Vulnerability Details CVE-2002-1200
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.065
EPSS Ranking 90.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2002-1200
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.0
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.10
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.15
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.7
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.8
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.9
-
cpe:2.3:a:oneidentity:syslog-ng:1.5.15
-
cpe:2.3:a:oneidentity:syslog-ng:1.5.20