|
|
Log in / Subscribe / Register

Debian alert DLA-4329-1 (libfcgi)

From:  Thorsten Alteholz <debian@alteholz.de>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4329-1] libfcgi security update
Date:  Mon, 13 Oct 2025 14:45:27 +0000
Message-ID:  <40d74a87-8554-8e52-c587-86a151654@alteholz.de>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4329-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Thorsten Alteholz October 13, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libfcgi Version : 2.4.2-2+deb11u1 CVE ID : CVE-2025-23016 An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. For Debian 11 bullseye, this problem has been fixed in version 2.4.2-2+deb11u1. We recommend that you upgrade your libfcgi packages. For the detailed security status of libfcgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libfcgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmjtEIdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEc+QBAAn/m5cgUFc1N2G+5BoKQgAfwy2owH2LbLaf4rLxSCinKZCHQFF8nBe8M+ n9ZHq1v7SqY5fltAa8rkFM7XN7hUxqSCWfS8Eds1NIF3Z7McnODN1/w2RK2IWZS1 dqwmw7gSuIhStbGUPIx3zVJnvbwYNvkmQCmgO71+V9/KW7+6LXdtg6TD9IP3fowy watiEN+Znd2qB9z3ryIfEmcPcBQ+/c6Wn7NErgNpFJvfZDRLS5NzTKN94WHRbPYK CPofVUCSxtDF7UUTkRvfXT7UzICgpxZrdMQdp9EAW/FLlzaE60NXUcZcYvIVqffe oAb8Ky6twfRhaHK/BNj5o5poLwXiXls2VEAP9SK7cg1ab+QXIxH5GyFUMNn0UE4h c83wO8FSO0tsw3vk8FwplLbmchZizSE42ULLe2BugFyV6OHoOJa4NFmPRmmQ4jlh UTnc/gq6KmAGk1zvB906OPrBHtYKnqkNli13ue8sDe0sVu8fPEwtvLgOoGZbcewB CooPtwe1FIOBMALqCFuICBSrbH3or+GkFBMwOpUw/XQoBpqBjPshTtz6UiRcLrno oL7hW1Z3EiGrn6sTVLDSjg6EUuAQVnmNhXo7MT+henJ+my8PMGN219CdhqnMuFWL AqckYLlaRJhq4WxKWXO2JWDdEqb6x70yjc0CKixm9rjfjhK4i3c= =28Wh -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds