The Apache Software Foundation and the Apache HTTP Server Project are
pleased to announce the release of version 2.3.6 of mod_fcgid, a
FastCGI implementation for Apache HTTP Server versions 2.0, 2.2, and
future 2.4. This version of mod_fcgid is a bug fix release.
A fix is included for CVE-2010-3872, a potential vulnerability which
can affect sites with untrusted FastCGI applications.
Additionally, default configuration settings for request body handling
have been changed to prevent large system resource use. Administrators
of all versions of mod_fcgid are strongly cautioned to ensure that
FcgidMaxRequestLen is configured appropriately.
You can get the source and Windows binaries from
your local mirror
Development of mod_fcgid can be followed through the
Subversion
repositories. For public access you can use:
% svn checkout http://svn.apache.org/repos/asf/httpd/mod_fcgid/trunk mod_fcgid