CVE-2012-6687Improper Input Validation in Libfcgi

Severity
5.0MEDIUMNVD
EPSS
25.5%
top 3.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateJun 11

Description

FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages23 packages

🔴Vulnerability Details

2
GHSA
GHSA-v5rv-9c87-6gww: FastCGI (aka fcgi and libfcgi) 22022-05-17
OSV
CVE-2012-6687: FastCGI (aka fcgi and libfcgi) 22015-02-19

📋Vendor Advisories

3
Microsoft
CVE-2012-6687: Mariner: Mariner cve@mitre2024-06-11
Red Hat
fcgi: numerous connections cause segfault DoS2012-07-14
Debian
CVE-2012-6687: libfcgi - FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial o...2012

💬Community

1
Bugzilla
CVE-2012-6687 fcgi: numerous connections cause segfault DoS2015-02-06
CVE-2012-6687 — Improper Input Validation in Libfcgi | cvebase