Back to search
CVE-2013-2765
Published: Jul 15, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[mod-security-users] 20130527 Availability of ModSecurity 2.7.4 Stable Release
mailing-list
x_refsource_MLIST
openSUSE-SU-2013:1342
vendor-advisory
x_refsource_SUSE
https://bugzilla.redhat.com/show_bug.cgi?id=967615
x_refsource_CONFIRM
openSUSE-SU-2013:1331
vendor-advisory
x_refsource_SUSE
20130528 [SECURITY][CVE-2013-2765][ModSecurity] Remote Null Pointer Dereference
mailing-list
x_refsource_BUGTRAQ
https://raw.github.com/SpiderLabs/ModSecurity/master/CHANGES
x_refsource_CONFIRM
http://www.shookalabs.com/
x_refsource_MISC
http://www.modsecurity.org/
x_refsource_CONFIRM
openSUSE-SU-2013:1336
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now