Lucene search

K
cve[email protected]CVE-2008-5110
HistoryNov 17, 2008 - 10:21 p.m.

CVE-2008-5110

2008-11-1722:21:27
web.nvd.nist.gov
35
4
cve-2008-5110
syslog-ng
chroot vulnerability
nvd
security advisory

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0.002

Percentile

59.3%

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.

Affected configurations

NVD
Node
oneidentitysyslog-ngRange2.0.9
VendorProductVersionCPE
oneidentitysyslog-ngcpe:/a:oneidentity:syslog-ng::::

Social References

More

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0.002

Percentile

59.3%