PT-2011-1025 · Perl · Fcgi

Jan Lieskovsky

·

Publicado

2011-09-23

·

Atualizado

2024-06-15

·

CVE-2011-2766

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FCGI module versions 0.70 through 0.73
Description The issue concerns the FCGI module for Perl, which allows remote attackers to bypass authentication via crafted HTTP headers. This is due to the module using environment variable values from one request during the processing of a later request. The exploitation of this issue can lead to a violation of confidentiality, integrity, and availability of protected information. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions 0.70 through 0.73, consider updating to a version outside of this range to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the CGI::Fast module until a patch is available. Avoid using crafted HTTP headers in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02004
CVE-2011-2766
DSA-2327-1
OPENSUSE-SU-2024:10387-1

Produtos afetados

Fcgi