[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-4365Date: (C)2013-10-19   (M)2023-12-22


Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-55197
BID-62939
DSA-2778
SUSE-SU-2013:1667
http://www.mail-archive.com/dev%40httpd.apache.org/msg58077.html
http://svn.apache.org/viewvc?view=revision&revision=1527362
openSUSE-SU-2013:1609
openSUSE-SU-2013:1613
openSUSE-SU-2013:1664

CPE    7
cpe:/o:opensuse:opensuse:12.2
cpe:/o:opensuse:opensuse:12.3
cpe:/o:opensuse:opensuse:11.4
cpe:/o:debian:debian_linux:6.0
...
CWE    1
CWE-787
OVAL    5
oval:org.secpod.oval:def:601126
oval:org.secpod.oval:def:1600250
oval:org.secpod.oval:def:1600277
oval:org.secpod.oval:def:105998
...

© SecPod Technologies