The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing of a later request, which allows remote attackers to bypass authentication via crafted HTTP headers.
| Software | From | Fixed in |
|---|---|---|
| fast_cgi_project / fast_cgi | 0.70 | 0.73.x |
| debian / debian_linux | 5.0 | 5.0.x |
| debian / debian_linux | 7.0 | 7.0.x |
| debian / debian_linux | 6.0 | 6.0.x |