Metrics
Affected Vendors & Products
Mon, 22 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Debian
Debian debian Linux |
|
CPEs | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | |
Vendors & Products |
Debian
Debian debian Linux |
Fri, 19 Sep 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oneidentity
Oneidentity syslog-ng |
|
CPEs | cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:*:*:*:* | |
Vendors & Products |
Oneidentity
Oneidentity syslog-ng |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 28 May 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 07 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 07 May 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could have an impact on TLS connections, such as in man-in-the-middle situations. Version 4.8.2 contains a fix for the issue. | |
Title | tranport: TLS host name wildcard matching too lax | |
Weaknesses | CWE-295 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-28T10:03:45.900Z
Reserved: 2024-09-27T20:37:22.121Z
Link: CVE-2024-47619

Updated: 2025-05-28T10:03:45.900Z

Status : Analyzed
Published: 2025-05-07T16:15:21.980
Modified: 2025-09-22T10:33:37.237
Link: CVE-2024-47619

No data.