[SECURITY] CVE-2007-6437 prone to denial of service attack
Bug #183389 reported by
Cody A.W. Somerville
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
syslog-ng (Debian) |
Fix Released
|
Unknown
|
|||
syslog-ng (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Edgy |
Fix Released
|
High
|
Unassigned | ||
Feisty |
Fix Released
|
High
|
Unassigned | ||
Gutsy |
Fix Released
|
High
|
Unassigned |
Bug Description
Binary package hint: syslog-ng
Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference. This has been fixed in the latest upload to Hardy.
References:
- http://
- http://
- http://
Changed in syslog-ng: | |
assignee: | nobody → cody-somerville |
importance: | Undecided → High |
status: | New → In Progress |
Changed in syslog-ng: | |
status: | Confirmed → Fix Released |
Changed in syslog-ng: | |
status: | Unknown → Fix Released |
To post a comment you must log in.
debdiff syslog- ng_2.0. 0-1ubuntu1. dsc syslog- ng_2.0. 0-1ubuntu1. 1.dsc > syslog- ng_2.0. 0-1ubuntu1. 1.gutsy- security. debdiff
Changes: git.balabit. hu/?p=bazsi/ syslog- ng-2.0. git;a=commitdif f;h=3126ebad217 e7fd6356f4733ca 33f571aa87a170 cve.mitre. org/cgi- bin/cvename. cgi?name= CVE-2007- 6437 bugs.debian. org/cgi- bin/bugreport. cgi?bug= 457334 4f565f1c3a758bf d48 713 admin extra syslog- ng_2.0. 0-1ubuntu1. 1.dsc d58a58b8d90f7ea 300 346056 admin extra syslog- ng_2.0. 0.orig. tar.gz e1f9ce5fe432615 bde 11211 admin extra syslog- ng_2.0. 0-1ubuntu1. 1.diff. gz
syslog-ng (2.0.0-1ubuntu1.1) gutsy-security; urgency=low
.
* SECURITY UPDATE: Allows remote attackers to cause a denial of service
(crash) via a message with a timestamp that does not contain a trailing
space, which triggers a NULL pointer dereference.
* src/logmsg.c (log_msg_parse): fixed possible NULL pointer dereference
in log message parsing, as done in upstream RCS
* References:
- http://
- http://
- http://
Files:
1506917867abfe
6ea55c647dcbd3
aa1cd8d197f63c