5
CVSSv2

CVE-2008-5618

Published: 17/12/2008 Updated: 17/12/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

imudp in rsyslog 4.x prior to 4.1.2, 3.21 prior to 3.21.9 beta, and 3.20 prior to 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote malicious users to cause a denial of service (disk consumption) via a large number of spurious messages.

Vulnerable Product Search on Vulmon Subscribe to Product

rsyslog rsyslog 4.1.0

rsyslog rsyslog 3.12.1

rsyslog rsyslog 4.1.1

rsyslog rsyslog 3.20.0

Vendor Advisories

Debian Bug report logs - #510906 CVE-2008-5618: possible DoS via full disk Package: rsyslog; Maintainer for rsyslog is Michael Biebl <biebl@debianorg>; Source for rsyslog is src:rsyslog (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Mon, 5 Jan 2009 20:33:01 UTC Severity: imp ...