Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Webcit | Citadel | * | 7.38 (including) |
Webcit | Citadel | 7.02 (including) | 7.02 (including) |
Webcit | Citadel | 7.10 (including) | 7.10 (including) |
Webcit | Citadel | 7.11 (including) | 7.11 (including) |
Webcit | Citadel | 7.12 (including) | 7.12 (including) |
Webcit | Citadel | 7.22 (including) | 7.22 (including) |
Webcit | Citadel | 7.37 (including) | 7.37 (including) |
Webcit | Ubuntu | intrepid | * |
Webcit | Ubuntu | jaunty | * |
Webcit | Ubuntu | upstream | * |