First published: Tue Dec 18 2007(Updated: )
Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
syslog-ng | <=2.0.6 | |
syslog-ng | <=2.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6437 has a severity rating that indicates it can lead to a denial of service due to a crash.
To fix CVE-2007-6437, upgrade syslog-ng to version 2.0.6 or later for the open source edition and 2.1.8 or later for the premium edition.
CVE-2007-6437 affects Balabit syslog-ng versions prior to 2.0.6 and 2.1.8.
Yes, CVE-2007-6437 can be exploited remotely by sending a specifically crafted message.
Exploiting CVE-2007-6437 can cause the syslog-ng service to crash, resulting in a denial of service.