Back to search
CVE-2018-1000140
Published: Mar 23, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3612-1
vendor-advisory
GLSA-201804-21
vendor-advisory
RHSA-2018:1703
vendor-advisory
RHSA-2018:1704
vendor-advisory
RHSA-2018:1702
vendor-advisory
RHSA-2018:1225
vendor-advisory
RHSA-2018:1707
vendor-advisory
RHSA-2018:1223
vendor-advisory
DSA-4151
vendor-advisory
RHSA-2018:1701
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now