Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-23016

Published: January 13, 2025Last modified: June 7, 2025

Description

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

Severity score breakdown

ParameterValue
Base score9.3
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Notes

https://github.com/FastCGI-Archives/fcgi2/commit/b0eabcaf4d4f371514891a52115c746815c2ff15

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSfcgiVulnerable (2.4.2-r1)
StreamfcgiFixed (2.4.6-r0)

References

ON THIS PAGE