Buffer Overflow Vulnerability in ManageEngine EventLog Analyzer Syslog Server
CVE-2010-4840
Currently unrated
Summary
The Syslog server in ManageEngine EventLog Analyzer version 6.1 is susceptible to multiple buffer overflow vulnerabilities. Attackers can leverage this weakness to initiate a denial of service by causing the SysEvttCol.exe process to crash or potentially execute arbitrary code. This is achieved by sending a long Syslog PRI message header to UDP ports 513 or 514. The vulnerability was addressed in version 7.2 Build 7020.
References
Timeline
Vulnerability published
Vulnerability Reserved