Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://secunia.com/advisories/55197 | third party advisory |
http://lists.opensuse.org/opensuse-updates/2013-10/msg00059.html | mailing list third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-updates/2013-10/msg00055.html | mailing list third party advisory vendor advisory |
http://www.debian.org/security/2013/dsa-2778 | third party advisory vendor advisory |
http://svn.apache.org/viewvc?view=revision&revision=1527362 | patch vendor advisory |
http://www.securityfocus.com/bid/62939 | vdb entry third party advisory |
http://lists.opensuse.org/opensuse-updates/2013-11/msg00024.html | mailing list third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00011.html | mailing list third party advisory vendor advisory |
http://www.mail-archive.com/dev%40httpd.apache.org/msg58077.html | mailing list |