PT-2013-4975 · Apache+1 · Mod Fcgid+1
Publicado
2013-10-17
·
Atualizado
2024-06-15
·
CVE-2013-4365
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mod fcgid module versions prior to 2.3.9 for the Apache HTTP Server
Description
A heap-based buffer overflow issue exists in the fcgid header bucket read function in fcgid bucket.c, allowing remote attackers to have an unspecified impact via unknown vectors.
Recommendations
For mod fcgid module versions prior to 2.3.9, update to version 2.3.9 or later to resolve the issue.
As a temporary workaround, consider restricting access to the mod fcgid module until a patch is available.
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Mod Fcgid