Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cherokee HTTPD Auth_Pam Authentication Remote Format String Vulnerability

It is reported that Cherokee is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.

A remote attacker may exploit this vulnerability to execute arbitrary code in the context of the affected service.







 

Privacy Statement
Copyright 2009, SecurityFocus