Access Control Issue in Rsyslog by Adiscon
CVE-2008-5617

Currently unrated

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
17 December 2008

What is CVE-2008-5617?

The Rsyslog product, specifically versions 3.12.1 through 3.20.0 and versions 4.1.0 and 4.1.1, has a flaw in its Access Control List (ACL) handling. The implementation does not adhere to the $AllowedSender directive, enabling remote attackers to circumvent established access restrictions. This vulnerability allows malicious entities to spoof log messages or inundate the system with false entries, thereby compromising the integrity of the logging system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.