CVE-2004-0156
ssmtp - format string
EPSS 3.5%
Description
Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.
How to fix CVE-2004-0156
To remediate CVE-2004-0156, upgrade the affected package to a fixed version below.
- Debian/ssmtp—upgrade to 2.60.7 or later
- Debian/ssmtp—upgrade to 2.50.6.1 or later
Is CVE-2004-0156 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.60.7
- from 0, < 2.50.6.1