Vulnerabilities > CVE-2005-1127 - Unspecified vulnerability in Postgrey 1.17/1.18

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
postgrey
nessus

Summary

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

Vulnerable Configurations

Part Description Count
Application
Postgrey
3

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1121.NASL
    descriptionPeter Bieringer discovered that postgrey, a greylisting implementation for Postfix, is vulnerable to a format string attack that allows remote attackers to cause a denial of service to the daemon.
    last seen2020-06-01
    modified2020-06-02
    plugin id22663
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22663
    titleDebian DSA-1121-1 : postgrey - format string
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200608-18.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200608-18 (Net::Server: Format string vulnerability) The log function of Net::Server does not handle format string specifiers properly before they are sent to syslog. Impact : By sending a specially crafted datastream to an application using Net::Server, an attacker could cause a Denial of Service. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id22217
    published2006-08-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22217
    titleGLSA-200608-18 : Net::Server: Format string vulnerability
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1122.NASL
    descriptionPeter Bieringer discovered that the
    last seen2020-06-01
    modified2020-06-02
    plugin id22664
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22664
    titleDebian DSA-1122-1 : libnet-server-perl - format string
  • NASL familySuSE Local Security Checks
    NASL idSUSE9_10270.NASL
    descriptionA format string problem was found in the logging routines of the perl-Net-Server perl module collection. This could lead to a remote attacker being able to crash a server using the perl-Net-Server module. This is tracked by the Mitre CVE ID CVE-2005-1127.
    last seen2020-06-01
    modified2020-06-02
    plugin id41076
    published2009-09-24
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/41076
    titleSuSE9 Security Update : perl-Net-Server (YOU Patch Number 10270)