Description
Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
Published: 2005-04-16
Score: 5.0 Medium
EPSS: 5.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1121-1 New postgrey packages fix denial of service
Debian DSA Debian DSA DSA-1122-1 New Net::Server packages fix denial of service
EUVD EUVD EUVD-2005-1130 Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
History

No history.

Subscriptions

Postgrey Postgrey
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T21:36:00.202Z

Reserved: 2005-04-16T00:00:00.000Z

Link: CVE-2005-1127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-05-02T04:00:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2005-1127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses