Logo
vulnerabilityCVE-2025-23016
Name
CVE-2025-23016
Source
NVD ( link)Debian ( link)
Description
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
fcgi
Patched

Vulnerability Ratings#


9.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.4.7
Not Affected
buildroot
master
2.4.7
Not Affected
yocto
master
2.4.7
Not Affected
yocto
scarthgap
2.4.2
Patched

Resolved with patches#


fcgi (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix size_t overflow in Malloc() argument in ReadParams()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2025-23016
2
Update fcgiapp.c
Pycatchown <39068868+Pycatchown@users.noreply.github.com>
CVE-2025-23016

fcgi (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix size_t overflow in Malloc() argument in ReadParams()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2025-23016
2
Update fcgiapp.c
Pycatchown <39068868+Pycatchown@users.noreply.github.com>
CVE-2025-23016