ELA-1435-1 libfcgi-perl security update

buffer overflow

2025-05-26
Packagelibfcgi-perl
Version0.77-1+deb8u2 (jessie), 0.78-2+deb9u1 (stretch), 0.78-2+deb10u1 (buster)
Related CVEs CVE-2025-40907


libfcgi-perl is a helper module for FastCGI, a binary protocol for interfacing interactive programs with a web server. It was found the included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket which may lead to a denial of service or other unspecified impact.



For Debian 10 buster, these problems have been fixed in version 0.78-2+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 0.77-1+deb8u2.

For Debian 9 stretch, these problems have been fixed in version 0.78-2+deb9u1.

We recommend that you upgrade your libfcgi-perl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.