Oneidentity

Syslog-ng

7 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Published 07.05.2025 15:12:02
  • Last modified 22.09.2025 10:33:37

syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but sh...

  • EPSS 6.12%
  • Published 23.01.2023 16:15:10
  • Last modified 03.04.2025 15:15:42

An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and...

Exploit
  • EPSS 0.04%
  • Published 29.06.2020 12:15:10
  • Last modified 21.11.2024 05:38:13

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module for Legacy Software 12, SUSE Linux Enterprise Point o...

  • EPSS 1.55%
  • Published 11.07.2011 20:55:01
  • Last modified 11.04.2025 00:51:21

lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regula...

  • EPSS 0.12%
  • Published 28.01.2011 16:00:03
  • Last modified 11.04.2025 00:51:21

Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows loca...

  • EPSS 1.09%
  • Published 17.11.2008 22:21:27
  • Last modified 09.04.2025 00:30:58

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0....

Exploit
  • EPSS 6.53%
  • Published 28.10.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to ca...