Back

CVE-2004-2417

Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
smtp.proxy smtp.proxy 1.1.3

GitHub Security Advisory GHSA-cj4f-f844-qfff

Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.69%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub