libapache2-mod-fcgid: code execution
Package(s): | libapache2-mod-fcgid |
CVE #(s): | CVE-2013-4365
|
Created: | October 14, 2013 |
Updated: | February 10, 2014 |
Description: |
From the Debian advisory:
Robert Matthews discovered that the Apache FCGID module, a FastCGI
implementation for Apache HTTP Server, fails to perform adequate
boundary checks on user-supplied input. This may allow a remote attacker
to cause a heap-based buffer overflow, resulting in a denial of service
or potentially allowing the execution of arbitrary code. |
Alerts: |
|