Back

HIGH

syslog-ng improper chroot

Published Nov 17, 2008

Description

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 17, 2008
Updated Aug 7, 2024
Reserved Nov 17, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 17, 2008