Lucene search

K
ubuntuUbuntuUSN-1224-1
HistoryOct 03, 2011 - 12:00 a.m.

rsyslog vulnerability

2011-10-0300:00:00
ubuntu.com
34

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.155

Percentile

95.9%

Releases

  • Ubuntu 11.04

Packages

  • rsyslog - enhanced multi-threaded syslogd

Details

It was discovered that rsyslog had an off-by-two error when parsing legacy
syslog messages. An attacker could potentially exploit this to cause a
denial of service via application crash.

OSVersionArchitecturePackageVersionFilename
Ubuntu11.04noarchrsyslog< 4.6.4-2ubuntu4.1UNKNOWN
Ubuntu11.04noarchrsyslog-gnutls< 4.6.4-2ubuntu4.1UNKNOWN
Ubuntu11.04noarchrsyslog-gssapi< 4.6.4-2ubuntu4.1UNKNOWN
Ubuntu11.04noarchrsyslog-mysql< 4.6.4-2ubuntu4.1UNKNOWN
Ubuntu11.04noarchrsyslog-pgsql< 4.6.4-2ubuntu4.1UNKNOWN
Ubuntu11.04noarchrsyslog-relp< 4.6.4-2ubuntu4.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.155

Percentile

95.9%