Required CVE Record Information
Description
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.
References 6 Total
- http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git%3Ba=commit%3Bh=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff
- https://bugzilla.redhat.com/show_bug.cgi?id=709088
- openwall.com: [oss-security] 20110526 CVE Request -- syslog-ng -- Possible DoS mailing-list
- lists.fedoraproject.org: FEDORA-2011-8405 vendor-advisory
- securityfocus.com: 47800 vdb-entry
- secunia.com: 45122 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git%3Ba=commit%3Bh=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=709088 x_transferred
- openwall.com: [oss-security] 20110526 CVE Request -- syslog-ng -- Possible DoS mailing-listx_transferred
- lists.fedoraproject.org: FEDORA-2011-8405 vendor-advisoryx_transferred
- securityfocus.com: 47800 vdb-entryx_transferred
- secunia.com: 45122 third-party-advisoryx_transferred