CVE-2021-39275
published 2021-09-16CVE-2021-39275: ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
39.40%
98.5th percentile
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.49 | 2.4.49 |
| apache_software_foundation | apache_http_server | Apache HTTP Server 2.4 – 2.4.48 | — |
| debian | apache2 | < apache2 2.4.49-1 (bookworm) | apache2 2.4.49-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_httpd_2.4.52-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.49-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
| siemens | sinema_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable function is ap_escape_quotes() in Apache HTTP Server — monitor for out-of-bounds write conditions triggered by malicious input passed to this function via third-party/external modules. ↗
- →Restrict and monitor access to Port 443/TCP on affected Apache HTTP Server deployments (specifically Siemens RUGGEDCOM NMS, SINEC NMS, SINEMA Remote Connect Server, SINEMA Server v14) as a mitigation indicator. ↗
- ·No built-in Apache HTTP Server modules pass untrusted data to ap_escape_quotes(); exploitation requires a third-party or external module to be present that does so. Assess deployed third-party modules before prioritizing this CVE. ↗
- ·Red Hat confirmed no httpd module in RHEL or Red Hat Software Collections passes untrusted data to ap_escape_quotes, reducing practical impact in those environments. ↗
- ·Affected versions are Apache HTTP Server 2.4.48 and earlier; fixed in 2.4.49. Verify the running httpd version to confirm exposure. ↗
- ·No known public exploits specifically target this vulnerability as of the CISA advisory publication. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_cisco9.0CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens Apache HTTP Server (Update A)
cisa_ics·2022-06-16·CVSS 7.5
[HIGH] Siemens Apache HTTP Server (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Apache HTTP Server (Update A)
Last RevisedOctober 13, 2022
Alert CodeICSA-22-167-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Apache HTTP Server
- Vulnerabilities: NULL Pointer Dereference, Out-of-bounds Write, Server-side Request Forgery (SSRF)
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-22-167-06 Siemens Apache HTTP Server that was published June 16, 2022, to the ICS webpage on www.cisa.gov/uscert.
## 3. RISK EVALUATION
Success
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (Apache HTTP Server) — CVE-2021-39275
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-39275 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (Apache HTTP Server) — CVE-2021-39275
Oracle Oracle Fusion Middleware Risk Matrix: Web Listener (Apache HTTP Server) vulnerability
CVE: CVE-2021-39275
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Cisco
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
vendor_cisco·2021-11-24·CVSS 9.0
CVE-2021-33193 [CRITICAL] CWE-120 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
On September 16, 2021, the Apache Software Foundation disclosed five vulnerabilities affecting the Apache HTTP Server (httpd) 2.4.48 and earlier releases.
For a description of these vulnerabilities, see the Apache HTTP Server 2.4.49 section of the Apache HTTP Server 2.4 vulnerabilities webpage.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2021-09-28·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-5090-1 introduced a regression in Apache HTTP Server.
USN-5090-1 fixed vulnerabilities in Apache HTTP Server. One of the upstream
fixes introduced a regression in UDS URIs. This update fixes the problem.
Original advisory details:
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi mod
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-09-27·CVSS 7.5
CVE-2021-39275 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-5090-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
It was discovered that the Apache HTTP Server incorrectly handled escaping
quotes. If the server was configured with third-party modules, a remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-39275)
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2021-09-27·CVSS 7.5
CVE-2021-34798 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
This issue
Red Hat
httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
vendor_redhat·2021-09-16·CVSS 9.8
CVE-2021-39275 [CRITICAL] CWE-787 httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
An out-of-bounds write in function ap_escape_quotes of httpd allows an unauthenticated remote attacker to crash the server or potentially execute code on the system with the privileges of the httpd user, by providing malicious input to the function.
Statement: No httpd module in Red Hat Enterprise Linux and Red Hat Software Collections pass untrusted data to ap_escape_quotes function, thus the Impact of the flaw has been set to Moderate.
Mitigation: Mitigation for this issue is ei
Microsoft
ap_escape_quotes buffer overflow
vendor_msrc·2021-09-14·CVSS 9.8
CVE-2021-39275 [CRITICAL] CWE-787 ap_escape_quotes buffer overflow
ap_escape_quotes buffer overflow
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/
Debian
CVE-2021-39275: apache2 - ap_escape_quotes() may write beyond the end of a buffer when given malicious inp...
vendor_debian·2021·CVSS 9.8
CVE-2021-39275 [CRITICAL] CVE-2021-39275: apache2 - ap_escape_quotes() may write beyond the end of a buffer when given malicious inp...
