PT-2006-4986 · Apache · Apache+1
Sparfell
·
Published
2006-10-16
·
Updated
2017-07-20
·
CVE-2006-4154
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache 2.x with mod tcl module 1.0
Description
The issue allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a
set var function call in files tcl cmds.c and tcl core.c.Recommendations
For Apache 2.x with mod tcl module 1.0, consider disabling the
set var function in tcl cmds.c and tcl core.c until a patch is available. Restrict access to the mod tcl module to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Mod Tcl