Double Free Vulnerability in ElasticSearch Plugin for rsyslog
CVE-2013-4758

Currently unrated

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
4 October 2013

What is CVE-2013-4758?

A double free vulnerability exists in the writeDataError function of the ElasticSearch plugin for rsyslog. This occurs when the errorfile is configured to use local logging, allowing remote attackers to craft malicious JSON responses that may lead to a crash of the rsyslog service. Additionally, this vulnerability poses a potential risk for remote code execution, thereby compromising the security of the system.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.