Httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.5epss 2.8%
probabilidade de exploração
2.8%top 15% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
Fedora · Fedoran/a · mod_fcgidRed Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Referências
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050930.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050932.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050976.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00005.htmlhttp://osvdb.org/69275https://access.redhat.com/security/cve/CVE-2010-3872https://bugzilla.redhat.com/show_bug.cgi?id=2248172http://secunia.com/advisories/42288http://secunia.com/advisories/42302http://secunia.com/advisories/42815https://exchange.xforce.ibmcloud.com/vulnerabilities/63303