Severity
7.5HIGH
EPSS
6.7%
top 8.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

NVDapache/mod_fcgid< 2.3.9
Debianlibapache2-mod-fcgid< 1:2.3.9-1+3
NVDsuse/cloud1.0, 2.0+1
NVDopensuse/opensuse11.4, 12.2, 12.3+2

Also affects: Debian Linux 6.0, 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pvf8-q83q-x8pr: Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket2022-05-13
CVEList
CVE-2013-4365: Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket2013-10-17
OSV
CVE-2013-4365: Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket2013-10-17

📋Vendor Advisories

2
Red Hat
mod_fcgid: heap overflow2013-09-29
Debian
CVE-2013-4365: libapache2-mod-fcgid - Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_buc...2013

💬Community

3
Bugzilla
CVE-2013-4365 mod_fcgid: heap overflow2013-10-09
Bugzilla
CVE-2013-4365 mod_fcgid: heap overflow [epel-all]2013-10-09
Bugzilla
CVE-2013-4365 mod_fcgid: heap overflow [fedora-all]2013-10-09