FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade perl-FCGI | Jul 4, 2025 | May 16, 2025 |
| Amazon Linux Ami 2 | — | Upgrade perl-FCGIUpgrade perl-FCGI-debuginfo | Jun 13, 2025 | May 16, 2025 |
| Debian | — | Upgrade libfcgi-perl | May 20, 2025 | May 16, 2025 |
| Oracle_linux | — | Upgrade perl-FCGI | Jun 10, 2025 | May 16, 2025 |
| Redhat_linux | — | Upgrade perl-FCGI-debugsourceUpgrade perl-FCGI-debuginfoUpgrade perl-FCGI | Jun 10, 2025 | May 16, 2025 |
| Rocky_linux | — | Upgrade perl-FCGI-debugsourceUpgrade perl-FCGIUpgrade perl-FCGI-debuginfo | Jul 31, 2025 | Jul 29, 2025 |
| Ubuntu | — | Upgrade libfcgi-perlUpgrade libfcgi-perl (Ubuntu Pro) | May 26, 2025 | May 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub