Back

CVE-2004-1097

Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
cherokee cherokee_httpd 0.1
cherokee cherokee_httpd 0.1.5
cherokee cherokee_httpd 0.1.6
cherokee cherokee_httpd 0.2
cherokee cherokee_httpd 0.2.5
cherokee cherokee_httpd 0.2.6
cherokee cherokee_httpd 0.2.7
cherokee cherokee_httpd 0.4.6
cherokee cherokee_httpd 0.4.7
cherokee cherokee_httpd 0.4.8
cherokee cherokee_httpd 0.4.17

GitHub Security Advisory GHSA-m8r7-8362-fv6x

Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 5.56%

Top 8% most likely to be exploited

Threat Score 41.7 / 100

Data Sources

NVD EPSS GitHub