Balabit syslog-ng 拒绝服务漏洞

admin 2022-07-23 06:24:06 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Balabit syslog-ng 拒绝服务漏洞

  • CNNVD编号:CNNVD-200712-225
  • 危害等级: 中危
  • CVE编号: CVE-2007-6437
  • 漏洞类型: 输入验证
  • 发布时间: 2007-12-19
  • 威胁类型: 远程
  • 更新时间: 2007-12-19
  • 厂        商: balabit
  • 漏洞来源: Oriol Carreras dis...

漏洞简介

Balabit syslog-ng 2.0.x版本之前的版本2.0.6以及2.1.x版本之前的版本2.1.8中,远程攻击者可以借助一个不具有拖动空间的timestamp的信息造成拒绝服务(崩溃),该信息引发一个空值指示器作废。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Balabit syslog-ng 1.4 .0rc3

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.10

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.11

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.12

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.14

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Axis Communications StorPoint 1.4.15

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.15

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Axis Communications StorPoint 1.4.16

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.16

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.6

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.7

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.8

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.4.9

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.5.15

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.5.20

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 1.5.21

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 2.0.1

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 2.0.2

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 2.0.3

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 2.0.4

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

Balabit syslog-ng 2.0.5

Balabit syslog-ng-2.0.6.tar.gz

http://www.balabit.com/downloads/files/syslog-ng/sources/2.0/src/syslo g-ng-2.0.6.tar.gz

参考网址

来源: XF

名称: syslogng-timestamp-dos(39082)

链接:http://xforce.iss.net/xforce/xfdb/39082

来源: VUPEN

名称: ADV-2007-4257

链接:http://www.frsirt.com/english/advisories/2007/4257

来源: SECTRACK

名称: 1019105

链接:http://securitytracker.com/id?1019105

来源: SECUNIA

名称: 28118

链接:http://secunia.com/advisories/28118

来源: BUGTRAQ

名称: 20071217 ZSA-2007-029: syslog-ng Denial of Service

链接:http://seclists.org/bugtraq/2007/Dec/0202.HTML

来源: FEDORA

名称: FEDORA-2008-0559

链接:https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00610.HTML

来源: FEDORA

名称: FEDORA-2008-0523

链接:https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00606.HTML

来源: bugzilla.redhat.com

链接:https://bugzilla.redhat.com/show_bug.cgi?id=426173

来源: BID

名称: 26897

链接:http://www.securityfocus.com/bid/26897

来源: BUGTRAQ

名称: 20071217 Re: [syslog-ng] ZSA-2007-029: syslog-ng Denial of Service

链接:http://www.securityfocus.com/archive/1/archive/1/485181/100/0/threaded

来源: OSVDB

名称: 39551

链接:http://www.osvdb.org/39551

来源: DEBIAN

名称: DSA-1464

链接:http://www.debian.org/security/2008/dsa-1464

来源: GENTOO

名称: GLSA-200712-19

链接:http://security.gentoo.org/glsa/glsa-200712-19.xml

来源: SECUNIA

名称: 28483

链接:http://secunia.com/advisories/28483

来源: SECUNIA

名称: 28372

链接:http://secunia.com/advisories/28372

来源: SECUNIA

名称: 28279

链接:http://secunia.com/advisories/28279

受影响实体

  • Balabit Syslog-Ng_premium_edition:2.1.8  
  • Balabit Syslog-Ng_open_source_edition:2.0.6  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0