cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.0-1build2", "binary_name": "qweborf" }, { "binary_version": "1.0-1build2", "binary_name": "weborf" }, { "binary_version": "1.0-1build2", "binary_name": "weborf-daemon" }, { "binary_version": "1.0-1build2", "binary_name": "weborf-dbgsym" } ] }