{"api_version":"1","generated_at":"2026-07-23T06:05:49+00:00","cve":"CVE-2005-1100","urls":{"html":"https://cve.report/CVE-2005-1100","api":"https://cve.report/api/cve/CVE-2005-1100.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1100","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1100"},"summary":{"title":"CVE-2005-1100","description":"Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.osvdb.org/15493","name":"http://www.osvdb.org/15493","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/14941","name":"http://secunia.com/advisories/14941","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - Gld Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200504-10.xml","name":"http://security.gentoo.org/glsa/glsa-200504-10.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Gentoo Linux Documentation\n--\n  Gld: Remote execution of arbitrary code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20067","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20067","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=111339935903880&w=2","name":"http://marc.info/?l=bugtraq&m=111339935903880&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'GLD (Greylisting daemon for Postfix) multiple vulnerabilities.' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://securitytracker.com/alerts/2005/Apr/1013678.html","name":"http://securitytracker.com/alerts/2005/Apr/1013678.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Gld Format String Flaws and Buffer Overflows Let Remote Users Execute Arbitrary Code With Root Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1100","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1100","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1100","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"salim_gasmi","cpe5":"gld","cpe6":"1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1100","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"salim_gasmi","cpe5":"gld","cpe6":"1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:35:59.937Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15493","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/15493"},{"name":"1013678","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/alerts/2005/Apr/1013678.html"},{"name":"GLSA-200504-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200504-10.xml"},{"name":"14941","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14941"},{"name":"20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111339935903880&w=2"},{"name":"gld-cnfc-format-string(20067)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20067"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-04-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15493","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/15493"},{"name":"1013678","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/alerts/2005/Apr/1013678.html"},{"name":"GLSA-200504-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200504-10.xml"},{"name":"14941","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14941"},{"name":"20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111339935903880&w=2"},{"name":"gld-cnfc-format-string(20067)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20067"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1100","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15493","refsource":"OSVDB","url":"http://www.osvdb.org/15493"},{"name":"1013678","refsource":"SECTRACK","url":"http://securitytracker.com/alerts/2005/Apr/1013678.html"},{"name":"GLSA-200504-10","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200504-10.xml"},{"name":"14941","refsource":"SECUNIA","url":"http://secunia.com/advisories/14941"},{"name":"20050412 GLD (Greylisting daemon for Postfix) multiple vulnerabilities.","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111339935903880&w=2"},{"name":"gld-cnfc-format-string(20067)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20067"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1100","datePublished":"2005-04-13T04:00:00.000Z","dateReserved":"2005-04-13T00:00:00.000Z","dateUpdated":"2024-08-07T21:35:59.937Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:salim_gasmi:gld:1.3:*:*:*:*:*:*:*","matchCriteriaId":"ED36FC52-E63D-480F-9141-C3BD9DE60DB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:salim_gasmi:gld:1.4:*:*:*:*:*:*:*","matchCriteriaId":"777D93B6-589F-4B76-841A-4343F3A24740"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1100","Ordinal":"1","Title":"CVE-2005-1100","CVE":"CVE-2005-1100","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1100","Ordinal":"1","NoteData":"Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.","Type":"Description","Title":"CVE-2005-1100"},{"CveYear":"2005","CveId":"1100","Ordinal":"2","NoteData":"2005-04-13","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1100","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}