Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Syslog-ng Macro Expansion Remote Buffer Overflow Vulnerability

A vulnerability has been discovered in syslog-ng.

Reportedly, syslog-ng macro expansion fails to do proper bounds checking when handling constant characters. By passing an overly large amount of constants to a macro, it may be possible to cause a overflow in the macro expansion buffer.

This issue could be exploited by a remote attacker to execute arbitrary commands as the syslog-ng process.

Although discovered for version 1.4.15 and 1.5.20, it is likely that early versions of the software are also vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus