Description

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

INFO

Published Date :

2025-01-10T00:00:00.000Z

Last Modified :

2026-02-26T19:09:30.942Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-23016 vulnerability.

Vendors Products
Fastcgi
  • Fcgi

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact