CVE-2011-2766
Summary
| CVE | CVE-2011-2766 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-23 10:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 5.0 | All | All | All |
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Fast Cgi Project | Fast Cgi | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| hermes.opensuse.org/messages/13154637 | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | Broken Link |
| Support / Security / Advisories / / MDVSA-2012:001 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-2327-1 libfcgi-perl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| #607479 - libfcgi-perl: [CVE-2011-2766] After reloading some environment vars become constants, that will be used if not overruled by the headers of new requests. - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | Exploit, Issue Tracking, Mailing List, Third Party Advisory |
| Bug #68380 for FCGI: FCGI-0.70 to 0.72 with perl5.12: CGI.pm receives CGI variables from previous requests | af854a3a-2127-422b-91ae-364da2661108 | rt.cpan.org | Exploit, Patch, Third Party Advisory |
| Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Bug 736604 – CVE-2011-2766 perl-FCGI, fcgi: Certain environment variables shared between first and subsequent HTTP requests | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Exploit, Issue Tracking, Third Party Advisory |
| oss-security - Re: CVE Request -- libfcgi-perl / perl-FCGI: Certain environment variables shared between first and subsequent HTTP requests | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| hermes.opensuse.org/messages/13155253 | af854a3a-2127-422b-91ae-364da2661108 | hermes.opensuse.org | Broken Link |
| oss-security - CVE Request -- libfcgi-perl / perl-FCGI: Certain environment variables shared between first and subsequent HTTP requests | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900136 CBL-Mariner Linux Security Update for perl 5.30.3