I've pushed a mod_security update for CVE-2013-2765: NULL pointer dereference (DoS, crash) when forceRequestBodyVariable action triggered and unknown Content-Type was used.
- https://admin.fedoraproject.org/updates/mod_security-2.7.3-2.fc19
- https://admin.fedoraproject.org/updates/mod_security-2.7.3-2.fc18
- https://admin.fedoraproject.org/updates/mod_security-2.7.3-2.fc17
- https://admin.fedoraproject.org/updates/mod_security-2.7.3-2.el6
- https://admin.fedoraproject.org/updates/mod_security-2.6.8-4.el5