Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2018-1223

Опубликовано: 24 апр. 2018
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2018-1223: librelp security update (CRITICAL)

[1.2.12-1.1]

  • fixed bad NVR
  • resolves rhbz#1561232

[1.2.12-2]

  • fixed CVE-2018-1000140
  • resolves rhbz#1561232

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

librelp

1.2.12-1.el7_5.1

librelp-devel

1.2.12-1.el7_5.1

Oracle Linux x86_64

librelp

1.2.12-1.el7_5.1

librelp-devel

1.2.12-1.el7_5.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 8.1
redhat
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
nvd
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
debian
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow ...

suse-cvrf
больше 7 лет назад

Security update for librelp