Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses.
| Software | From | Fixed in |
|---|---|---|
| kim_storm / nn | 6.6.1 | 6.6.1.x |
| kim_storm / nn | 6.6.0 | 6.6.0.x |
| kim_storm / nn | 6.6.2 | 6.6.2.x |
| kim_storm / nn | 6.6.3 | 6.6.3.x |