DSA-2140-1 libapache2-mod-fcgid -- stack overflow

Related Vulnerabilities: CVE-2010-3872  

A vulnerability has been found in Apache mod_fcgid. The Common Vulnerabilities and Exposures project identifies the following problem: CVE-2010-3872 A stack overflow could allow an untrusted FCGI application to cause a server crash or possibly to execute arbitrary code as the user running the web server. For the stable distribution (lenny), this problem has been fixed in version 2.2-1+lenny1. For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 2.3.6-1. We recommend that you upgrade your libapache2-mod-fcgid packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Debian Security Advisory

DSA-2140-1 libapache2-mod-fcgid -- stack overflow

Date Reported:
05 Jan 2011
Affected Packages:
libapache2-mod-fcgid
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2010-3872.
More information:

A vulnerability has been found in Apache mod_fcgid. The Common Vulnerabilities and Exposures project identifies the following problem:

  • CVE-2010-3872

    A stack overflow could allow an untrusted FCGI application to cause a server crash or possibly to execute arbitrary code as the user running the web server.

For the stable distribution (lenny), this problem has been fixed in version 2.2-1+lenny1.

For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 2.3.6-1.

We recommend that you upgrade your libapache2-mod-fcgid packages.

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/