CVE-2025-23016
published 2025-01-10CVE-2025-23016: FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to…
PriorityP347critical9.3CVSS 3.1
AVLACLPRNUINSCCHIHAH
EPSS
0.57%
43.8th percentile
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libfcgi | < libfcgi 2.4.2-2+deb12u1 (bookworm) | libfcgi 2.4.2-2+deb12u1 (bookworm) |
| debian | libfcgi-perl | < libfcgi-perl 0.79+ds-2 (bookworm) | libfcgi-perl 0.79+ds-2 (bookworm) |
| ether | fcgi | 0.44 – 0.82 | — |
| fastcgi | fcgi | 0.44 – 0.82 | — |
CVSS provenance
nvdv3.19.3CRITICALCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_oracle8.2CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (FastCGI fcgi2) — CVE-2025-23016
vendor_oracle·2025-07-15·CVSS 8.2
CVE-2025-23016 [CRITICAL] Oracle Oracle Communications Risk Matrix: Third Party (FastCGI fcgi2) — CVE-2025-23016
Oracle Oracle Communications Risk Matrix: Third Party (FastCGI fcgi2) vulnerability
CVE: CVE-2025-23016
CVSS: 8.2
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Red Hat
perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
vendor_redhat·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CWE-1395 perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
A flaw was found in the FCGI library. In affected versions, specially crafted nameLen or valueLen values in data sent to the IPC socket may result in a heap-based buffer overflow, which can cause an application crash or other undefined behavior. This occurs in ReadParams in fcgiapp.c.
Statement: This vulnerability is Impor
Ubuntu
FastCGI vulnerability
vendor_ubuntu·2025-05-06
CVE-2025-23016 FastCGI vulnerability
Title: FastCGI vulnerability
Summary: FastCGI could be made to crash or execute arbitrary code.
It was discovered that FastCGI incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-23016: libfcgi - FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultan...
vendor_debian·2025·CVSS 9.3
CVE-2025-23016 [CRITICAL] CVE-2025-23016: libfcgi - FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultan...
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Scope: local
bookworm: resolved (fixed in 2.4.2-2+deb12u1)
bullseye: resolved (fixed in 2.4.2-2+deb11u1)
forky: resolved (fixed in 2.4.5-0.1)
sid: resolved (fixed in 2.4.5-0.1)
trixie: resolved (fixed in 2.4.5-0.1)
Debian
CVE-2025-40907: libfcgi-perl - FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the F...
vendor_debian·2025·CVSS 9.3
CVE-2025-40907 [CRITICAL] CVE-2025-40907: libfcgi-perl - FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the F...
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Scope: local
bookworm: resolved (fixed in 0.79+ds-2)
bullseye: resolved (fixed in 0.79+ds-2)
forky: resolved (fixed in 0.79+ds-2)
sid: resolved (fixed in 0.79+ds-2)
trixie: resolved (fixed in 0.79+ds-2)
OSV
CVE-2025-40907: FCGI versions 0
osv·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CVE-2025-40907: FCGI versions 0
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
GHSA
GHSA-488m-4fx8-f36v: FCGI versions 0
ghsa_unreviewed·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CWE-122 GHSA-488m-4fx8-f36v: FCGI versions 0
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
GHSA
GHSA-9825-56cx-cfg6: FastCGI fcgi2 (aka fcgi) 2
ghsa_unreviewed·2025-01-10
CVE-2025-23016 [CRITICAL] CWE-190 GHSA-9825-56cx-cfg6: FastCGI fcgi2 (aka fcgi) 2
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
OSV
CVE-2025-23016: FastCGI fcgi2 (aka fcgi) 2
osv·2025-01-10·CVSS 9.3
CVE-2025-23016 [CRITICAL] CVE-2025-23016: FastCGI fcgi2 (aka fcgi) 2
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVEs, su
Qualys
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
blogs_qualys·2025-07-16
Oracle Critical Patch Update, July 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 309 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 84, constituting about 27% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 40 and 36 security patches.
228 of the 309 security patches provided by the July Critical Patch Update (about 74%) are for non-Oracle CVE
https://github.com/FastCGI-Archives/fcgi2/issues/67https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-libraryhttp://www.openwall.com/lists/oss-security/2025/04/23/4https://lists.debian.org/debian-lts-announce/2025/10/msg00009.htmlhttps://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library
2025-01-10
Published