CVE-2006-0150
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
Date published : 2006-01-09
http://www.securityfocus.com/bid/16177
http://www.securityfocus.com/archive/1/421286/100/0/threaded