First published: Mon Nov 17 2008(Updated: )
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oneidentity Syslog-ng | <=2.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.