CVE
- Id
- 10372
- CVE No.
- CVE-2004-1946
- Status
- Candidate
- Description
- Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.
- Phase
- Assigned (20050504)
- Votes
- None (candidate not yet proposed)
- Comments