Upstream information

CVE-2006-4154 at MITRE

Description

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Note from the SUSE Security Team

This problem affects mod_tcl, which is not shipped with SUSE Linux Enterprise 10 or 11. So SUSE Linux Enterprise 10 and 11 are not affected by this security problem.

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.