CVE-2005-1127

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgrey:postgrey:*:*:*:*:*:*:*:*
cpe:2.3:a:postgrey:postgrey:1.17:*:*:*:*:*:*:*
cpe:2.3:a:postgrey:postgrey:1.18:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-05-02 04:00

Updated : 2024-02-04 16:52


NVD link : CVE-2005-1127

Mitre link : CVE-2005-1127

CVE.ORG link : CVE-2005-1127


JSON object : View

Products Affected

postgrey

  • postgrey