Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.
| Software | From | Fixed in |
|---|---|---|
| citadel / ux | 6.26 | 6.26.x |
| citadel / ux | 6.08 | 6.08.x |
| citadel / ux | 6.24 | 6.24.x |
| citadel / ux | 6.23 | 6.23.x |
| citadel / ux | 6.27 | 6.27.x |
| citadel / ux | 6.07 | 6.07.x |