CVE Vulnerabilities

CVE-2008-5618

Published: Dec 17, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.

Affected Software

Name Vendor Start Version End Version
Rsyslog Rsyslog 3.12.1 (including) 3.12.1 (including)
Rsyslog Rsyslog 3.20.0 (including) 3.20.0 (including)
Rsyslog Rsyslog 4.1.0 (including) 4.1.0 (including)
Rsyslog Rsyslog 4.1.1 (including) 4.1.1 (including)
Rsyslog Ubuntu hardy *
Rsyslog Ubuntu intrepid *
Rsyslog Ubuntu upstream *

References