PT-2011-1135 · Rsyslog+1 · Rsyslog+1

Martin Osvald

·

Published

2011-09-01

·

Updated

2024-06-15

·

CVE-2011-3200

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions rsyslog versions 4.6.x through 4.6.7 rsyslog versions 5.2.0 through 5.8.4
Description The issue is related to a stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd. This might allow remote attackers to cause a denial of service (application exit) via a long TAG in a legacy syslog message. The vulnerability can be exploited remotely and may lead to disruption of protected information availability.
Recommendations For rsyslog versions 4.6.x through 4.6.7, update to version 4.6.8 or later. For rsyslog versions 5.2.0 through 5.8.4, update to a version later than 5.8.4. As a temporary workaround, consider restricting access to the parseLegacySyslogMsg function until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-07081
BDU:2015-07082
BDU:2015-07083
BDU:2015-07084
BDU:2015-07085
BDU:2015-07086
BDU:2015-07087
CVE-2011-3200
OPENSUSE-SU-2024:10498-1
RHSA-2011:1247
RHSA-2011_1247

Affected Products

Red Hat
Rsyslog