CVE-2012-6687
published 2015-02-19CVE-2012-6687: FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.09%
92.7th percentile
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libfcgi | < libfcgi 2.4.0-8.3 (bookworm) | libfcgi 2.4.0-8.3 (bookworm) |
| debian | libfcgi-perl | < libfcgi 2.4.0-8.3 (bookworm) | libfcgi 2.4.0-8.3 (bookworm) |
| fastcgi | fcgi | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | fcgi-2.4.0-7.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | fcgi-2.4.0-7.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | fcgi-2.4.0-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | fcgi-2.4.0-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | fcgi-2.4.0-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | fcgi-2.4.0-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | fcgi-debuginfo-2.4.0-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | fcgi-debuginfo-2.4.0-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | fcgi-debuginfo-2.4.0-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | fcgi-debuginfo-2.4.0-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | fcgi-devel-2.4.0-7.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | fcgi-devel-2.4.0-7.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | fcgi-devel-2.4.0-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | fcgi-devel-2.4.0-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | fcgi-devel-2.4.0-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | fcgi-devel-2.4.0-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2012-6687: Mariner: Mariner
cve@mitre
vendor_msrc·2024-06-11·CVSS 5.0
CVE-2012-6687 [MEDIUM] CVE-2012-6687: Mariner: Mariner
cve@mitre
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
fcgi: numerous connections cause segfault DoS
vendor_redhat·2012-07-14·CVSS 5.0
CVE-2012-6687 [MEDIUM] fcgi: numerous connections cause segfault DoS
fcgi: numerous connections cause segfault DoS
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
Package: fcgi (Red Hat Ceph Storage 1.2) - Not affected
Package: fcgi (Red Hat Ceph Storage 1.3) - Not affected
Debian
CVE-2012-6687: libfcgi - FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial o...
vendor_debian·2012·CVSS 5.0
CVE-2012-6687 [MEDIUM] CVE-2012-6687: libfcgi - FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial o...
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
Scope: local
bookworm: resolved (fixed in 2.4.0-8.3)
bullseye: resolved (fixed in 2.4.0-8.3)
forky: resolved (fixed in 2.4.0-8.3)
sid: resolved (fixed in 2.4.0-8.3)
trixie: resolved (fixed in 2.4.0-8.3)
GHSA
GHSA-v5rv-9c87-6gww: FastCGI (aka fcgi and libfcgi) 2
ghsa_unreviewed·2022-05-17
CVE-2012-6687 [MEDIUM] CWE-20 GHSA-v5rv-9c87-6gww: FastCGI (aka fcgi and libfcgi) 2
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
OSV
CVE-2012-6687: FastCGI (aka fcgi and libfcgi) 2
osv·2015-02-19·CVSS 5.0
CVE-2012-6687 [MEDIUM] CVE-2012-6687: FastCGI (aka fcgi and libfcgi) 2
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0184.htmlhttp://www.openwall.com/lists/oss-security/2015/02/06/4http://www.openwall.com/lists/oss-security/2015/02/07/4https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681591https://bugs.launchpad.net/ubuntu/+source/libfcgi/+bug/933417https://bugzilla.redhat.com/show_bug.cgi?id=1189958https://exchange.xforce.ibmcloud.com/vulnerabilities/100696http://advisories.mageia.org/MGASA-2015-0184.htmlhttp://www.openwall.com/lists/oss-security/2015/02/06/4http://www.openwall.com/lists/oss-security/2015/02/07/4https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=681591https://bugs.launchpad.net/ubuntu/+source/libfcgi/+bug/933417https://bugzilla.redhat.com/show_bug.cgi?id=1189958https://exchange.xforce.ibmcloud.com/vulnerabilities/100696
2015-02-19
Published