5
CVSSv2

CVE-2007-6437

Published: 19/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Balabit syslog-ng 2.0.x prior to 2.0.6 and 2.1.x prior to 2.1.8 allows remote malicious users to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

balabit syslog-ng premium edition

balabit syslog-ng open source edition

Vendor Advisories

Debian Bug report logs - #457334 syslog-ng: CVE-2007-6437 prone to denial of service attack Package: syslog-ng; Maintainer for syslog-ng is syslog-ng maintainers <syslog-ng-maintainers@alioth-listsdebiannet>; Source for syslog-ng is src:syslog-ng (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: ...
Oriol Carreras discovered that syslog-ng, a next generation logging daemon can be tricked into dereferencing a NULL pointer through malformed timestamps, which can lead to denial of service and the disguise of an subsequent attack, which would otherwise be logged The old stable distribution (sarge) is not affected For the stable distribution ...