CVE-2017-12588: Critical severity suse rsyslog vulnerability
Published Aug 6, 2017
·Updated
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
Affected Software
1 affected component
rsyslog Rsyslog<=8.27.0
Remediation
Patch Available
Event History
Aug 6, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12588?
CVE-2017-12588 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-12588?
To fix CVE-2017-12588, upgrade rsyslog to version 8.28.0 or later.
3
What does CVE-2017-12588 affect?
CVE-2017-12588 affects the zmq3 input and output modules of rsyslog versions prior to 8.28.0.
4
What type of attack is associated with CVE-2017-12588?
CVE-2017-12588 is associated with a format string attack.
5
What is the potential impact of CVE-2017-12588?
The potential impact of CVE-2017-12588 is unspecified, as it could vary based on the context of the attack.