CVE Vulnerabilities

CVE-2011-4623

Published: Sep 25, 2012 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5.4 MODERATE
AV:A/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Rsyslog Rsyslog 4.1.0 (including) 4.1.0 (including)
Rsyslog Rsyslog 4.1.1 (including) 4.1.1 (including)
Rsyslog Rsyslog 4.1.2 (including) 4.1.2 (including)
Rsyslog Rsyslog 4.1.3 (including) 4.1.3 (including)
Rsyslog Rsyslog 4.1.4 (including) 4.1.4 (including)
Rsyslog Rsyslog 4.1.5 (including) 4.1.5 (including)
Rsyslog Rsyslog 4.1.6 (including) 4.1.6 (including)
Rsyslog Rsyslog 4.1.7 (including) 4.1.7 (including)
Rsyslog Rsyslog 4.2.0 (including) 4.2.0 (including)
Rsyslog Rsyslog 4.3.0 (including) 4.3.0 (including)
Rsyslog Rsyslog 4.3.1 (including) 4.3.1 (including)
Rsyslog Rsyslog 4.3.2 (including) 4.3.2 (including)
Rsyslog Rsyslog 4.4.0 (including) 4.4.0 (including)
Rsyslog Rsyslog 4.4.1 (including) 4.4.1 (including)
Rsyslog Rsyslog 4.4.2 (including) 4.4.2 (including)
Rsyslog Rsyslog 4.5.0 (including) 4.5.0 (including)
Rsyslog Rsyslog 4.5.1 (including) 4.5.1 (including)
Rsyslog Rsyslog 4.5.2 (including) 4.5.2 (including)
Rsyslog Rsyslog 4.5.3 (including) 4.5.3 (including)
Rsyslog Rsyslog 4.5.4 (including) 4.5.4 (including)
Rsyslog Rsyslog 4.5.5 (including) 4.5.5 (including)
Rsyslog Rsyslog 4.5.6 (including) 4.5.6 (including)
Rsyslog Rsyslog 4.5.7 (including) 4.5.7 (including)
Rsyslog Rsyslog 4.5.8 (including) 4.5.8 (including)
Rsyslog Rsyslog 4.6.0 (including) 4.6.0 (including)
Rsyslog Rsyslog 4.6.1 (including) 4.6.1 (including)
Rsyslog Rsyslog 4.6.2 (including) 4.6.2 (including)
Rsyslog Rsyslog 4.6.3 (including) 4.6.3 (including)
Rsyslog Rsyslog 4.6.4 (including) 4.6.4 (including)
Rsyslog Rsyslog 4.6.5 (including) 4.6.5 (including)
Red Hat Enterprise Linux 6 RedHat rsyslog-0:5.8.10-2.el6 *
Rsyslog Ubuntu natty *
Rsyslog Ubuntu upstream *

References