VDB
CVE-2011-1951
CVE-2011-1951
PUBLISHED
CVSS 4.300000190734863 MEDIUM
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.
EPSS 1.55% · 81.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.55%
81.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oneidentity | syslog-ng | 0 |
| n/a | n/a | n/a |
Exploit Intelligence
Timeline
- Jul 11, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git%3Ba=commit%3Bh=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff url
- https://bugzilla.redhat.com/show_bug.cgi?id=709088 url
- [oss-security] 20110526 CVE Request -- syslog-ng -- Possible DoS mailing-list
- FEDORA-2011-8405 vendor-advisory
- 47800 vdb
- 45122 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-1951 advisory
- http://git.balabit.hu/?p=bazsi/syslog-ng-3.2.git;a=commit;h=09710c0b105e579d35c7b5f6c66d1ea5e3a3d3ff url