Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-2765NULL Pointer Dereference in Modsecurity

Severity
5.0MEDIUMNVD
EPSS
5.4%
top 9.88%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 15
Latest updateMay 13

Description

The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDopensuse/opensuse11.4, 12.2, 12.3+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x49q-wq3g-gh64: The ModSecurity module before 22022-05-13
OSV
CVE-2013-2765: The ModSecurity module before 22013-07-15
CVEList
CVE-2013-2765: The ModSecurity module before 22013-07-15

💥Exploits & PoCs

1
Exploit-DB
ModSecurity - Remote Null Pointer Dereference2013-05-31

📋Vendor Advisories

1
Debian
CVE-2013-2765: modsecurity-apache - The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote att...2013

💬Community

1
Bugzilla
mod_security: NULL pointer dereference (DoS, crash) when forceRequestBodyVariable action triggered and unknown Content-Type was used2013-05-27
CVE-2013-2765 — NULL Pointer Dereference in Modsecurity | cvebase