Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rsyslog | Rsyslog | * | 7.4.1 (including) |
Rsyslog | Rsyslog | * | 7.5.1 (including) |
Rsyslog | Rsyslog | 6.4.2 (including) | 6.4.2 (including) |
Rsyslog | Rsyslog | 6.5.1 (including) | 6.5.1 (including) |
Rsyslog | Rsyslog | 6.6.0 (including) | 6.6.0 (including) |
Rsyslog | Rsyslog | 7.1.0 (including) | 7.1.0 (including) |
Rsyslog | Rsyslog | 7.1.1 (including) | 7.1.1 (including) |
Rsyslog | Rsyslog | 7.1.2 (including) | 7.1.2 (including) |
Rsyslog | Rsyslog | 7.1.3 (including) | 7.1.3 (including) |
Rsyslog | Rsyslog | 7.1.4 (including) | 7.1.4 (including) |
Rsyslog | Rsyslog | 7.1.5 (including) | 7.1.5 (including) |
Rsyslog | Rsyslog | 7.1.6 (including) | 7.1.6 (including) |
Rsyslog | Rsyslog | 7.1.7 (including) | 7.1.7 (including) |
Rsyslog | Rsyslog | 7.1.8 (including) | 7.1.8 (including) |
Rsyslog | Rsyslog | 7.1.9 (including) | 7.1.9 (including) |
Rsyslog | Rsyslog | 7.1.10 (including) | 7.1.10 (including) |
Rsyslog | Rsyslog | 7.1.11 (including) | 7.1.11 (including) |
Rsyslog | Rsyslog | 7.1.12 (including) | 7.1.12 (including) |
Rsyslog | Rsyslog | 7.2.1 (including) | 7.2.1 (including) |
Rsyslog | Rsyslog | 7.2.2 (including) | 7.2.2 (including) |
Rsyslog | Rsyslog | 7.2.3 (including) | 7.2.3 (including) |
Rsyslog | Rsyslog | 7.2.4 (including) | 7.2.4 (including) |
Rsyslog | Rsyslog | 7.2.5 (including) | 7.2.5 (including) |
Rsyslog | Rsyslog | 7.2.6 (including) | 7.2.6 (including) |
Rsyslog | Rsyslog | 7.2.7 (including) | 7.2.7 (including) |
Rsyslog | Rsyslog | 7.3.0 (including) | 7.3.0 (including) |
Rsyslog | Rsyslog | 7.3.1 (including) | 7.3.1 (including) |
Rsyslog | Rsyslog | 7.3.3 (including) | 7.3.3 (including) |
Rsyslog | Rsyslog | 7.3.4 (including) | 7.3.4 (including) |
Rsyslog | Rsyslog | 7.3.5 (including) | 7.3.5 (including) |
Rsyslog | Rsyslog | 7.3.6 (including) | 7.3.6 (including) |
Rsyslog | Rsyslog | 7.3.7 (including) | 7.3.7 (including) |
Rsyslog | Rsyslog | 7.3.8 (including) | 7.3.8 (including) |
Rsyslog | Rsyslog | 7.3.9 (including) | 7.3.9 (including) |
Rsyslog | Rsyslog | 7.3.10 (including) | 7.3.10 (including) |
Rsyslog | Rsyslog | 7.3.11 (including) | 7.3.11 (including) |
Rsyslog | Rsyslog | 7.3.12 (including) | 7.3.12 (including) |
Rsyslog | Rsyslog | 7.3.13 (including) | 7.3.13 (including) |
Rsyslog | Rsyslog | 7.3.14 (including) | 7.3.14 (including) |
Rsyslog | Rsyslog | 7.3.15 (including) | 7.3.15 (including) |
Rsyslog | Rsyslog | 7.4.0 (including) | 7.4.0 (including) |
Rsyslog | Rsyslog | 7.5.0-devel (including) | 7.5.0-devel (including) |