LWN.net Logo

rsyslog: multiple vulnerabilities

Package(s):rsyslog CVE #(s):CVE-2008-5617 CVE-2008-5618
Created:December 22, 2008 Updated:January 12, 2009
Description:

From the rsyslog advisory:

CVE-2008-5617: Due to a coding error in the modularization effort, the $AllowedSender directive is no longer honored but silently accepted. As such, rsyslog-based access control via $AllowedSender is not working and messages from every sender will be accepted by rsyslog. Most importantly, this could lead to misleading log entries or a remote DoS, by a malicious sender simply flooding the system logs with messages until the system runs out of disk space.

From the CVE entry:

CVE-2008-5618: imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.

Alerts:
Fedora FEDORA-2008-11476 2008-12-21
Fedora FEDORA-2008-11538 2008-12-21
SuSE SUSE-SR:2009:001 2009-01-12

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds