CVE-2008-5618 : Detail

CVE-2008-5618

0.24%V3
Network
2008-12-17
02h00 +00:00
2024-09-16
18h34 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:N/I:N/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Products Mentioned

Configuraton 0

Rsyslog>>Rsyslog >> Version 3.12.1

Rsyslog>>Rsyslog >> Version 3.20.0

Rsyslog>>Rsyslog >> Version 4.1.0

Rsyslog>>Rsyslog >> Version 4.1.1

References

http://www.rsyslog.com/Topic4.phtml
Tags : x_refsource_CONFIRM