MGASA-2015-0184
Dashboard / Vulnerabilities / MGASA-2015-0184
Summary: Updated fcgi packages fix CVE-2012-6687
Details: Updated fcgi packages fix security vulnerability: FCGI does not perform range checks for file descriptors before use of the FD_SET macro. This FD_SET macro could allow for more than 1024 total file descriptors to be monitored in the closing state. This may allow remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening many socket connections to the host and crashing the service (CVE-2012-6687).
References: https://advisories.mageia.org/MGASA-2015-0184.html, https://bugs.mageia.org/show_bug.cgi?id=15808, https://lists.fedoraproject.org/pipermail/package-announce/2015-April/156731.html
Affected packages
Package
Name: fcgi
Purl: pkg:rpm/mageia/fcgi?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
