PT-2011-3494 · Balabit+1 · Syslog-Ng+1

Jan Lieskovsky

·

Published

2011-07-11

·

Updated

2023-02-13

·

CVE-2011-1951

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions syslog-ng versions prior to 3.2.4
Description The issue allows remote attackers to cause a denial of service, specifically memory consumption, by sending a message that does not match a regular expression. This occurs when the global flag is set and PCRE 8.12, or possibly other versions, is in use.
Recommendations For versions prior to 3.2.4, update to version 3.2.4 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2011-1951
OPENSUSE-SU-2024:10493-1

Affected Products

Pcre
Syslog-Ng