First published: Mon Sep 30 2019(Updated: )
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Rsyslog | =8.1908.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-17040 is critical with a CVSS score of 9.8.
CVE-2019-17040 affects Rsyslog v8.1908.0.
The CWE ID of CVE-2019-17040 is CWE-125.
To fix CVE-2019-17040, upgrade Rsyslog to a version later than v8.1908.0.
You can find more information about CVE-2019-17040 at the following references: - [ChangeLog](https://github.com/rsyslog/rsyslog/blob/v8-stable/ChangeLog) - [Pull Request](https://github.com/rsyslog/rsyslog/pull/3875) - [Fedora Project Announcement](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KPNCHI7X2IEXRH6RYD6IDPR4PLB5RPC7/)