Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000140

Опубликовано: 23 мар. 2018
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

1.2.15-1
devel

not-affected

1.2.15-1
disco

not-affected

1.2.15-1
eoan

not-affected

1.2.15-1
esm-apps/bionic

released

1.2.14-3ubuntu0.1~esm1
esm-apps/focal

not-affected

1.2.15-1
esm-apps/jammy

not-affected

1.2.15-1
esm-apps/xenial

released

1.2.9-1ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 97%
0.42505
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
nvd
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

CVSS3: 9.8
debian
больше 7 лет назад

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow ...

suse-cvrf
больше 7 лет назад

Security update for librelp

suse-cvrf
больше 3 лет назад

Security update for librelp

EPSS

Процентиль: 97%
0.42505
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2018-1000140