ALAS-2013-239


Amazon Linux AMI Security Advisory: ALAS-2013-239
Advisory Release Date: 2014-09-16 21:49 Pacific
Severity: Important
References: CVE-2013-4365 

Issue Overview:

Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.


Affected Packages:

mod24_fcgid


Issue Correction:
Run yum update mod24_fcgid to update your system.

New Packages:
i686:
    mod24_fcgid-debuginfo-2.3.9-1.7.amzn1.i686
    mod24_fcgid-2.3.9-1.7.amzn1.i686

src:
    mod24_fcgid-2.3.9-1.7.amzn1.src

x86_64:
    mod24_fcgid-2.3.9-1.7.amzn1.x86_64
    mod24_fcgid-debuginfo-2.3.9-1.7.amzn1.x86_64