Back to search
CVE-2022-38725
Published: Jan 23, 2023
Modified: Apr 3, 2025
PUBLISHED
Description
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2023-43eb573065
vendor-advisory
FEDORA-2023-3d44a41fa3
vendor-advisory
DSA-5369
vendor-advisory
GLSA-202305-09
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now