next 30 days.

The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.

Affected products

  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Trustwave Modsecurity: before 2.7.4 (fixed in 2.7.4)

Published 2013-07-15. Last modified 2026-06-16.