|
|
Log in / Subscribe / Register

fcgi: denial of service

Package(s):fcgi CVE #(s):CVE-2012-6687
Created:April 30, 2015 Updated:March 3, 2016
Description: From the Red Hat bugzilla:

A stack-smashing bug for fcgi was reported to Ubuntu and subsequently patched in both Ubuntu and Debian.

According to the bug report, if more than 1024 connections are received, a segfault can occur.

A patch is provided with the bug reports:

https://bugs.launchpad.net/ubuntu/+source/libfcgi/+bug/933417

and the report at debian:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681591

Alerts:
Mageia MGASA-2016-0089 perl-FCGI 2016-03-02
Debian-LTS DLA-431-1 libfcgi-perl 2016-02-25
Debian-LTS DLA-430-1 libfcgi 2016-02-25
Mandriva MDVSA-2015:226 fcgi 2015-05-04
Mageia MGASA-2015-0184 fcgi 2015-05-03
Fedora FEDORA-2015-1790 fcgi 2015-04-30
Fedora FEDORA-2015-1803 fcgi 2015-04-30

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds