Fix CVE-2025-23016. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bf22da3848 2025-06-08 02:30:29.771940+00:00 -------------------------------------------------------------------------------- Name : fcgi Product : Fedora 41 Version : 2.4.0 Release : 52.fc41 URL : Summary : FastCGI development kit Description : FastCGI is a language independent, scalable, open extension to CGI that provides high performance without the limitations of server specific APIs. -------------------------------------------------------------------------------- Update Information: Fix CVE-2025-23016 -------------------------------------------------------------------------------- ChangeLog: * Fri May 30 2025 Andrew Bauer - 2.4.0-52 - Fix CVE-2025-23016 * Thu Jan 16 2025 Fedora Release Engineering - 2.4.0-51 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369269 - CVE-2025-23016 FastCGI integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2369269 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-bf22da3848' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
PHP could be made to run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4166-2 October 29, 2019 php5 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: PHP could be made to run programs if it received specially crafted network traffic. Software Description: - php5: HTML-embedded scripting language interpreter Details: USN-4166-1 fixed a vulnerability in PHP. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that PHP incorrectly handled certain paths when being used in FastCGI configurations. A remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.29+esm6 php5-cgi 5.5.9+dfsg-1ubuntu4.29+esm6 php5-cli 5.5.9+dfsg-1ubuntu4.29+esm6 php5-fpm 5.5.9+dfsg-1ubuntu4.29+esm6 Ubuntu 12.04 ESM: libapache2-mod-php5 5.3.10-1ubuntu3.40 php5-cgi 5.3.10-1ubuntu3.40 php5-cli 5.3.10-1ubuntu3.40 php5-fpm 5.3.10-1ubuntu3.40 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4166-2 https://ubuntu.com/security/notices/USN-4166-1 CVE-2019-11043 . The Ubuntu Security Notice USN-4166-3 pertains to a vulnerability in php7 that could enable remote code execution through specially designed requests.. PHP Vulnerability, Ubuntu Security Notice, Remote Code Execution, FastCGI Issue. . Severity: Critical. LinuxSecurity.com Team
Fix crash when too many connections are used. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1790 2015-02-07 00:47:26 -------------------------------------------------------------------------------- Name : fcgi Product : Fedora 20 Version : 2.4.0 Release : 26.fc20 URL : Summary : FastCGI development kit Description : FastCGI is a language independent, scalable, open extension to CGI that provides high performance without the limitations of server specific APIs. -------------------------------------------------------------------------------- Update Information: Fix crash when too many connections are used -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 6 2015 Till Maas - 2.4.0-26 - Use %license * Fri Feb 6 2015 Till Maas - 2.4.0-25 - Fix crash when too many connections are used - Make gcc build dependencies obvious for local builds * Sat Aug 16 2014 Fedora Release Engineering - 2.4.0-24 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering - 2.4.0-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Mon Feb 3 2014 Till Maas - 2.4.0-22 - Harden build -------------------------------------------------------------------------------- References: [ 1 ] Bug #1189958 - Stack smashing while using a lot of connections https://bugzilla.redhat.com/show_bug.cgi?id=1189958 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fcgi' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.