Memory Leak Vulnerability in Rsyslog Affects Multiple Ruleset Processing
CVE-2011-1489

5.5MEDIUM

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
14 November 2019

What is CVE-2011-1489?

A memory leak in Rsyslog prior to version 5.7.6 affects how the daemon processes log messages, particularly when handling multiple rulesets. This flaw occurs when output batches contain messages from more than one ruleset, allowing a local attacker to exploit the vulnerability. By sending specially crafted log messages, the attacker can trigger a denial of service, disrupting the normal functioning of the rsyslogd daemon and potentially affecting all operations reliant on logging services.

Affected Version(s)

rsyslog before 5.7.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.