Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
BID:49549
Info
Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
| Bugtraq ID: | 49549 |
| Class: | Design Error |
| CVE: |
CVE-2011-2766 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2011 12:00AM |
| Updated: | Apr 13 2015 09:13PM |
| Credit: | Ferdinand and Russ Allbery |
| Vulnerable: |
Sven Verdoolaege FCGI 0.73 Sven Verdoolaege FCGI 0.72 Sven Verdoolaege FCGI 0.71 Sven Verdoolaege FCGI 0.70 Simple Simple:Press Forum 0 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Sven Verdoolaege FCGI 0.74 |
Discussion
Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
Perl Fast CGI module is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security protections and obtain access to restricted resources.
Fast CGI 0.70 to 0.73 are vulnerable.
Perl Fast CGI module is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security protections and obtain access to restricted resources.
Fast CGI 0.70 to 0.73 are vulnerable.
Exploit / POC
Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
MandrakeSoft Enterprise Server 5 x86_64
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.1 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
-
Mandriva perl-FCGI-0.710.0-1.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva fcgi-2.4.0-11.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64fcgi0-2.4.0-11.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64fcgi0-devel-2.4.0-11.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64fcgi0-static-devel-2.4.0-11.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva perl-FCGI-0.730.0-1.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva perl-FCGI-0.730.0-1.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva fcgi-2.4.0-11.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libfcgi0-2.4.0-11.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libfcgi0-devel-2.4.0-11.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libfcgi0-static-devel-2.4.0-11.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva perl-FCGI-0.710.0-1.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Perl Fast CGI Module CGI Variables Authentication Security Bypass Vulnerability
References:
References:
- Bug #68380 for FCGI: FCGI-0.70 to 0.72 with perl5.12: CGI.pm receives CGI variab (Perl)
- Bug 736604 - (CVE-2011-2766) CVE-2011-2766 perl-FCGI, fcgi: Certain environment (Red Hat)
- libfcgi-perl: After reloading some environment vars become constants, that will (Debian)
- Perl FCGI (Sven Verdoolaege)
- Perl Homepage (Perl.org)
- RT 4.0.7 Released (bestpractical)
- Version 0.74 Release Notes (Sven Verdoolaege)