Apache mod_fcgid Module < 2.3.9 fcgid_header_bucket_read() Function Heap-Based Buffer Overflow

High Nessus Plugin ID 70682


The remote web server is affected by a buffer overflow vulnerability.


According to its self-reported banner, the Apache web server listening on this port includes a version of the mod_fcgid module earlier than 2.3.9. That reportedly has a heap-based buffer overflow vulnerability because of an error in the pointer arithmetic used in the 'fcgid_header_bucket_read()' function.


Update to version 2.3.9 or later.

See Also

http://www.mail-archive.com/[email protected]/msg58077.html


Plugin Details

Severity: High

ID: 70682

File Name: mod_fcgid_2_3_9.nasl

Version: $Revision: 1.3 $

Type: remote

Family: Web Servers

Published: 2013/10/29

Modified: 2014/05/24

Dependencies: 10107

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:apache:mod_fcgid

Required KB Items: Settings/ParanoidReport

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2013/10/08

Vulnerability Publication Date: 2013/09/29

Reference Information

CVE: CVE-2013-4365

BID: 62939

OSVDB: 98300