Rsyslog and Sysklogd Integer Overflow Vulnerability Analysis
CVE-2014-3683

Currently unrated

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
2 November 2014

What is CVE-2014-3683?

The vulnerability stems from an integer overflow in Rsyslog versions prior to 7.6.7 and 8.x before 8.4.2, as well as Sysklogd version 1.5 and earlier. Attackers can exploit this vulnerability by sending a large priority (PRI) value, which can trigger a denial of service by crashing the affected services. This issue was noted as a consequence of an incomplete fix for a previous vulnerability, highlighting the need for organizations to ensure they are running patched versions of affected software to prevent potential exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.