MEDIUM · 4.3

CVE-2011-1951

lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consu...

Vulnerability Description

lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular expression.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
OneidentitySyslog-Ng< 3.2.4
PcrePcre8.12

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1951?

CVE-2011-1951 is a vulnerability with a CVSS score of 4.3 (MEDIUM). lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consu...

How severe is CVE-2011-1951?

CVE-2011-1951 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1951?

Check the references section above for vendor advisories and patch information. Affected products include: Oneidentity Syslog-Ng, Pcre Pcre.