Vulnerability Name: | CVE-2002-2280 (CCN-10702) | ||||||||
Assigned: | 2002-11-20 | ||||||||
Published: | 2002-11-20 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-16 | ||||||||
Vulnerability Consequences: | Configuration | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20021120 [OpenBSD] [syslogd] false src-IP when logging to remote syslogd Source: CCN Type: BugTraq Mailing List, Wed Nov 20 2002 - 09:36:43 CST [OpenBSD] [syslogd] false src-IP when logging to remote syslogd Source: MITRE Type: CNA CVE-2002-2280 Source: CCN Type: OSVDB ID: 60223 OpenBSD syslogd Persistent IP Logging Weakness Source: BID Type: UNKNOWN 6219 Source: CCN Type: BID-6219 OpenBSD False syslogd Source IP Reporting Weakness Source: XF Type: UNKNOWN openbsd-syslogd-incorrect-reporting(10702) Source: XF Type: UNKNOWN openbsd-syslogd-incorrect-reporting(10702) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |