Bug 2366847 (CVE-2025-40907) - CVE-2025-40907 perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
Summary: CVE-2025-40907 perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include ...
Keywords:
Status: NEW
Alias: CVE-2025-40907
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2366914
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-16 14:01 UTC by OSIDB Bzimport
Modified: 2025-05-20 06:00 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-05-16 14:01:16 UTC
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.

The included FastCGI library is affected by  CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

Comment 2 Petr Pisar 2025-05-19 11:00:11 UTC
FCGI upstream bug report <https://github.com/perl-catalyst/FCGI/issues/14>.


Note You need to log in before you can comment on or make changes to this bug.