Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:8696

Опубликовано: 29 июл. 2025
Источник: rocky
Оценка: Important

Описание

Important: perl-FCGI:0.78 security update

The perl-FCGI package provides a Perl module for writing FastCGI applications. FastCGI is a more efficient alternative to traditional CGI, as it keeps application processes persistent across multiple requests. This module allows Perl web applications to handle requests faster and with lower resource overhead, making it suitable for high-traffic environments.

Security Fix(es):

  • perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library (CVE-2025-40907)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
perl-FCGIx86_6412.module+el8.10.0+1990+6591fbc7perl-FCGI-0.78-12.module+el8.10.0+1990+6591fbc7.x86_64.rpm
perl-FCGIx86_6412.module+el8.10.0+1990+7f517b07perl-FCGI-0.78-12.module+el8.10.0+1990+7f517b07.x86_64.rpm
perl-FCGIx86_6412.module+el8.10.0+1990+99c43398perl-FCGI-0.78-12.module+el8.10.0+1990+99c43398.x86_64.rpm
perl-FCGIx86_6412.module+el8.10.0+1990+d30a9ea8perl-FCGI-0.78-12.module+el8.10.0+1990+d30a9ea8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 месяцев назад

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

CVSS3: 7.5
redhat
7 месяцев назад

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

CVSS3: 5.3
nvd
7 месяцев назад

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

CVSS3: 5.3
debian
7 месяцев назад

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable versio ...

rocky
3 месяца назад

Important: perl-FCGI security update