module

rsyslog Long Tag Off-By-Two DoS

Disclosed
Sep 1, 2011
Created
May 30, 2018

Description

This module triggers an off-by-two overflow in the
rsyslog daemon. This flaw is unlikely to yield code execution
but is effective at shutting down a remote log daemon. This bug
was introduced in version 4.6.0 and corrected in 4.6.8/5.8.5.
Compiler differences may prevent this bug from causing any
noticeable result on many systems (RHEL6 is affected).

Author

hdm x@hdm.io

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/dos/syslog/rsyslog_long_tag
msf auxiliary(rsyslog_long_tag) > show actions
...actions...
msf auxiliary(rsyslog_long_tag) > set ACTION < action-name >
msf auxiliary(rsyslog_long_tag) > show options
...show and set options...
msf auxiliary(rsyslog_long_tag) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.