CVE-2004-2417
UnknownEPSS 2.69%
Last modified
CVE-2004-2417 is a vulnerability of currently unknown severity. Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.. EPSS estimates a 2.69% chance of exploitation in the next 30 days.
Description
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Smtp.Proxy | Smtp.Proxy | 1.1.3 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0267.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/11823Vendor Advisory
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0267.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/11823Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2417?
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
How severe is CVE-2004-2417?
Severity scoring for CVE-2004-2417 is pending analysis. The EPSS model estimates a 2.69% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2417?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2411The CleanseMessage function in shop$db.asp for VP-ASP Shoppi…
- CVE-2004-2412Multiple SQL injection vulnerabilities in VP-ASP Shopping Ca…
- CVE-2004-2413SQL injection vulnerability in VP-ASP Shopping Cart 4.0 thro…
- CVE-2004-2414Novell NetWare 6.5 SP 1.1, when installing or upgrading usin…
- CVE-2004-2415Davenport before 0.9.10 allows attackers to cause a denial o…
- CVE-2004-2416Buffer overflow in the logging component of CCProxy allows r…
- CVE-2004-2418Buffer overflow in SlimFTPd 3.15 and earlier allows local us…
- CVE-2004-2419Keene Digital Media Server 1.0.2 allows local users to obtai…
- CVE-2004-2420Hitachi Job Management Partner (JP1) JP1/File Transmission S…
- CVE-2004-2421Unknown vulnerability in Hitachi Job Management Partner (JP1…
- CVE-2004-2422Multiple features in Ipswitch IMail Server before 8.13 allow…
- CVE-2004-2423Unknown vulnerability in the Web calendaring component of Ip…
Are you affected by CVE-2004-2417?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
