Candidate: CVE-2013-4365 PublicDate: 2013-10-17 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4365 http://www.mail-archive.com/dev@httpd.apache.org/msg58077.html Description: Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725942 https://bugs.launchpad.net/bugs/1238242 Priority: medium Discovered-by: Robert Matthews Assigned-to: CVSS: Patches_libapache2-mod-fcgid: upstream_libapache2-mod-fcgid: released (1:2.3.9-1) lucid_libapache2-mod-fcgid: ignored (reached end-of-life) precise_libapache2-mod-fcgid: released (1:2.3.6-1.1ubuntu0.1) quantal_libapache2-mod-fcgid: released (1:2.3.7-0ubuntu2.12.10.1) raring_libapache2-mod-fcgid: released (1:2.3.7-0ubuntu2.13.04.1) saucy_libapache2-mod-fcgid: released (1:2.3.9-1) devel_libapache2-mod-fcgid: released (1:2.3.9-1)