Memory Leak Vulnerability in rsyslog Daemon Affects Multiple Rulesets Processing
CVE-2011-1490

5.5MEDIUM

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
14 November 2019

What is CVE-2011-1490?

A vulnerability in the rsyslog daemon prior to version 5.7.6 allows a local attacker to exploit a memory leak caused by the handling of log messages that belong to multiple rulesets. This improper processing can lead to a denial of service condition, ultimately disrupting the functionality of the rsyslogd daemon. Attackers can craft specific log messages that, when processed, trigger this memory leak, potentially causing instability or crashes in the logging service.

Affected Version(s)

rsyslog before 5.7.6

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.