Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Whois | Whois | 4.5.7 (including) | 4.5.7 (including) |
Whois | Whois | 4.6.6 (including) | 4.6.6 (including) |