On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/a23au/awe-base-images
- https://github.com/jercle/awe-base-images
- https://github.com/stkcat/awe-base-images