Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an account file.
References
Configurations
Information
Published : 2014-06-02 08:55
Updated : 2014-06-03 07:56
NVD link : CVE-2013-7386
Mitre link : CVE-2013-7386
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
rom_walton
- boinc