// For flags

CVE-2010-3872

Httpd: mod_fcgid: stack-based buffer overflow in fcgid_header_bucket_read() in modules/fcgid/fcgid_bucket.c

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() function, resulting in an application crash.

La función apr_status_t fcgid_header_bucket_read en fcgid_bucket.c en Apache mod_fcgid anterior a v2.3.6 no utiliza punteros aritméticos bytewise en ciertas ciscunstancias, lo que provoca un impacto desconocido y vectores de ataque relacionados con "untrusted FastCGI applications" y un "stack buffer overwrite".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-10-08 CVE Reserved
  • 2010-11-20 CVE Published
  • 2023-11-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Mod Fcgid
Search vendor "Apache" for product "Mod Fcgid"
<= 2.3.5
Search vendor "Apache" for product "Mod Fcgid" and version " <= 2.3.5"
-
Affected
Apache
Search vendor "Apache"
Mod Fcgid
Search vendor "Apache" for product "Mod Fcgid"
2.3.1
Search vendor "Apache" for product "Mod Fcgid" and version "2.3.1"
-
Affected
Apache
Search vendor "Apache"
Mod Fcgid
Search vendor "Apache" for product "Mod Fcgid"
2.3.2
Search vendor "Apache" for product "Mod Fcgid" and version "2.3.2"
-
Affected
Apache
Search vendor "Apache"
Mod Fcgid
Search vendor "Apache" for product "Mod Fcgid"
2.3.3
Search vendor "Apache" for product "Mod Fcgid" and version "2.3.3"
-
Affected
Apache
Search vendor "Apache"
Mod Fcgid
Search vendor "Apache" for product "Mod Fcgid"
2.3.4
Search vendor "Apache" for product "Mod Fcgid" and version "2.3.4"
-
Affected