Unrated severityNVD Advisory· Published Dec 19, 2007· Updated Apr 23, 2026
CVE-2007-6437
CVE-2007-6437
Description
Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.
Affected products
2- cpe:2.3:a:balabit:syslog-ng_open_source_edition:*:*:*:*:*:*:*:*Range: <=2.0.6
- cpe:2.3:a:balabit:syslog-ng_premium_edition:*:*:*:*:*:*:*:*Range: <=2.1.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- secunia.com/advisories/28118nvdVendor Advisory
- seclists.org/bugtraq/2007/Dec/0202.htmlnvd
- secunia.com/advisories/28279nvd
- secunia.com/advisories/28372nvd
- secunia.com/advisories/28483nvd
- security.gentoo.org/glsa/glsa-200712-19.xmlnvd
- securitytracker.com/idnvd
- www.debian.org/security/2008/dsa-1464nvd
- www.osvdb.org/39551nvd
- www.securityfocus.com/archive/1/485181/100/0/threadednvd
- www.securityfocus.com/bid/26897nvd
- www.vupen.com/english/advisories/2007/4257nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39082nvd
- www.redhat.com/archives/fedora-package-announce/2008-January/msg00606.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-January/msg00610.htmlnvd
News mentions
0No linked articles in our index yet.