CVE-2008-5618: Medium severity rsyslog Rsyslog vulnerability
imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5618?
CVE-2008-5618 is classified as a medium-severity vulnerability due to its potential for causing denial of service through disk consumption.
How do I fix CVE-2008-5618?
To fix CVE-2008-5618, upgrade rsyslog to version 4.1.2 or later.
What are the affected versions of rsyslog for CVE-2008-5618?
The affected versions of rsyslog are 4.1.1, 4.1.0, 3.21 beta versions before 3.21.9, and 3.20 before 3.20.2.
Can CVE-2008-5618 be exploited remotely?
Yes, CVE-2008-5618 can be exploited remotely by sending unauthorized messages to the rsyslog service.
What is the impact of CVE-2008-5618 on system performance?
The impact of CVE-2008-5618 on system performance includes potential disk consumption leading to denial of service.