CVE-2010-3872 Information

Description

The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances which has unspecified impact and attack vectors related to \untrusted FastCGI applications\ and a \stack buffer overwrite.\

Reference

http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050930.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050932.html http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050976.html http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00004.html http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00005.html http://osvdb.org/69275 http://secunia.com/advisories/42288 http://secunia.com/advisories/42302 http://secunia.com/advisories/42815 http://www.debian.org/security/2010/dsa-2140 http://www.gossamer-threads.com/lists/apache/announce/391406 http://www.securityfocus.com/bid/44900 http://www.vupen.com/english/advisories/2010/2997 http://www.vupen.com/english/advisories/2010/2998 http://www.vupen.com/english/advisories/2011/0031 https://exchange.xforce.ibmcloud.com/vulnerabilities/63303 https://issues.apache.org/bugzilla/show_bug.cgi?id=49406

Share on: