Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
http://www.novell.com/linux/security/advisories/2002_039_syslog_ng.html
http://www.linuxsecurity.com/advisories/other_advisory-2513.html
http://www.iss.net/security_center/static/10339.php