MGASA-2016-0089
Dashboard / Vulnerabilities / MGASA-2016-0089
Summary: Updated perl-FCGI packages fix CVE-2012-6687
Details: Updated fcgi packages fix security vulnerability: FCGI does not perform range checks for file descriptors before use of the FD_SET macro. This FD_SET macro could allow for more than 1024 total file descriptors to be monitored in the closing state. This may allow remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening many socket connections to the host and crashing the service (CVE-2012-6687).
References: https://advisories.mageia.org/MGASA-2016-0089.html, https://bugs.mageia.org/show_bug.cgi?id=17823, http://lwn.net/Alerts/677312/
Affected packages
Package
Name: perl-FCGI
Purl: pkg:rpm/mageia/perl-FCGI?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
