CVE-2021-39275

CRITICAL9.8EPSS 37.7%

ap_escape_quotes buffer overflow

Published: 9/16/2021Modified: 5/20/2025
Also known as:ALPINE-CVE-2021-39275BIT-apache-2021-39275

Description

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (18)