Computer Security
[EN] securityvulns.ru no-pyccku


rsyslog DoS
Published:05.10.2014
Source:
SecurityVulns ID:13992
Type:remote
Threat Level:
5/10
Description:DoS on request parsing.
Affected:RSYSLOG : rsyslog 8.4
CVE:CVE-2014-3683 (Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.)
 CVE-2014-3634 (rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 3040-1] rsyslog security update (05.10.2014)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod