CVE-2011-2766 — Improper Authentication in Libfcgi-perl
Severity
7.5HIGHNVD
EPSS
0.3%
top 50.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 23
Latest updateMay 13
Description
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages2 packages
Also affects: Debian Linux 5.0, 6.0, 7.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2011-2766: libfcgi-perl - The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast,...↗2011
💬Community
3Bugzilla▶
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests [epel-6]↗2011-09-08
Bugzilla▶
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests↗2011-09-08
Bugzilla▶
CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests [fedora-all]↗2011-09-08