Описание
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash.
Меры по смягчению последствий
This vulnerability requires the "imptcp" module to be enabled, and listening on a port that can potentially be reached by attackers. This module is not enabled by default in Red Hat Enterprise Linux 7. To check if imptcp is enabled, look for the string $InputPTCPServerRunin your rsyslog configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | rsyslog | Not affected | ||
| Red Hat Enterprise Linux 5 | rsyslog5 | Not affected | ||
| Red Hat Enterprise Linux 6 | rsyslog | Not affected | ||
| Red Hat Enterprise Linux 6 | rsyslog7 | Not affected | ||
| Red Hat Enterprise Linux 8 | rsyslog | Not affected | ||
| Red Hat Enterprise Linux 7 | rsyslog | Fixed | RHSA-2019:2110 | 06.08.2019 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rsyslog | Fixed | RHBA-2019:2501 | 15.08.2019 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased | Fixed | RHSA-2019:2437 | 12.08.2019 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | ovirt-node-ng | Fixed | RHSA-2019:2437 | 12.08.2019 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host | Fixed | RHSA-2019:2437 | 12.08.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
A denial of service vulnerability was found in rsyslog in the imptcp m ...
EPSS
5.3 Medium
CVSS3