CVE-2011-2766
libfcgi-perl - authentication bypass
EPSS 7.2%
Description
The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
How to fix CVE-2011-2766
To remediate CVE-2011-2766, upgrade the affected package to a fixed version below.
- Debian/libfcgi-perl—upgrade to 0.73-2 or later
- Debian/libfcgi-perl—upgrade to 0.71-1+squeeze1 or later
Is CVE-2011-2766 being exploited?
Moderate — EPSS is 7.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.73-2
- from 0, < 0.71-1+squeeze1