In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
| Software | From | Fixed in |
|---|---|---|
| openbsd / openbsd | - | 7.3 |
| openbsd / openbsd | 7.3 | 7.3.x |
| openbsd / openbsd | 7.3-errata_001 | 7.3-errata_001.x |
| openbsd / openbsd | 7.3-errata_002 | 7.3-errata_002.x |
| openbsd / openbsd | 7.3-errata_003 | 7.3-errata_003.x |
| openbsd / openbsd | 7.3-errata_004 | 7.3-errata_004.x |
| openbsd / openbsd | 7.3-errata_005 | 7.3-errata_005.x |
| openbsd / openbsd | 7.3-errata_006 | 7.3-errata_006.x |
| openbsd / openbsd | 7.3-errata_007 | 7.3-errata_007.x |
| openbsd / openbsd | 7.3-errata_008 | 7.3-errata_008.x |
| openbsd / openbsd | 7.3-errata_009 | 7.3-errata_009.x |
| openbsd / openbsd | 7.3-errata_010 | 7.3-errata_010.x |
| openbsd / openbsd | 7.3-errata_011 | 7.3-errata_011.x |
| openbsd / openbsd | 7.3-errata_012 | 7.3-errata_012.x |
| openbsd / openbsd | 7.3-errata_013 | 7.3-errata_013.x |
| openbsd / openbsd | 7.3-errata_014 | 7.3-errata_014.x |
| openbsd / openbsd | 7.3-errata_015 | 7.3-errata_015.x |
| openbsd / openbsd | 7.3-errata_016 | 7.3-errata_016.x |
| openbsd / openbsd | 7.3-errata_017 | 7.3-errata_017.x |
| openbsd / openbsd | 7.3-errata_018 | 7.3-errata_018.x |
| openbsd / openbsd | 7.3-errata_019 | 7.3-errata_019.x |
| openbsd / openbsd | 7.4 | 7.4.x |
| openbsd / openbsd | 7.4-errata_001 | 7.4-errata_001.x |
| openbsd / openbsd | 7.4-errata_002 | 7.4-errata_002.x |
| openbsd / openbsd | 7.4-errata_003 | 7.4-errata_003.x |
| openbsd / openbsd | 7.4-errata_004 | 7.4-errata_004.x |
| openbsd / openbsd | 7.4-errata_005 | 7.4-errata_005.x |