{
  "modified": "2025-08-09T19:01:26Z",
  "published": "2011-12-10T17:55:01Z",
  "id": "CVE-2011-4357",
  "details": "Format string vulnerability in the p_cgi_error function in python/neo_cgi.c in the Python CGI Kit (neo_cgi) module for Clearsilver 0.10.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are not properly handled when creating CGI error messages using the cgi_error API function.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/47016"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2011/dsa-2355"
    },
    {
      "type": "WEB",
      "url": "http://code.google.com/p/clearsilver/source/detail?r=919"
    },
    {
      "type": "WEB",
      "url": "http://osvdb.org/77419"
    },
    {
      "type": "WEB",
      "url": "http://tech.groups.yahoo.com/group/ClearSilver/message/1422"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2011/11/27/1"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71599"
    }
  ]
}
