Описание
Security update for FastCGI
This update for FastCGI fixes the following issues:
- CVE-2025-23016: Fixed integer overflow in FastCGI fcgi2 library (bsc#1243325)
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
FastCGI-devel-2.4.0-169.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
FastCGI-devel-2.4.0-169.3.1
Ссылки
- Link for SUSE-SU-2025:02369-1
- E-Mail link for SUSE-SU-2025:02369-1
- SUSE Security Ratings
- SUSE Bug 1243325
- SUSE CVE CVE-2025-23016 page
Описание
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:FastCGI-devel-2.4.0-169.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:FastCGI-devel-2.4.0-169.3.1
Ссылки
- CVE-2025-23016
- SUSE Bug 1243325