CVE-2005-1099
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 68%
from disclosure to weapon0 days
Published on NVDApr 13
1st PoCApr 12
metasploitApr 12
exploitation probability
68%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/16841unverifiedexploitdbwww.exploit-db.com/exploits/10023unverifiedexploitdbwww.exploit-db.com/exploits/25392unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=111339935903880&w=2http://marc.info/?l=bugtraq&m=111342432325670&w=2http://secunia.com/advisories/14941http://security.gentoo.org/glsa/glsa-200504-10.xmlhttp://securitytracker.com/alerts/2005/Apr/1013678.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/20066http://www.gasmi.net/down/gld-historyhttp://www.osvdb.org/15492