PT-2013-4975 · Apache+1 · Mod Fcgid+1
Published
2013-10-17
·
Updated
2024-06-15
·
CVE-2013-4365
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mod fcgid module versions prior to 2.3.9 for the Apache HTTP Server
Description
A heap-based buffer overflow issue exists in the fcgid header bucket read function in fcgid bucket.c, allowing remote attackers to have an unspecified impact via unknown vectors.
Recommendations
For mod fcgid module versions prior to 2.3.9, update to version 2.3.9 or later to resolve the issue.
As a temporary workaround, consider restricting access to the mod fcgid module until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Mod Fcgid