Vulnerability Details CVE-2011-1951
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2011-1951
-
cpe:2.3:a:oneidentity:syslog-ng:-
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.0
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.10
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.15
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.7
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.8
-
cpe:2.3:a:oneidentity:syslog-ng:1.4.9
-
cpe:2.3:a:oneidentity:syslog-ng:1.5.15
-
cpe:2.3:a:oneidentity:syslog-ng:1.5.20
-
cpe:2.3:a:oneidentity:syslog-ng:2.0
-
cpe:2.3:a:oneidentity:syslog-ng:2.0.9
-
cpe:2.3:a:oneidentity:syslog-ng:2.0.9-27.34.40.5.1
-
cpe:2.3:a:oneidentity:syslog-ng:3.0
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.1
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.2
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.3
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.4
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.5
-
cpe:2.3:a:oneidentity:syslog-ng:3.0.8
-
cpe:2.3:a:oneidentity:syslog-ng:3.1
-
cpe:2.3:a:oneidentity:syslog-ng:3.1.0
-
cpe:2.3:a:oneidentity:syslog-ng:3.2
-
cpe:2.3:a:oneidentity:syslog-ng:3.2.1
-
cpe:2.3:a:oneidentity:syslog-ng:3.2.2
-