|
Syslog-ng Macro Expansion Remote Buffer Overflow Vulnerability
A vulnerability has been discovered in syslog-ng. Reportedly, syslog-ng macro expansion fails to do proper bounds checking when handling constant characters. By passing an overly large amount of constants to a macro, it may be possible to cause a overflow in the macro expansion buffer. This issue could be exploited by a remote attacker to execute arbitrary commands as the syslog-ng process. Although discovered for version 1.4.15 and 1.5.20, it is likely that early versions of the software are also vulnerable. |
|
|
Privacy Statement |