Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 26 May 2011 13:09:12 +0200
From: Szalay Attila <sasa@...abit.hu>
To: Open Source Software Security <oss-security@...ts.openwall.com>
Subject: CVE Request -- syslog-ng -- Possible DoS

Hi All,

In syslog-ng if a recent enough libpcre is installed (ie. 8.12 or newer)
there is a possible Denial of Service.

In our (BalaBit) opinion tis is not a big security issue, because if you
use the vulnerable setting you will run into the DoS for sure without
any malicious attack.

The attack vector is that the attacker send a message which the regexp
not match. 

But because of this bug get this amount of attention, it' may worth the
CVE id.

References:
http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git;a=commit;h=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff
http://www.securityfocus.com/bid/47800/


-- 
Szalay Attila
BalaBit IT Kft.
Security Team Leader

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.