Format string vulnerability in the log function in Net::Server 0.87...
Vulnerability Description
Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-1127
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.gentoo.org/security/en/glsa/glsa-200608-18.xml
- http://www.debian.org/security/2006/dsa-1122
- http://secunia.com/advisories/21452
- http://lists.ee.ethz.ch/postgrey/msg00630.html
- http://www.osvdb.org/15517
- http://secunia.com/advisories/21164
- http://marc.info/?l=full-disclosure&m=111354538331167&w=2
- http://secunia.com/advisories/21152
- http://lists.ee.ethz.ch/postgrey/msg00627.html
- http://secunia.com/advisories/21149
- http://lists.ee.ethz.ch/postgrey/msg00647.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20108
- http://www.debian.org/security/2006/dsa-1121
- http://secunia.com/advisories/14958
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:131
- http://www.securityfocus.com/bid/13193
Affected Vendor
postgrey
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.