syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade syslog-ng | Jul 30, 2024 | Nov 17, 2008 |
| Freebsd | — | Upgrade syslog-ngUpgrade syslog-ng2 | Dec 10, 2025 | Nov 18, 2008 |
| Gentoo Linux | — | Upgrade app-admin/syslog-ng. | Oct 30, 2017 | Nov 17, 2008 |
| Suse | — | Upgrade syslog-ng | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub