Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000140

Опубликовано: 23 мар. 2018
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

A stack-based buffer overflow was found in the way librelp parses X.509 certificates. By connecting or accepting connections from a remote peer, an attacker may use a specially crafted X.509 certificate to exploit this flaw and potentially execute arbitrary code.

Меры по смягчению последствий

Users are strongly advised not to expose their logging RELP services to a public network.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8librelpNot affected
Red Hat Enterprise Linux 6librelpFixedRHSA-2018:122524.04.2018
Red Hat Enterprise Linux 6.6 Advanced Update SupportlibrelpFixedRHSA-2018:170123.05.2018
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportlibrelpFixedRHSA-2018:170123.05.2018
Red Hat Enterprise Linux 6.7 Extended Update SupportlibrelpFixedRHSA-2018:170223.05.2018
Red Hat Enterprise Linux 7librelpFixedRHSA-2018:122324.04.2018
Red Hat Enterprise Linux 7.2 Advanced Update SupportlibrelpFixedRHSA-2018:170323.05.2018
Red Hat Enterprise Linux 7.2 Telco Extended Update SupportlibrelpFixedRHSA-2018:170323.05.2018
Red Hat Enterprise Linux 7.2 Update Services for SAP SolutionslibrelpFixedRHSA-2018:170323.05.2018
Red Hat Enterprise Linux 7.3 Extended Update SupportlibrelpFixedRHSA-2018:170723.05.2018

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1560084librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c

EPSS

Процентиль: 97%
0.42505
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
nvd
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
debian
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow ...

suse-cvrf
больше 7 лет назад

Security update for librelp

suse-cvrf
больше 3 лет назад

Security update for librelp

EPSS

Процентиль: 97%
0.42505
Средний

8.1 High

CVSS3