CVE-2012-1181
Estado: ModificadaMedia (5)—
fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.81%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615814
- http://www.debian.org/security/2012/dsa-2436
- http://www.openwall.com/lists/oss-security/2012/03/15/10
- http://www.openwall.com/lists/oss-security/2012/03/16/2
- http://www.securityfocus.com/bid/52565
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74181
- https://issues.apache.org/bugzilla/show_bug.cgi?id=49902
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615814
- http://www.debian.org/security/2012/dsa-2436
- http://www.openwall.com/lists/oss-security/2012/03/15/10
- http://www.openwall.com/lists/oss-security/2012/03/16/2
- http://www.securityfocus.com/bid/52565
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74181
- https://issues.apache.org/bugzilla/show_bug.cgi?id=49902
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-1181",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-03-19T21:55:01.077",
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615814",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2012/dsa-2436",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/03/15/10",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/03/16/2",
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/52565",
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74181",
"source": "secalert@redhat.com"
},
{
"url": "https://issues.apache.org/bugzilla/show_bug.cgi?id=49902",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=615814",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2012/dsa-2436",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/03/15/10",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/03/16/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/52565",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74181",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.apache.org/bugzilla/show_bug.cgi?id=49902",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit."
},
{
"lang": "es",
"value": "fcgid_spawn_ctl.c en el módulo de mod_fcgid v2.3.6 para el Servidor Apache HTTP no reconoce la directiva FcgidMaxProcessesPerClass para un host virtual, lo que hace que sea más fácil para los atacantes remotos causar una denegación de servicio (consumo de memoria) a través de una serie de peticiones HTTP que desencadena un proceso de contar superior al límite previsto."
}
],
"lastModified": "2026-06-16T23:39:12.157",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:http_server:2.3.6:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A727D554-21B0-4FD4-8828-51348E9F7C21"
},
{
"criteria": "cpe:2.3:a:apache:mod_fcgid:2.3.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34A3EE79-BDC3-480F-9BE5-943AAE9E7CBC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}