CVE-2006-6664

Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the TopLevelLogger::logMessageV function in Misc/Logging.cpp. NOTE: some details were obtained from third party information.

Date published : 2006-12-20

http://marathon.sourceforge.net/release-notes/20061202.html

http://sourceforge.net/project/shownotes.php?release_id=471964