LWN.net Logo

rsyslog: denial of service

Package(s):rsyslog CVE #(s):CVE-2011-4623
Created:January 24, 2012 Updated:July 10, 2012
Description: From the Ubuntu advisory:

Peter Eisentraut discovered that Rsyslog would not properly perform input validation when configured to use imfile. If an attacker were able to craft messages in a file that Rsyslog monitored, an attacker could cause a denial of service. The imfile module is disabled by default in Ubuntu.

Alerts:
Ubuntu USN-1338-1 2012-01-23
Red Hat RHSA-2012:0796-04 2012-06-20
Mandriva MDVSA-2012:100 2012-06-25
Oracle ELSA-2012-0796 2012-07-02
Scientific Linux SL-rsys-20120709 2012-07-09
CentOS CESA-2012:0796 2012-07-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds