Unrated severityNVD Advisory· Published Oct 16, 2006· Updated Jun 16, 2026
CVE-2006-4154
CVE-2006-4154
Description
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
45cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*+ 43 more
- cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.28:beta:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.28:beta:win32:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.32:beta:win32:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.34:beta:win32:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.43:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.45:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.56:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.58:*:win32:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.2:*:windows:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.3:*:windows:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- labs.idefense.com/intelligence/vulnerabilities/display.phpnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/366020nvdUS Government Resource
- secunia.com/advisories/22458nvd
- secunia.com/advisories/22549nvd
- security.gentoo.org/glsa/glsa-200610-12.xmlnvd
- securitytracker.com/idnvd
- www.osvdb.org/29536nvd
- www.securityfocus.com/bid/20527nvd
- www.vupen.com/english/advisories/2006/4033nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29550nvd
News mentions
0No linked articles in our index yet.