Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3683

Опубликовано: 02 окт. 2014
Источник: redhat
CVSS2: 6.8

Описание

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

Отчет

This issue did not affect the versions of sysklogd and rsyslog packages as shipped with Red Hat Enterprise Linux 5, 6, and7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rsyslogNot affected
Red Hat Enterprise Linux 5rsyslog5Not affected
Red Hat Enterprise Linux 5sysklogdNot affected
Red Hat Enterprise Linux 6rsyslogNot affected
Red Hat Enterprise Linux 6rsyslog7Not affected
Red Hat Enterprise Linux 7rsyslogNot affected
Red Hat OpenShift Enterprise 2rsyslog7Not affected
Red Hat Storage 2.1rsyslogNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1149081rsyslog: integer overflow in PRI parsing

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

nvd
больше 11 лет назад

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

debian
больше 11 лет назад

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysk ...

github
больше 3 лет назад

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

fstec
около 11 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

6.8 Medium

CVSS2