← Back

CVE-2013-4758

nvd nist
Published: Oct 4, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.

Affected (42)

Products: Rsyslog: Rsyslog
1 product
Rsyslog
Configuration A
42 vulnerable
Vulnerable SoftwareAffected Versions
Rsyslog
Up to 7.4.1
Up to 7.5.1
Version 6.4.2
Version 6.5.1
Version 6.6.0
Version 7.1.0
Version 7.1.10
Version 7.1.11
Version 7.1.12
Version 7.1.1
Version 7.1.2
Version 7.1.3
Version 7.1.4
Version 7.1.5
Version 7.1.6
Version 7.1.7
Version 7.1.8
Version 7.1.9
Version 7.2.1
Version 7.2.2
Version 7.2.3
Version 7.2.4
Version 7.2.5
Version 7.2.6
Version 7.2.7
Version 7.3.0
Version 7.3.10
Version 7.3.11
Version 7.3.12
Version 7.3.13
Version 7.3.14
Version 7.3.15
Version 7.3.1
Version 7.3.3
Version 7.3.4
Version 7.3.5
Version 7.3.6
Version 7.3.7
Version 7.3.8
Version 7.3.9
Version 7.4.0
Version 7.5.0 devel

Related CWEs

References (6)

Timeline

No history available yet.