Apache FCGID module resources exhaustion
Description:FcgidMaxProcessesPerClass limit is no actually working..
Affected:APACHE : mod_fcgid 2.3
CVE:CVE-2012-1181 (fcgid_spawn_ctl.c in the mod_fcgid module 2.3.6 for the Apache HTTP Server does not recognize the FcgidMaxProcessesPerClass directive for a virtual host, which makes it easier for remote attackers to cause a denial of service (memory consumption) via a series of HTTP requests that triggers a process count higher than the intended limit.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 2436-1] libapache2-mod-fcgid security update (20.03.2012)

