CVE-2010-3872
Httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
Fedora · Fedoran/a · mod_fcgidRed Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050930.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050932.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050976.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00005.htmlhttp://osvdb.org/69275https://access.redhat.com/security/cve/CVE-2010-3872https://bugzilla.redhat.com/show_bug.cgi?id=2248172http://secunia.com/advisories/42288http://secunia.com/advisories/42302http://secunia.com/advisories/42815https://exchange.xforce.ibmcloud.com/vulnerabilities/63303