CVE-2013-2765
EPSS 5.4%
Description
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.
How to fix CVE-2013-2765
To remediate CVE-2013-2765, upgrade the affected package to a fixed version below.
- Debian/modsecurity-apache—upgrade to 2.6.6-9 or later
Is CVE-2013-2765 being exploited?
Moderate — EPSS is 5.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.6-9