Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Whois | Whois | 4.5.7 (including) | 4.5.7 (including) |
| Whois | Whois | 4.6.6 (including) | 4.6.6 (including) |