PT-2008-6673 · Rsyslog · Rsyslog

Published

2008-12-17

·

Updated

2008-12-17

·

CVE-2008-5618

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions rsyslog versions 3.20.0 through 3.20.1 rsyslog versions 3.21.0 through 3.21.8 rsyslog versions 4.0.0 through 4.1.1
Description The issue allows remote attackers to cause a denial of service via a large number of spurious messages, resulting in disk consumption. This occurs because the imudp module in the affected rsyslog versions generates a message even when it is sent by an unauthorized sender.
Recommendations For rsyslog versions 3.20.0 through 3.20.1, update to version 3.20.2 or later. For rsyslog versions 3.21.0 through 3.21.8, update to version 3.21.9 beta or later. For rsyslog versions 4.0.0 through 4.1.1, update to version 4.1.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-5618

Affected Products

Rsyslog