RSyslog Syslog Message SQL Injection Vulnerability
BID:14942
Info
RSyslog Syslog Message SQL Injection Vulnerability
| Bugtraq ID: | 14942 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 26 2005 12:00AM |
| Updated: | Sep 26 2005 12:00AM |
| Credit: | The discoverer of this vulnerability is currently unknown; the vendor announced this issue. |
| Vulnerable: |
RSyslog RSyslog 1.10 RSyslog RSyslog 0.9.8 RSyslog RSyslog 0.9.7 RSyslog RSyslog 0.9.4 RSyslog RSyslog 0.9.3 RSyslog RSyslog 0.9.6 RSyslog RSyslog 0.9.5 |
| Not Vulnerable: |
RSyslog RSyslog 1.10.1 RSyslog RSyslog 1.0.1 |
Discussion
RSyslog Syslog Message SQL Injection Vulnerability
RSyslog is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
RSyslog is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
RSyslog Syslog Message SQL Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
RSyslog Syslog Message SQL Injection Vulnerability
Solution:
The vendor has addressed this issue in the stable version 1.0.1 and the development version 1.10.1:
RSyslog RSyslog 0.9.6
RSyslog RSyslog 0.9.5
RSyslog RSyslog 0.9.3
RSyslog RSyslog 0.9.4
RSyslog RSyslog 0.9.7
RSyslog RSyslog 0.9.8
RSyslog RSyslog 1.10
Solution:
The vendor has addressed this issue in the stable version 1.0.1 and the development version 1.10.1:
RSyslog RSyslog 0.9.6
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 0.9.5
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 0.9.3
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 0.9.4
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 0.9.7
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 0.9.8
-
RSyslog rsyslog-1.0.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-17.phtml
RSyslog RSyslog 1.10
-
RSyslog rsyslog-1.10.1.tar.gz
http://www.rsyslog.com/Downloads-index-req-getit-lid-18.phtml
References
RSyslog Syslog Message SQL Injection Vulnerability
References:
References:
- RSyslog Homepage (RSyslog)
- SecurityAdvisories :: SQL Injection Vulnerability in rsyslogd :: (RSyslog)