Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smtp.proxy | Smtp.proxy | 1.1.3 (including) | 1.1.3 (including) |