7.5
CVSSv2

CVE-2011-4357

Published: 10/12/2011 Updated: 29/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the p_cgi_error function in python/neo_cgi.c in the Python CGI Kit (neo_cgi) module for Clearsilver 0.10.5 and previous versions allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are not properly handled when creating CGI error messages using the cgi_error API function.

Vulnerable Product Search on Vulmon Subscribe to Product

brandon long clearsilver 0.9.14

brandon long clearsilver 0.9.7

brandon long clearsilver 0.7.2

brandon long clearsilver 0.7.1

brandon long clearsilver 0.2

brandon long clearsilver 0.1

brandon long clearsilver 0.10.4

brandon long clearsilver 0.10.3

brandon long clearsilver 0.9.2

brandon long clearsilver 0.9.1

brandon long clearsilver 0.5

brandon long clearsilver 0.4

brandon long clearsilver 0.10.2

brandon long clearsilver 0.10.1

brandon long clearsilver 0.9.0

brandon long clearsilver 0.8.1

brandon long clearsilver 0.8.0

brandon long clearsilver 0.3

brandon long clearsilver 0.2.1

brandon long clearsilver

brandon long clearsilver 0.9.6

brandon long clearsilver 0.9.3

brandon long clearsilver 0.7

brandon long clearsilver 0.6

Vendor Advisories

Debian Bug report logs - #649322 clearsilver: FTBFS with -Werror=format-security Package: clearsilver; Maintainer for clearsilver is Debian QA Group <packages@qadebianorg>; Reported by: Leo Iannacone <l3on@ubuntucom> Date: Sat, 19 Nov 2011 22:21:06 UTC Severity: grave Tags: patch, security Fixed in version clears ...