RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
BID:32630
Info
RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
| Bugtraq ID: | 32630 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-5617 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2008 12:00AM |
| Updated: | Apr 13 2015 09:00PM |
| Credit: | This issue was disclosed by the vendor following an unspecified user's bug report. |
| Vulnerable: |
S.u.S.E. openSUSE 11.1 RSyslog RSyslog 4.1.1 RSyslog RSyslog 4.1 RSyslog RSyslog 3.20 RSyslog RSyslog 3.12.1 |
| Not Vulnerable: |
RSyslog RSyslog 3.21.9 RSyslog RSyslog 3.20.1 |
Discussion
RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
RSyslog is prone to a security-bypass vulnerability because of an error in the daemon's ACL (Access Control List) handling.
Attackers can exploit this issue to bypass ACL restrictions that limit which hosts may send messages to the daemon. Successful exploits can result in misleading log entries or denial-of-service conditions. Other attacks may also be possible.
RSyslog is prone to a security-bypass vulnerability because of an error in the daemon's ACL (Access Control List) handling.
Attackers can exploit this issue to bypass ACL restrictions that limit which hosts may send messages to the daemon. Successful exploits can result in misleading log entries or denial-of-service conditions. Other attacks may also be possible.
Exploit / POC
RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
An attacker may exploit this issue via readily available tools.
An attacker may exploit this issue via readily available tools.
Solution / Fix
RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RSyslog '$AllowedSender' Configuration Directive Security Bypass Vulnerability
References:
References:
- $AllowedSender not honored (RSyslog)
- rsyslog 3.21.9 (v3-beta) released - IMPORTANT SECURITY RELEASE (RSyslog)
- RSyslog Homepage (RSyslog)