关键信息摘要 漏洞名称: Weex: Format string vulnerability — GLSA 200510-09 发布日期: October 08, 2005 最新修订日期: October 08, 2005: 01 影响的包: Package: on all architectures 受影响的版本: 不受影响的版本: 漏洞严重性: normal 利用方式: remote 漏洞描述: Weex contains a format string error that may be exploited by malicious servers to execute arbitrary code. 漏洞发现者: Ulf Harnhammar 漏洞触发条件: Triggered when Weex is first run (or when its cache files are rebuilt, using the option). 漏洞影响: An attacker could set up a malicious FTP server which, when accessed using Weex, could execute arbitrary code with the rights of the user running Weex. 解决方法: All Weex users should upgrade to the latest version: 相关漏洞编号: CAN-2005-3150