Back
CVE-2004-1097
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
Published: Jan 10, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| cherokee | cherokee_httpd | 0.1 |
| cherokee | cherokee_httpd | 0.1.5 |
| cherokee | cherokee_httpd | 0.1.6 |
| cherokee | cherokee_httpd | 0.2 |
| cherokee | cherokee_httpd | 0.2.5 |
| cherokee | cherokee_httpd | 0.2.6 |
| cherokee | cherokee_httpd | 0.2.7 |
| cherokee | cherokee_httpd | 0.4.6 |
| cherokee | cherokee_httpd | 0.4.7 |
| cherokee | cherokee_httpd | 0.4.8 |
| cherokee | cherokee_httpd | 0.4.17 |
GitHub Security Advisory GHSA-m8r7-8362-fv6x
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17...
References (8)
- http://bugs.gentoo.org/show_bug.cgi?id=67667
- http://www.gentoo.org/security/en/glsa/glsa-200411-02.xml Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11574 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17934
- http://bugs.gentoo.org/show_bug.cgi?id=67667
- http://www.gentoo.org/security/en/glsa/glsa-200411-02.xml Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11574 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17934
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
5.56%
Top 8% most likely to be exploited
Threat Score
41.7 / 100
Data Sources
NVD
EPSS
GitHub