5
CVSSv2

CVE-2011-3200

Published: 06/09/2011 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 540
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x prior to 4.6.8 and 5.2.0 up to and including 5.8.4 might allow remote malicious users to cause a denial of service (application exit) via a long TAG in a legacy syslog message.

Vulnerable Product Search on Vulmon Subscribe to Product

rsyslog rsyslog 4.6.6

rsyslog rsyslog 4.6.7

rsyslog rsyslog 4.6.3

rsyslog rsyslog 4.6.4

rsyslog rsyslog 4.6.1

rsyslog rsyslog 4.6.2

rsyslog rsyslog 4.6.0

rsyslog rsyslog 4.6.5

rsyslog rsyslog 5.5.6

rsyslog rsyslog 5.5.7

rsyslog rsyslog 5.4.2

rsyslog rsyslog 5.5.0

rsyslog rsyslog 5.5.4

rsyslog rsyslog 5.5.1

rsyslog rsyslog 5.6.1

rsyslog rsyslog 5.3.6

rsyslog rsyslog 5.8.3

rsyslog rsyslog 5.6.4

rsyslog rsyslog 5.7.5

rsyslog rsyslog 5.5.3

rsyslog rsyslog 5.8.0

rsyslog rsyslog 5.8.2

rsyslog rsyslog 5.6.2

rsyslog rsyslog 5.6.0

rsyslog rsyslog 5.6.5

rsyslog rsyslog 5.7.7

rsyslog rsyslog 5.7.9

rsyslog rsyslog 5.4.0

rsyslog rsyslog 5.7.2

rsyslog rsyslog 5.3.1

rsyslog rsyslog 5.7.4

rsyslog rsyslog 5.7.10

rsyslog rsyslog 5.2.0

rsyslog rsyslog 5.3.7

rsyslog rsyslog 5.2.2

rsyslog rsyslog 5.8.1

rsyslog rsyslog 5.3.3

rsyslog rsyslog 5.7.6

rsyslog rsyslog 5.3.2

rsyslog rsyslog 5.7.8

rsyslog rsyslog 5.6.3

rsyslog rsyslog 5.5.2

rsyslog rsyslog 5.2.1

rsyslog rsyslog 5.4.1

rsyslog rsyslog 5.7.0

rsyslog rsyslog 5.7.3

rsyslog rsyslog 5.5.5

rsyslog rsyslog 5.3.4

rsyslog rsyslog 5.7.1

rsyslog rsyslog 5.3.5

rsyslog rsyslog 5.8.4

Vendor Advisories

Debian Bug report logs - #644611 CVE-2011-3200: Stack-based buffer overflow in the parseLegacySyslogMsg function Package: rsyslog; Maintainer for rsyslog is Michael Biebl <biebl@debianorg>; Source for rsyslog is src:rsyslog (PTS, buildd, popcon) Reported by: emeric boit <emericboit@yahoofr> Date: Fri, 7 Oct 2011 1 ...
Rsyslog could be made to crash if it processed a specially crafted message ...