CVE-2011-1951
Gentoo Linux Security Advisory 201412-09
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.
lib/logmatcher.c en Balabit syslog-ng anterior a v3.2.4, cuando la bandera global está habilitada y cuando usa PCRE v8.12 y posiblemente otras versiones, permite a atacantes remotos provocar una denegación de servicio(consumo de memoria) a través de un mensaje que no coincide con una expresión regular.
This GLSA contains notification of vulnerabilities found in several Gentoo packages which have been fixed prior to January 1, 2012. The worst of these vulnerabilities could lead to local privilege escalation and remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-05-09 CVE Reserved
- 2011-07-11 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git%3Ba=commit%3Bh=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff | X_refsource_confirm | |
http://secunia.com/advisories/45122 | Third Party Advisory | |
http://www.securityfocus.com/bid/47800 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2011/05/26/1 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=709088 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062107.html | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oneidentity Search vendor "Oneidentity" | Syslog-ng Search vendor "Oneidentity" for product "Syslog-ng" | < 3.2.4 Search vendor "Oneidentity" for product "Syslog-ng" and version " < 3.2.4" | - |
Affected
| in | Pcre Search vendor "Pcre" | Pcre Search vendor "Pcre" for product "Pcre" | 8.12 Search vendor "Pcre" for product "Pcre" and version "8.12" | - |
Safe
|