CVE-2008-5110

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2008
Last modified:
09/04/2025

Description

syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:*:*:*:* 2.0.9 (including)