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Scope: local
bookworm: resolved (fixed in 2.4.49-1)
bullseye: resolved (fixed in 2.4.51-1~deb11u1)
forky: resolved (fixed in 2.4.49-1)
sid: resolved (fixed in 2.4.49-1)
trixie: resolved (fixed in 2.4.49-1)
Cisco
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
vendor_cisco·CVSS 3.1
CVE-2021-39275 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
CVE-2021-39275: Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
On September 16, 2021, the Apache Software Foundation disclosed five vulnerabilities affecting the Apache HTTP Server (httpd) 2.4.48 and earlier releases. For a description of these vulnerabilities, see the Apache HTTP Server 2.4.49 section of the Apache HTTP Server 2.4 vulnerabilities webpage. This advisory will be updated as additional information becomes available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
CVSS: 3.1
CWE: CWE-120, CWE-125, CWE-476, CWE-120, CWE-125, CWE-476, CWE-918, CWE-120, CWE-125, CWE-476, CWE-120, CWE-125, CWE-476, CWE-918
Bug IDs: CSCwa33065,
GHSA
GHSA-p59c-pqfv-4fwc: ap_escape_quotes() may write beyond the end of a buffer when given malicious input
ghsa_unreviewed·2022-05-24
CVE-2021-39275 [CRITICAL] CWE-120 GHSA-p59c-pqfv-4fwc: ap_escape_quotes() may write beyond the end of a buffer when given malicious input
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
OSV
apache2 regression
osv·2021-09-28·CVSS 7.5
CVE-2021-33193 [HIGH] apache2 regression
apache2 regression
USN-5090-1 fixed vulnerabilities in Apache HTTP Server. One of the upstream
fixes introduced a regression in UDS URIs. This update fixes the problem.
Original advisory details:
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly us
OSV
apache2 vulnerabilities
osv·2021-09-27·CVSS 7.5
CVE-2021-34798 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-5090-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
It was discovered that the Apache HTTP Server incorrectly handled escaping
quotes. If the server was configured with third-party modules, a remote
attacker could use this issue to cause the server to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2021-39275)
It was discovered that the Apache mod_proxy module incorrectly handled
certain request
OSV
apache2 vulnerabilities
osv·2021-09-27·CVSS 7.5
CVE-2021-33193 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
James Kettle discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain crafted methods. A remote attacker could
possibly use this issue to perform request splitting or cache poisoning
attacks. (CVE-2021-33193)
It was discovered that the Apache HTTP Server incorrectly handled certain
malformed requests. A remote attacker could possibly use this issue to
cause the server to crash, resulting in a denial of service.
(CVE-2021-34798)
Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly
handled certain request uri-paths. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.04.
(CVE-2021-36160)
It was discovered t
OSV
CVE-2021-39275: ap_escape_quotes() may write beyond the end of a buffer when given malicious input
osv·2021-09-16·CVSS 9.8
CVE-2021-39275 [CRITICAL] CVE-2021-39275: ap_escape_quotes() may write beyond the end of a buffer when given malicious input
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
No detection rules found.
No public exploits indexed.
Hackernews
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
blogs_hackernews·2026-07-20
CVE-2016-7407 Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv , and the locations of Ukrainian troops.
That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing.
In Ukraine, the surveillance has not stayed passive. Camera access there has been "
Bugzilla
CVE-2021-39275 httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
bugzilla·2021-09-16·CVSS 9.8
CVE-2021-39275 [CRITICAL] CVE-2021-39275 httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
CVE-2021-39275 httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Reference:
https://httpd.apache.org/security/vulnerabilities_24.html
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 2005120]
---
This vulnerability is out of security support scope for the following product:
* Red Hat JBoss Enterprise Application Platform 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
Hi,
May I know when to fix this in Red Hat JBoss Core Service of fjbcs-ht
https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdfhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/10/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20211008-0004/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQhttps://www.debian.org/security/2021/dsa-4982https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdfhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/10/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20211008-0004/https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQhttps://www.debian.org/security/2021/dsa-4982https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2021-09-16
Published