CVE Vulnerabilities

CVE-2008-5617

Published: Dec 17, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:L/Au:N/C:N/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.

Affected Software

NameVendorStart VersionEnd Version
RsyslogRsyslog3.12.1 (including)3.12.1 (including)
RsyslogRsyslog3.12.2 (including)3.12.2 (including)
RsyslogRsyslog3.12.3 (including)3.12.3 (including)
RsyslogRsyslog3.12.4 (including)3.12.4 (including)
RsyslogRsyslog3.12.5 (including)3.12.5 (including)
RsyslogRsyslog3.13.0 (including)3.13.0 (including)
RsyslogRsyslog3.15.0 (including)3.15.0 (including)
RsyslogRsyslog3.15.1-beta (including)3.15.1-beta (including)
RsyslogRsyslog3.17.0 (including)3.17.0 (including)
RsyslogRsyslog3.17.1 (including)3.17.1 (including)
RsyslogRsyslog3.17.4-beta (including)3.17.4-beta (including)
RsyslogRsyslog3.17.5-beta (including)3.17.5-beta (including)
RsyslogRsyslog3.19.0 (including)3.19.0 (including)
RsyslogRsyslog3.19.1 (including)3.19.1 (including)
RsyslogRsyslog3.19.2 (including)3.19.2 (including)
RsyslogRsyslog3.19.3 (including)3.19.3 (including)
RsyslogRsyslog3.19.4 (including)3.19.4 (including)
RsyslogRsyslog3.19.5 (including)3.19.5 (including)
RsyslogRsyslog3.19.6 (including)3.19.6 (including)
RsyslogRsyslog3.19.7 (including)3.19.7 (including)
RsyslogRsyslog3.19.8 (including)3.19.8 (including)
RsyslogRsyslog3.19.9 (including)3.19.9 (including)
RsyslogRsyslog3.19.10 (including)3.19.10 (including)
RsyslogRsyslog3.19.11 (including)3.19.11 (including)
RsyslogRsyslog3.19.12 (including)3.19.12 (including)
RsyslogRsyslog3.20.0 (including)3.20.0 (including)
RsyslogRsyslog4.1.0 (including)4.1.0 (including)
RsyslogRsyslog4.1.1 (including)4.1.1 (including)
RsyslogUbuntuhardy*
RsyslogUbuntuintrepid*
RsyslogUbuntuupstream*

References