The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rsyslog | Rsyslog | 3.12.1 (including) | 3.12.1 (including) |
Rsyslog | Rsyslog | 3.12.2 (including) | 3.12.2 (including) |
Rsyslog | Rsyslog | 3.12.3 (including) | 3.12.3 (including) |
Rsyslog | Rsyslog | 3.12.4 (including) | 3.12.4 (including) |
Rsyslog | Rsyslog | 3.12.5 (including) | 3.12.5 (including) |
Rsyslog | Rsyslog | 3.13.0 (including) | 3.13.0 (including) |
Rsyslog | Rsyslog | 3.15.0 (including) | 3.15.0 (including) |
Rsyslog | Rsyslog | 3.15.1-beta (including) | 3.15.1-beta (including) |
Rsyslog | Rsyslog | 3.17.0 (including) | 3.17.0 (including) |
Rsyslog | Rsyslog | 3.17.1 (including) | 3.17.1 (including) |
Rsyslog | Rsyslog | 3.17.4-beta (including) | 3.17.4-beta (including) |
Rsyslog | Rsyslog | 3.17.5-beta (including) | 3.17.5-beta (including) |
Rsyslog | Rsyslog | 3.19.0 (including) | 3.19.0 (including) |
Rsyslog | Rsyslog | 3.19.1 (including) | 3.19.1 (including) |
Rsyslog | Rsyslog | 3.19.2 (including) | 3.19.2 (including) |
Rsyslog | Rsyslog | 3.19.3 (including) | 3.19.3 (including) |
Rsyslog | Rsyslog | 3.19.4 (including) | 3.19.4 (including) |
Rsyslog | Rsyslog | 3.19.5 (including) | 3.19.5 (including) |
Rsyslog | Rsyslog | 3.19.6 (including) | 3.19.6 (including) |
Rsyslog | Rsyslog | 3.19.7 (including) | 3.19.7 (including) |
Rsyslog | Rsyslog | 3.19.8 (including) | 3.19.8 (including) |
Rsyslog | Rsyslog | 3.19.9 (including) | 3.19.9 (including) |
Rsyslog | Rsyslog | 3.19.10 (including) | 3.19.10 (including) |
Rsyslog | Rsyslog | 3.19.11 (including) | 3.19.11 (including) |
Rsyslog | Rsyslog | 3.19.12 (including) | 3.19.12 (including) |
Rsyslog | Rsyslog | 3.20.0 (including) | 3.20.0 (including) |
Rsyslog | Rsyslog | 4.1.0 (including) | 4.1.0 (including) |
Rsyslog | Rsyslog | 4.1.1 (including) | 4.1.1 (including) |
Rsyslog | Ubuntu | hardy | * |
Rsyslog | Ubuntu | intrepid | * |
Rsyslog | Ubuntu | upstream | * |