FastCGI is a language independent, scalable, open extension to CGI that provides high performance without the limitations of server specific APIs.
Security Fix(es):
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.(CVE-2025-23016)
{
"severity": "Critical"
}{
"x86_64": [
"fcgi-2.4.2-3.oe2403sp2.x86_64.rpm",
"fcgi-debuginfo-2.4.2-3.oe2403sp2.x86_64.rpm",
"fcgi-debugsource-2.4.2-3.oe2403sp2.x86_64.rpm",
"fcgi-devel-2.4.2-3.oe2403sp2.x86_64.rpm"
],
"aarch64": [
"fcgi-2.4.2-3.oe2403sp2.aarch64.rpm",
"fcgi-debuginfo-2.4.2-3.oe2403sp2.aarch64.rpm",
"fcgi-debugsource-2.4.2-3.oe2403sp2.aarch64.rpm",
"fcgi-devel-2.4.2-3.oe2403sp2.aarch64.rpm"
],
"src": [
"fcgi-2.4.2-3.oe2403sp2.src.rpm"
]
}