CVE-2007-6437

Publication date 19 December 2007

Last updated 24 July 2024


Ubuntu priority

Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
syslog-ng 9.10 karmic
Fixed 2.0.6-1
9.04 jaunty
Fixed 2.0.6-1
8.10 intrepid
Fixed 2.0.6-1
8.04 LTS hardy
Fixed 2.0.6-1
7.10 gutsy
Fixed 2.0.0-1ubuntu1.1
7.04 feisty
Fixed 2.0.0-1ubuntu0.1
6.10 edgy
Fixed 1.9.11-1.1ubuntu0.1
6.06 LTS dapper Ignored end of life