CVE-2025-40907

EUVD-2025-15438
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.

The included FastCGI library is affected by  CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.63%
Affected Products (NVD)
VendorProductVersion
fastcgifcgi
0.44 ≤
𝑥
≤ 0.82
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libfcgi-perl
bookworm
0.82+ds-2
fixed
forky
0.82+ds-3
fixed
sid
0.82+ds-3
fixed
trixie
0.82+ds-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libfcgi-perl
bionic
Fixed 0.78-2ubuntu0.1~esm1
released
focal
Fixed 0.79-1ubuntu0.1
released
jammy
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
xenial
Fixed 0.77-1ubuntu0.1~esm1
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
perl-FCGI
RHEL 9
1:0.79-8.1.el9_6
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-FCGI
Amazon Linux 2
1:0.74-8.amzn2.0.3
fixed
perl-FCGI-debuginfo
Amazon Linux 2
1:0.74-8.amzn2.0.3
fixed