Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: 2025-0144 critical: fcgi buffer overflow issue

mageia
Calendar Grey May 5, 2025
Dist Mageia Esm H88
FastCGI fcgi2 releases from 2.x to 2.4.4 exhibit severe heap overflow vulnerabilities. It is advisable to upgrade promptly to lower security risks in Mageia 9.
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket

Summary

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c. (CVE-2025-23016)

References

- https://bugs.mageia.org/show_bug.cgi?id=34222

- https://www.openwall.com/lists/oss-security/2025/04/23/4

- https://www.cve.org/CVERecord?id=CVE-2025-23016

Resolution

SRPMS

- 9/core/fcgi-2.4.0-22.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0144.html
Type: security
CVE: CVE-2025-23016

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here