Back
CVE-2005-1100
Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| salim_gasmi | gld | 1.3 |
| salim_gasmi | gld | 1.4 |
GitHub Security Advisory GHSA-7jpj-7rqq-pq5x
Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and...
References (12)
- http://marc.info/?l=bugtraq&m=111339935903880&w=2
- http://secunia.com/advisories/14941 Patch
- http://security.gentoo.org/glsa/glsa-200504-10.xml Patch
- http://securitytracker.com/alerts/2005/Apr/1013678.html
- http://www.osvdb.org/15493
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20067
- http://marc.info/?l=bugtraq&m=111339935903880&w=2
- http://secunia.com/advisories/14941 Patch
- http://security.gentoo.org/glsa/glsa-200504-10.xml Patch
- http://securitytracker.com/alerts/2005/Apr/1013678.html
- http://www.osvdb.org/15493
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20067
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
10.99%
Top 4% most likely to be exploited
Threat Score
33.3 / 100
Data Sources
NVD
EPSS
GitHub