6.8
CVSSv2

CVE-2013-4758

Published: 04/10/2013 Updated: 07/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog prior to 7.4.2 and prior to 7.5.2 devel, when errorfile is set to local logging, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.

Vulnerable Product Search on Vulmon Subscribe to Product

rsyslog rsyslog 7.3.7

rsyslog rsyslog 7.3.6

rsyslog rsyslog 7.3.5

rsyslog rsyslog 7.3.4

rsyslog rsyslog 7.1.10

rsyslog rsyslog 7.1.9

rsyslog rsyslog 7.1.8

rsyslog rsyslog 7.1.7

rsyslog rsyslog 7.1.6

rsyslog rsyslog 7.4.0

rsyslog rsyslog 7.3.15

rsyslog rsyslog 7.3.14

rsyslog rsyslog 7.3.13

rsyslog rsyslog 7.2.6

rsyslog rsyslog 7.2.5

rsyslog rsyslog 7.2.4

rsyslog rsyslog 7.2.3

rsyslog rsyslog 7.1.1

rsyslog rsyslog 7.1.0

rsyslog rsyslog 6.6.0

rsyslog rsyslog 6.5.1

rsyslog rsyslog

rsyslog rsyslog 7.3.12

rsyslog rsyslog 7.3.10

rsyslog rsyslog 7.3.8

rsyslog rsyslog 7.3.3

rsyslog rsyslog 7.3.0

rsyslog rsyslog 7.2.1

rsyslog rsyslog 7.1.11

rsyslog rsyslog 7.1.4

rsyslog rsyslog 7.1.2

rsyslog rsyslog 6.4.2

rsyslog rsyslog 7.5.0

rsyslog rsyslog 7.3.11

rsyslog rsyslog 7.3.9

rsyslog rsyslog 7.3.1

rsyslog rsyslog 7.2.7

rsyslog rsyslog 7.2.2

rsyslog rsyslog 7.1.12

rsyslog rsyslog 7.1.5

rsyslog rsyslog 7.1.3

Vendor Advisories

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 742 and before 752 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response ...