Debian Security Advisory

DSA-2140-1 libapache2-mod-fcgid -- stack overflow

Date Reported:
05 Jan 2011
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2010-3872.
More information:

A vulnerability has been found in Apache mod_fcgid. The Common Vulnerabilities and Exposures project identifies the following problem:

  • CVE-2010-3872

    A stack overflow could allow an untrusted FCGI application to cause a server crash or possibly to execute arbitrary code as the user running the web server.

For the stable distribution (lenny), this problem has been fixed in version 2.2-1+lenny1.

For the unstable distribution (sid), and the testing distribution (squeeze), this problem has been fixed in version 2.3.6-1.

We recommend that you upgrade your libapache2-mod-fcgid packages.

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: