First published: Mon Nov 17 2008(Updated: )
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OneIdentity Syslog-ng | <=2.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5110 is considered a moderate severity vulnerability that allows potential jail escape for attackers.
To fix CVE-2008-5110, upgrade syslog-ng to a version later than 2.0.9.
CVE-2008-5110 affects syslog-ng versions up to and including 2.0.9.
CVE-2008-5110 requires the presence of another vulnerability to be exploitable.
CVE-2008-5110 allows attackers to escape the chroot jail due to the absence of chdir in the chroot call.