SB2013100404 - Resource management error in rsyslog.com rsyslog



SB2013100404 - Resource management error in rsyslog.com rsyslog

Published: October 4, 2013 Updated: August 10, 2020

Security Bulletin ID SB2013100404
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2013-4758)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.


Remediation

Install update from vendor's website.