Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22016
http://www.securityfocus.com/bid/14666
http://www.kb.cert.org/vuls/id/139421
http://www.debian.org/security/2005/dsa-786
http://sourceforge.net/project/shownotes.php?group_id=604&release_id=351847