Security Advisory
CVE-2004-2417
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.