Описание
Security update for FastCGI
This update for FastCGI fixes the following issues:
- CVE-2025-23016: Fixed integer overflow in FastCGI fcgi2 library (bsc#1243325)
Список пакетов
SUSE Enterprise Storage 7.1
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Module for Development Tools 15 SP6
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server 15 SP3-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server 15 SP4-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server 15 SP5-LTSS
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
openSUSE Leap 15.6
FastCGI-2.4.0-150000.4.3.1
FastCGI-devel-2.4.0-150000.4.3.1
libfcgi0-2.4.0-150000.4.3.1
perl-FastCGI-2.4.0-150000.4.3.1
Ссылки
- Link for SUSE-SU-2025:02372-1
- E-Mail link for SUSE-SU-2025:02372-1
- SUSE Security Ratings
- SUSE Bug 1243325
- SUSE CVE CVE-2025-23016 page
Описание
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Затронутые продукты
SUSE Enterprise Storage 7.1:FastCGI-2.4.0-150000.4.3.1
SUSE Enterprise Storage 7.1:FastCGI-devel-2.4.0-150000.4.3.1
SUSE Enterprise Storage 7.1:libfcgi0-2.4.0-150000.4.3.1
SUSE Enterprise Storage 7.1:perl-FastCGI-2.4.0-150000.4.3.1
Ссылки
- CVE-2025-23016
- SUSE Bug 1243325