CVE-2011-2766Improper Authentication in Libfcgi-perl

Severity
7.5HIGHNVD
EPSS
0.3%
top 50.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 13

Description

The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

debiandebian/libfcgi-perl< libfcgi-perl 0.73-2 (bookworm)
NVDfast_cgi_project/fast_cgi0.700.73

Also affects: Debian Linux 5.0, 6.0, 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-57h3-ccpr-f6f8: The FCGI (aka Fast CGI) module 02022-05-13
OSV
CVE-2011-2766: The FCGI (aka Fast CGI) module 02011-09-23

📋Vendor Advisories

1
Debian
CVE-2011-2766: libfcgi-perl - The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast,...2011

💬Community

3
Bugzilla
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests [epel-6]2011-09-08
Bugzilla
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests2011-09-08
Bugzilla
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests [fedora-all]2011-09-08
CVE-2011-2766 — Improper Authentication in Libfcgi-perl | cvebase