Debian Libfcgi vulnerabilities
2 known vulnerabilities affecting debian/libfcgi.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-23016CRITICALCVSS 9.3fixed in libfcgi 2.4.2-2+deb12u1 (bookworm)2025
CVE-2025-23016 [CRITICAL] CVE-2025-23016: libfcgi - FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultan...
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Scope: local
bookworm: resolved (fixed in 2.4.2-2+deb12u1)
bullseye: resolved (fixed in 2.4.2-2+deb11u1)
forky: resolved (fixed in 2.4.5-0.1)
sid: r
debian
CVE-2012-6687MEDIUMCVSS 5.0fixed in libfcgi 2.4.0-8.3 (bookworm)2012
CVE-2012-6687 [MEDIUM] CVE-2012-6687: libfcgi - FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial o...
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
Scope: local
bookworm: resolved (fixed in 2.4.0-8.3)
bullseye: resolved (fixed in 2.4.0-8.3)
forky: resolved (fixed in 2.4.0-8.3)
sid: resolved (fixed in 2.4.0-8.3)
trixie: resolved (fixed in 2.4.0-8.3)
debian