Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://secunia.com/advisories/34457 | third party advisory |
http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23 | vendor advisory |
http://osvdb.org/52915 | vdb entry |
http://www.securityfocus.com/bid/34206 | vdb entry patch |
http://www.debian.org/security/2009/dsa-1752 | vendor advisory |