OESA-2022-1758
Dashboard / Vulnerabilities / OESA-2022-1758
Summary: mod_fcgid security update
Details: Mod_fcgid is an Apache module providing a FastCGI interface. It's an alternative to mod_fastcgi that is specifically tuned for the dynamic FastCGI configuration used on DreamHost servers. Security Fix(es): A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.(CVE-2016-1000104)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1758, https://nvd.nist.gov/vuln/detail/CVE-2016-1000104
Affected packages
Package
Name: mod_fcgid
Purl: pkg:rpm/openEuler/mod_fcgid&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.3.9-20.oe1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
