[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4329-1] libfcgi security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4329-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
October 13, 2025                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libfcgi
Version        : 2.4.2-2+deb11u1
CVE ID         : CVE-2025-23016


An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket.


For Debian 11 bullseye, this problem has been fixed in version
2.4.2-2+deb11u1.

We recommend that you upgrade your libfcgi packages.

For the detailed security status of libfcgi please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libfcgi

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmjtEIdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEc+QBAAn/m5cgUFc1N2G+5BoKQgAfwy2owH2LbLaf4rLxSCinKZCHQFF8nBe8M+
n9ZHq1v7SqY5fltAa8rkFM7XN7hUxqSCWfS8Eds1NIF3Z7McnODN1/w2RK2IWZS1
dqwmw7gSuIhStbGUPIx3zVJnvbwYNvkmQCmgO71+V9/KW7+6LXdtg6TD9IP3fowy
watiEN+Znd2qB9z3ryIfEmcPcBQ+/c6Wn7NErgNpFJvfZDRLS5NzTKN94WHRbPYK
CPofVUCSxtDF7UUTkRvfXT7UzICgpxZrdMQdp9EAW/FLlzaE60NXUcZcYvIVqffe
oAb8Ky6twfRhaHK/BNj5o5poLwXiXls2VEAP9SK7cg1ab+QXIxH5GyFUMNn0UE4h
c83wO8FSO0tsw3vk8FwplLbmchZizSE42ULLe2BugFyV6OHoOJa4NFmPRmmQ4jlh
UTnc/gq6KmAGk1zvB906OPrBHtYKnqkNli13ue8sDe0sVu8fPEwtvLgOoGZbcewB
CooPtwe1FIOBMALqCFuICBSrbH3or+GkFBMwOpUw/XQoBpqBjPshTtz6UiRcLrno
oL7hW1Z3EiGrn6sTVLDSjg6EUuAQVnmNhXo7MT+henJ+my8PMGN219CdhqnMuFWL
AqckYLlaRJhq4WxKWXO2JWDdEqb6x70yjc0CKixm9rjfjhK4i3c=
=28Wh
-----END PGP SIGNATURE-----


Reply to: