Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9825-56cx-cfg6

Опубликовано: 10 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.3

Описание

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

EPSS

Процентиль: 6%
0.00028
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.3
ubuntu
5 месяцев назад

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

CVSS3: 9.3
nvd
5 месяцев назад

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

CVSS3: 9.3
msrc
около 2 месяцев назад

Описание отсутствует

CVSS3: 9.3
debian
5 месяцев назад

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (an ...

CVSS3: 10
fstec
2 месяца назад

Уязвимость функции ReadParams реализации протокола FastCGI библиотеки fcgi2 (fcgi), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 6%
0.00028
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-190