There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command. This vulnerability allows remote code execution, a different vulnerability than CVE-2019-15846. This CVE is in CISA’s Known Exploited Vulnerabilities Catalog. Apply updates per vendor instructions, please wait. Switch to CPE 2.2 CPEs loading. Change history 14 change records found show changes. Are we missing a CPE here? Please let us know.”]

