Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
| Software | From | Fixed in |
|---|---|---|
| stellar-x_software / msntauth | - | 2.0.3.x |