CVE-2021-39275

Related Vulnerabilities: CVE-2021-39275  

An out-of-bounds write in function ap_escape_quotes of httpd allows an unauthenticated remote attacker to crash the server or potentially execute code on the system with the privileges of the httpd user, by providing malicious input to the function.

Description

An out-of-bounds write in function ap_escape_quotes of httpd allows an unauthenticated remote attacker to crash the server or potentially execute code on the system with the privileges of the httpd user, by providing malicious input to the function.

Statement

No httpd module in Red Hat Enterprise Linux and Red Hat Software Collections pass untrusted data to ap_escape_quotes function, thus the Impact of the flaw has been set to Moderate.

No httpd module in Red Hat Enterprise Linux and Red Hat Software Collections pass untrusted data to ap_escape_quotes function, thus the Impact of the flaw has been set to Moderate.

Additional Information

  • Bugzilla 2005119: CVE-2021-39275 httpd: out-of-bounds write in ap_escape_quotes() via malicious input
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2021-39275