The aprwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using aprwrite() or aprputs(), such as with modluas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'aprputs' function and may pass it a very large (INTMAX or larger) string must be compiled against current headers to resolve the issue.
{ "cpes": [ "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*" ], "severity": "Medium" }