Описание
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
Ссылки
- Patch
- PatchVendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
- Patch
- PatchVendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:qwikmail:qwikmail_smtp:0.3:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.15333
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
EPSS
Процентиль: 94%
0.15333
Средний
7.5 High
CVSS2
Дефекты
NVD-CWE-Other