Tanne is a small, secure session-management solution for HTTP. It replaces common sessions with a system consisting of PIN and TANs, well known from online banking. Its main purpose is to enable programmers of Web applications to have really secured sessions without cookies or session-ids. A vulnerability in the product allows remote attackers to cause the program to execute arbitrary code, by exploiting a format string vulnerability.
Credit:
The information has been provided by dong-h0un yoU.