From the Gentoo advisory: Multiple vulnerabilities were discovered in ModSecurity:
* Juan Galiana Lara of ISecAuditors discovered a NULL pointer
dereference when processing multipart requests without a part header
name (CVE-2009-1902).
* Steve Grubb of Red Hat reported that the "PDF XSS protection"
feature does not properly handle HTTP requests to a PDF file that do
not use the GET method (CVE-2009-1903).