lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade syslog-ng | Jul 30, 2024 | Jul 11, 2011 |
| Gentoo Linux | — | Upgrade sys-fs/lvm2.Upgrade net-misc/rsync.Upgrade dev-php/PEAR-PEAR.Upgrade net-misc/mrouted.Upgrade x11-apps/xrdb.Upgrade net-libs/libsoup.Upgrade dev-php/PEAR-Mail.Upgrade sys-apps/shadow.Upgrade dev-db/unixODBC.Upgrade net-misc/vino.Upgrade net-libs/webkit-gtk.Upgrade app-office/gnucash.Upgrade gnome-base/gdm.Upgrade media-libs/fmod.Upgrade dev-vcs/gitolite.Upgrade net-analyzer/sflowtool.Upgrade sys-cluster/resource-agents.Upgrade dev-libs/xmlsec.Upgrade app-admin/syslog-ng.Upgrade media-libs/xine-lib.Upgrade media-sound/lastfmplayer.Upgrade app-misc/ca-certificates.Upgrade dev-util/oprofile.Upgrade dev-util/qt-creator.Upgrade games-sports/racer-bin. | Oct 30, 2017 | Jul 11, 2011 |
| Suse | — | Upgrade syslog-ng | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub