Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2013-10-04T17:00:00Z
Updated: 2024-09-16T18:34:27.910Z
Reserved: 2013-07-04T00:00:00Z
Link: CVE-2013-4758
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-10-04T17:55:09.947
Modified: 2024-11-21T01:56:19.563
Link: CVE-2013-4758
Redhat