Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-39275

Опубликовано: 16 сент. 2021
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

An out-of-bounds write in function ap_escape_quotes of httpd allows an unauthenticated remote attacker to crash the server or potentially execute code on the system with the privileges of the httpd user, by providing malicious input to the function.

Отчет

No httpd module in Red Hat Enterprise Linux and Red Hat Software Collections pass untrusted data to ap_escape_quotes function, thus the Impact of the flaw has been set to Moderate.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdOut of support scope
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:714326.10.2022
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2022:714326.10.2022
Red Hat Enterprise Linux 7httpdFixedRHSA-2022:014317.01.2022
Red Hat Enterprise Linux 8httpdFixedRHSA-2022:089115.03.2022
Red Hat Software Collections for Red Hat Enterprise Linux 7httpd24-httpdFixedRHSA-2022:675329.09.2022
Text-Only JBCSjbcs-httpd24-httpdFixedRHSA-2022:714426.10.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2005119httpd: Out-of-bounds write in ap_escape_quotes() via malicious input

EPSS

Процентиль: 98%
0.46965
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS3: 9.8
nvd
почти 4 года назад

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS3: 9.8
debian
почти 4 года назад

ap_escape_quotes() may write beyond the end of a buffer when given mal ...

suse-cvrf
больше 3 лет назад

Security update for apache2

CVSS3: 9.8
github
около 3 лет назад

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

EPSS

Процентиль: 98%
0.46965
Средний

8.1 High

CVSS3