Format String Vulnerability in Rsyslog Input and Output Modules
CVE-2017-12588
9.8CRITICAL
What is CVE-2017-12588?
Rsyslog prior to version 8.28.0 contains a vulnerability in its zmq3 input and output modules where description fields are incorrectly interpreted as format strings. This flaw could be exploited to launch a format string attack, potentially compromising the confidentiality and integrity of system data. Users of Rsyslog are advised to update to the latest version to mitigate these security risks.
