Stack-based Buffer Overflow in rsyslogd Affecting Multiple Versions
CVE-2011-3200

Currently unrated

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
6 September 2011

What is CVE-2011-3200?

A stack-based buffer overflow vulnerability exists in the parseLegacySyslogMsg function of rsyslogd. This flaw may allow remote attackers to remotely send specially crafted legacy syslog messages with long TAGs, potentially leading to application crashes or denial of service. The affected versions include rsyslog 4.6.x prior to 4.6.8 and rsyslog 5.2.0 through 5.8.4, necessitating prompt mitigation measures for users operating these versions.

References

EPSS Score

20% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.