Format string vulnerability in the log_message function in lks.c in Linux Kiss Server 1.2, when background (daemon) mode is disabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in an invalid command.
https://exchange.xforce.ibmcloud.com/vulnerabilities/41018
http://www.vupen.com/english/advisories/2008/0785