Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging.
| Software | From | Fixed in |
|---|---|---|
| qbik / wingate | 6.0 | 6.0.x |
| qbik / wingate | - | 6.2.1.x |
| qbik / wingate | 5.0 | 5.0.x |