Buffer Overflow Vulnerability in ManageEngine EventLog Analyzer Syslog Server
CVE-2010-4840

Currently unrated

Key Information:

Vendor
CVE Published:
27 September 2011

Summary

The Syslog server in ManageEngine EventLog Analyzer version 6.1 is susceptible to multiple buffer overflow vulnerabilities. Attackers can leverage this weakness to initiate a denial of service by causing the SysEvttCol.exe process to crash or potentially execute arbitrary code. This is achieved by sending a long Syslog PRI message header to UDP ports 513 or 514. The vulnerability was addressed in version 7.2 Build 7020.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.