Back

CVE-2005-1127

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
postgrey postgrey *
postgrey postgrey 1.17
postgrey postgrey 1.18

GitHub Security Advisory GHSA-3c38-6263-x4qc

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.70%

Top 15% most likely to be exploited

Threat Score 20.8 / 100

Data Sources

NVD EPSS GitHub