GLSA-200712-19 : Syslog-ng: Denial of Service
Medium Nessus Plugin ID 29816
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200712-19 (Syslog-ng: Denial of Service)
Oriol Carreras reported a NULL pointer dereference in the log_msg_parse() function when processing timestamps without a terminating whitespace character.
A remote attacker could send a specially crafted event to a vulnerable Syslog-ng server, resulting in a crash.
There is no known workaround at this time.
SolutionAll Syslog-ng users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=app-admin/syslog-ng-2.0.6'