Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4329-1
libfcgi-perl could be made to crash or execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-7527-1 May 22, 2025 libfcgi-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: libfcgi-perl could be made to crash or execute arbitrary code. Software Description: - libfcgi-perl: Fast CGI module for perl Details: It was discovered that libfcgi-perl incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libfcgi-perl 0.79-1ubuntu0.1 Ubuntu 18.04 LTS libfcgi-perl 0.78-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libfcgi-perl 0.77-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7527-1 CVE-2025-40907 Package Information: https://launchpad.net/ubuntu/+source/libfcgi-perl/0.79-1ubuntu0.1 . Ubuntu Security Notice USN-7528-1 pertains to a vulnerability in libcurl that could result in system instability or unauthorized code execution.. Libfcgi-perl, Ubuntu Security Notice, Execute Arbitrary Code, Crash Issue. . Severity: Critical. LinuxSecurity.com Team
FastCGI could be made to crash or execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-7486-1 May 06, 2025 libfcgi vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: FastCGI could be made to crash or execute arbitrary code. Software Description: - libfcgi: FastCGI bridge from CGI Details: It was discovered that FastCGI incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libfcgi0t64 2.4.2-2.1ubuntu0.25.04.1 Ubuntu 24.10 libfcgi0t64 2.4.2-2.1ubuntu0.24.10.1 Ubuntu 24.04 LTS libfcgi0t64 2.4.2-2.1ubuntu0.24.04.1 Ubuntu 22.04 LTS libfcgi0ldbl 2.4.2-2ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7486-1 CVE-2025-23016 Package Information: https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.25.04.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2.1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/libfcgi/2.4.2-2ubuntu0.1 . A vulnerability in FastCGI on Ubuntu poses risks of potential system crashes or the execution of arbitrary code. It's crucial to update the libfcgi package to mitigate this security issue.. libfcgi update, Ubuntu security, FastCGI CVE, system update, arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.