Description
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1423)
WordPress Plugin Simple File List Arbitrary File Download (3.2.7)
WordPress Plugin Caret Country Access Limit Cross-Site Scripting (1.0.1)
WordPress Plugin Contact Form Clean and Simple Cross-Site Scripting (4.7.0)