CVE-2012-1181 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-1181): fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
According to upstream this is fixed in 2.3.7: https://issues.apache.org/bugzilla/show_bug.cgi?id=49902
(In reply to comment #1) > According to upstream this is fixed in 2.3.7: > https://issues.apache.org/bugzilla/show_bug.cgi?id=49902 I just pushed 2.3.7 to portage FYI.
Great, thanks. Arches, please test and mark stable: =www-apache/mod_fcgid-2.3.7 Target keywords : "amd64 ppc x86"
amd64 stable
x86 stable
ppc done
Thanks, folks. GLSA Vote: yes.
GLSA vote: yes. Added to existing GLSA request.
This issue was resolved and addressed in GLSA 201207-09 at http://security.gentoo.org/glsa/glsa-201207-09.xml by GLSA coordinator Sean Amoss (ackle).