CVE Vulnerabilities

CVE-2009-0364

Use of Externally-Controlled Format String

Published: Mar 26, 2009 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

Name Vendor Start Version End Version
Webcit Citadel * 7.38 (including)
Webcit Citadel 7.02 (including) 7.02 (including)
Webcit Citadel 7.10 (including) 7.10 (including)
Webcit Citadel 7.11 (including) 7.11 (including)
Webcit Citadel 7.12 (including) 7.12 (including)
Webcit Citadel 7.22 (including) 7.22 (including)
Webcit Citadel 7.37 (including) 7.37 (including)
Webcit Ubuntu intrepid *
Webcit Ubuntu jaunty *
Webcit Ubuntu upstream *

Potential Mitigations

References