vendor:
WinSyslog
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: WinSyslog
Affected Version From: WinSyslog prior to 2003-09-15
Affected Version To: WinSyslog prior to 2003-09-15
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2003
WinSyslog System Freeze Vulnerability
WinSyslog is prone to a remotely exploitable denial of service vulnerability. The issue exists in the Interactive Syslog Server specifically. This occurs when the program receives multiple excessive syslog messages via the port it listens on (10514/UDP by default). This is also reported to cause system instability, which is likely due to resource exhaustion.
Mitigation:
The vendor has released hot fixes for the MonitorWare Agent product, which also includes the vulnerable component.