CVE-2010-3872
published 2010-11-22CVE-2010-3872: A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.77%
84.7th percentile
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mod_fcgid | <= 2.3.5 | — |
| apache | mod_fcgid | — | — |
| apache | mod_fcgid | — | — |
| apache | mod_fcgid | — | — |
| apache | mod_fcgid | — | — |
| debian | libapache2-mod-fcgid | < libapache2-mod-fcgid 1:2.3.6-1 (bookworm) | libapache2-mod-fcgid 1:2.3.6-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ff73-846q-p888: The fcgid_header_bucket_read function in fcgid_bucket
ghsa_unreviewed·2022-05-17
CVE-2010-3872 [HIGH] CWE-121 GHSA-ff73-846q-p888: The fcgid_header_bucket_read function in fcgid_bucket
The fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.6 for the Apache HTTP Server does not use bytewise pointer arithmetic in certain circumstances, which has unspecified impact and attack vectors related to "untrusted FastCGI applications" and a "stack buffer overwrite."
OSV
CVE-2010-3872: A flaw was found in the mod_fcgid module of httpd
osv·2010-11-22·CVSS 7.5
CVE-2010-3872 [HIGH] CVE-2010-3872: A flaw was found in the mod_fcgid module of httpd
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
Red Hat
httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c
vendor_redhat·2010-06-08·CVSS 7.5
CVE-2010-3872 [HIGH] CWE-121 httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c
httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
Statement: The mod_fcgid module of httpd as shipped with Red Hat Enterprise Linux 7, 8, and 9 is not affected by this vulnerability because it has a newer, fixed mod_fcgid version.
Package: mod_fcgid
Debian
CVE-2010-3872: libapache2-mod-fcgid - A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response ...
vendor_debian·2010·CVSS 7.5
CVE-2010-3872 [HIGH] CVE-2010-3872: libapache2-mod-fcgid - A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response ...
A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.
Scope: local
bookworm: resolved (fixed in 1:2.3.6-1)
bullseye: resolved (fixed in 1:2.3.6-1)
forky: resolved (fixed in 1:2.3.6-1)
sid: resolved (fixed in 1:2.3.6-1)
trixie: resolved (fixed in 1:2.3.6-1)
No detection rules found.
No writeups or analysis indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050930.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050932.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050976.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00005.htmlhttp://osvdb.org/69275http://secunia.com/advisories/42288http://secunia.com/advisories/42302http://secunia.com/advisories/42815http://www.debian.org/security/2010/dsa-2140http://www.gossamer-threads.com/lists/apache/announce/391406http://www.securityfocus.com/bid/44900http://www.vupen.com/english/advisories/2010/2997http://www.vupen.com/english/advisories/2010/2998http://www.vupen.com/english/advisories/2011/0031https://access.redhat.com/security/cve/CVE-2010-3872https://bugzilla.redhat.com/show_bug.cgi?id=2248172https://exchange.xforce.ibmcloud.com/vulnerabilities/63303https://github.com/apache/httpd-mod_fcgid/commit/b1afa70840b4ab4e6fbc12ac8798b2f3ccc336b2https://issues.apache.org/bugzilla/show_bug.cgi?id=49406http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050930.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050932.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050976.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00005.htmlhttp://osvdb.org/69275http://secunia.com/advisories/42288http://secunia.com/advisories/42302http://secunia.com/advisories/42815http://www.debian.org/security/2010/dsa-2140http://www.gossamer-threads.com/lists/apache/announce/391406http://www.securityfocus.com/bid/44900http://www.vupen.com/english/advisories/2010/2997http://www.vupen.com/english/advisories/2010/2998http://www.vupen.com/english/advisories/2011/0031https://access.redhat.com/security/cve/CVE-2010-3872https://bugzilla.redhat.com/show_bug.cgi?id=2248172https://exchange.xforce.ibmcloud.com/vulnerabilities/63303https://github.com/apache/httpd-mod_fcgid/commit/b1afa70840b4ab4e6fbc12ac8798b2f3ccc336b2https://issues.apache.org/bugzilla/show_bug.cgi?id=49406
2010-11-22
Published