syslog-ng is an enhanced log daemo. Prior to version 4.8.2, tls_wildcard_match() matches on certificates such as foo.*.bar although that is not allowed. It is also possible to pass partial wildcards such as foo.a*c.bar which glib matches but should be avoided / invalidated. This issue could have an impact on TLS connections, such as in man-in-the-middle situations. Version 4.8.2 contains a fix for the issue.
{
"cwe_ids": [
"CWE-295"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47619.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "4.8.2"
}
]
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47619.json"
[
{
"source": "https://github.com/syslog-ng/syslog-ng/commit/dadfdbecde5bfe710b0a6ee5699f96926b3f9006",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "129239506911275764281307254894892505243",
"length": 556.0
},
"id": "CVE-2024-47619-4b9796b8",
"target": {
"function": "tls_wildcard_match",
"file": "lib/transport/tls-verifier.c"
},
"deprecated": false
},
{
"source": "https://github.com/syslog-ng/syslog-ng/commit/dadfdbecde5bfe710b0a6ee5699f96926b3f9006",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"144541513471867889326114442209456853028"
],
"threshold": 0.9
},
"id": "CVE-2024-47619-fa74ab65",
"target": {
"file": "lib/transport/tls-verifier.h"
},
"deprecated": false
},
{
"source": "https://github.com/syslog-ng/syslog-ng/commit/dadfdbecde5bfe710b0a6ee5699f96926b3f9006",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"320867099991833213996933490347142131638",
"198564491072866669010713645662581422418",
"130768867755235571715613470296339569599",
"175945590735941958021196109711828184145",
"129472530188411827807498485074157218491",
"147340562262846051597295349768216229822",
"289153932437854639064117390956265939094",
"81822784586303148445462733690326310392",
"129855620224667633044020367374339344253",
"19828992689143592825861695807829785456",
"165047838817734404235791867276442929830",
"326183978764609974099154440618165803553",
"1028399239823189033354360737049753321",
"129069187869393803815608103214566573767",
"322380928818918564758180552477891444395",
"310135961403200717416709984929877123653",
"33621595125975772312162675380002173163",
"113866028751790042930893711117540937579",
"138474947308200909730483128113688298285",
"308580016231735313645848626876109702081",
"302114112848333277227593858845866393203"
],
"threshold": 0.9
},
"id": "CVE-2024-47619-fe919926",
"target": {
"file": "lib/transport/tls-verifier.c"
},
"deprecated": false
}
]
"2026-08-05T08:17:24Z"