VYPR
Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026

CVE-2005-1127

CVE-2005-1127

Description

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

Affected products

3
  • Postgrey/Postgrey3 versions
    cpe:2.3:a:postgrey:postgrey:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:postgrey:postgrey:*:*:*:*:*:*:*:*range: <=1.16
    • cpe:2.3:a:postgrey:postgrey:1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:postgrey:postgrey:1.18:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.