Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability

RSyslog is prone to a security-bypass vulnerability because of an error in the daemon's ACL (Access Control List) handling.

Attackers can exploit this issue to bypass ACL restrictions that limit which hosts may send messages to the daemon. Successful exploits can result in misleading log entries or denial-of-service conditions. Other attacks may also be possible.







 

Privacy Statement
Copyright 2008, SecurityFocus