LWN.net Logo

mod_tcl: format string vulnerability

Package(s):mod_tcl CVE #(s):CVE-2006-4154
Created:October 24, 2006 Updated:October 25, 2006
Description: Sparfell discovered format string errors in calls to the set_var function in tcl_cmds.c and tcl_core.c. A remote attacker could exploit the vulnerability to execute arbitrary code with the rights of the user running the Apache server.
Alerts:
Gentoo 200610-12 2006-10-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds