| MDVSA-2012:001: fcgi |
|
|
|
| Écrit par Administrator |
| Dimanche, 08 Janvier 2012 00:00 |
|
A vulnerability has been found and corrected in fcgi:
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers (CVE-2011-2766). The updated packages have been patched to correct this issue. |



























































