cbcvebase.
CVE-2014-3634
published 2014-11-02

CVE-2014-3634: rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary…

PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.55%
93.9th percentile
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debianinetutils< inetutils 2:1.9.2.39.3a460-1 (bookworm)inetutils 2:1.9.2.39.3a460-1 (bookworm)
debianrsyslog< inetutils 2:1.9.2.39.3a460-1 (bookworm)inetutils 2:1.9.2.39.3a460-1 (bookworm)
debianrsyslog< rsyslog 8.4.2-1 (bookworm)rsyslog 8.4.2-1 (bookworm)
gnuinetutils>= 0 < 2:1.9.2.39.3a460-12:1.9.2.39.3a460-1
gnuinetutils>= 0 < 2:1.9.2.39.3a460-12:1.9.2.39.3a460-1
gnuinetutils>= 0 < 2:1.9.2.39.3a460-12:1.9.2.39.3a460-1
gnuinetutils>= 0 < 2:1.9.2.39.3a460-12:1.9.2.39.3a460-1
rsyslogrsyslog<= 7.6.5
rsyslogrsyslog<= 7.6.6
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog
rsyslogrsyslog

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.