
Descriptionsyslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs505791

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
syslog-ng (PTS)jessie, jessie (lts)3.5.6-2+deb8u2fixed
stretch (lts), stretch3.8.1-10+deb9u1fixed
buster (security)3.19.1-5+deb10u1fixed
bullseye (security), bullseye3.28.1-2+deb11u1fixed
sid, trixie4.4.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


no security flaw by itself, still it should be fixed

