Debian: 2778-1: libapache2-mod-fcgid: heap-based buffer overflow

Posted by Ridcully on Oct 15, 2013 5:41 AM
By LinuxSecurity.com
Mail this story
Web version

Robert Matthews discovered that the Apache FCGID module, a FastCGI implementation for Apache HTTP Server, fails to perform adequate boundary checks on user-supplied input. This may allow a remote attacker to cause a heap-based buffer overflow, resulting in a denial of service or potentially allowing the execution of arbitrary code.

Full Story

Printed at http://lxer.com/module/newswire/view/192706/index.html