CVE-2011-1489
Publication date 14 November 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.
Status
Package | Ubuntu Release | Status |
---|---|---|
rsyslog | ||
14.04 LTS trusty |
Not affected
|
|
Patch details
Package | Patch details |
---|---|
rsyslog |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 · Medium |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |