5

CVE-2014-3683

Exploit

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

Data is provided by the National Vulnerability Database (NVD)
RsyslogRsyslog Version <= 7.6.6
RsyslogRsyslog Version8.1.0
RsyslogRsyslog Version8.1.1
RsyslogRsyslog Version8.1.2
RsyslogRsyslog Version8.1.3
RsyslogRsyslog Version8.1.4
RsyslogRsyslog Version8.1.5
RsyslogRsyslog Version8.1.6
RsyslogRsyslog Version8.2.0
RsyslogRsyslog Version8.2.1
RsyslogRsyslog Version8.2.2
RsyslogRsyslog Version8.2.3
RsyslogRsyslog Version8.3.0
RsyslogRsyslog Version8.3.1
RsyslogRsyslog Version8.3.2
RsyslogRsyslog Version8.3.3
RsyslogRsyslog Version8.3.4
RsyslogRsyslog Version8.3.5
RsyslogRsyslog Version8.4.0
RsyslogRsyslog Version8.4.1
Sysklogd ProjectSysklogd Version <= 1.5
Sysklogd ProjectSysklogd Version1.1
Sysklogd ProjectSysklogd Version1.2
Sysklogd ProjectSysklogd Version1.3
Sysklogd ProjectSysklogd Version1.4
Sysklogd ProjectSysklogd Version1.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.89% 0.824
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P