CVE-2008-5617 - CERT CVE
ID CVE-2008-5617
Sažetak The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
Reference
CVSS
Base: 8.5
Impact: 7.8
Exploitability:10.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL COMPLETE
CVSS vektor AV:N/AC:L/Au:N/C:N/I:P/A:C
Zadnje važnije ažuriranje 08-08-2017 - 01:33
Objavljeno 17-12-2008 - 02:30