CVE-2024-47619
- EPSS 0.06%
- Published 07.05.2025 15:12:02
- Last modified 22.09.2025 10:33:37
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but sh...
CVE-2022-38725
- EPSS 6.12%
- Published 23.01.2023 16:15:10
- Last modified 03.04.2025 15:15:42
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and...
CVE-2020-8019
- EPSS 0.04%
- Published 29.06.2020 12:15:10
- Last modified 21.11.2024 05:38:13
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point o...
CVE-2011-1951
- EPSS 1.55%
- Published 11.07.2011 20:55:01
- Last modified 11.04.2025 00:51:21
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regula...
CVE-2011-0343
- EPSS 0.12%
- Published 28.01.2011 16:00:03
- Last modified 11.04.2025 00:51:21
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows loca...
CVE-2008-5110
- EPSS 1.09%
- Published 17.11.2008 22:21:27
- Last modified 09.04.2025 00:30:58
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0....
CVE-2002-1200
- EPSS 6.53%
- Published 28.10.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to ca...