Format string vulnerability in the pcgierror function in python/neocgi.c in the Python CGI Kit (neocgi) module for Clearsilver 0.10.5 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are not properly handled when creating CGI error messages using the cgi_error API function.