Buffer Overflow Vulnerability in ap_escape_quotes() Function in Apache HTTP Server 2.4.48 and Earlier

Buffer Overflow Vulnerability in ap_escape_quotes() Function in Apache HTTP Server 2.4.48 and Earlier

CVE-2021-39275 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

Learn more about our Cis Benchmark Audit For Apache Http Server.