Executive brief
A vulnerability in the system logging service allows remote attackers to send unauthorized messages to the system logs. This can be used to fill up storage space, causing a service outage, or to flood logs with fake data to hide malicious activity. Organizations relying on these logs for security monitoring or operational stability are at risk of data loss and obscured audit trails.
Technical details
The vulnerability stems from an insecure configuration or implementation of the syslog service that allows unauthenticated remote message injection. By sending a high volume of syslog packets from any network location, an attacker can exhaust disk space on the logging host, leading to a denial of service (DoS) condition. Additionally, this capability allows for log spoofing, where an attacker injects false entries to mask unauthorized actions or complicate forensic analysis. The attack is reachable over the network and requires no prior authentication.
Affected products
- IBM aix
Timeline
- 1997-08-01: disclosed