CVE-2014-3634
published 2014-11-02CVE-2014-3634: rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.55%
93.9th percentile
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | inetutils | < inetutils 2:1.9.2.39.3a460-1 (bookworm) | inetutils 2:1.9.2.39.3a460-1 (bookworm) |
| debian | rsyslog | < inetutils 2:1.9.2.39.3a460-1 (bookworm) | inetutils 2:1.9.2.39.3a460-1 (bookworm) |
| debian | rsyslog | < rsyslog 8.4.2-1 (bookworm) | rsyslog 8.4.2-1 (bookworm) |
| gnu | inetutils | >= 0 < 2:1.9.2.39.3a460-1 | 2:1.9.2.39.3a460-1 |
| gnu | inetutils | >= 0 < 2:1.9.2.39.3a460-1 | 2:1.9.2.39.3a460-1 |
| gnu | inetutils | >= 0 < 2:1.9.2.39.3a460-1 | 2:1.9.2.39.3a460-1 |
| gnu | inetutils | >= 0 < 2:1.9.2.39.3a460-1 | 2:1.9.2.39.3a460-1 |
| rsyslog | rsyslog | <= 7.6.5 | — |
| rsyslog | rsyslog | <= 7.6.6 | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
| rsyslog | rsyslog | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Rsyslog vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 7.5
CVE-2014-3634 [HIGH] Rsyslog vulnerabilities
Title: Rsyslog vulnerabilities
Summary: Rsyslog could be made to crash if it received specially crafted input.
It was discovered that Rsyslog incorrectly handled invalid PRI values. An
attacker could use this issue to send malformed messages to the Rsyslog
server and cause it to stop responding, resulting in a denial of service
and possibly message loss. (CVE-2014-3634, CVE-2014-3683)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rsyslog: integer overflow in PRI parsing
vendor_redhat·2014-10-02·CVSS 7.5
CVE-2014-3683 [HIGH] CWE-190 rsyslog: integer overflow in PRI parsing
rsyslog: integer overflow in PRI parsing
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
Statement: This issue did not affect the versions of sysklogd and rsyslog packages as shipped with Red Hat Enterprise Linux 5, 6, and7.
Package: rsyslog (Red Hat Enterprise Linux 5) - Not affected
Package: rsyslog5 (Red Hat Enterprise Linux 5) - Not affected
Package: sysklogd (Red Hat Enterprise Linux 5) - Not affected
Package: rsyslog (Red Hat Enterprise Linux 6) - Not affected
Package: rsyslog7 (Red Hat Enterprise Linux 6) - Not affected
Package: rsyslog (Red Hat Enterprise Linu
Red Hat
rsyslog: remote syslog PRI vulnerability
vendor_redhat·2014-09-30·CVSS 7.5
CVE-2014-3634 [HIGH] CWE-129 rsyslog: remote syslog PRI vulnerability
rsyslog: remote syslog PRI vulnerability
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
A flaw was found in the way rsyslog handled invalid log message priority values. In certain configurations, a local attacker, or a remote attacker able to connect to the rsyslog port, could use this flaw to crash the rsyslog daemon or, potentially in rsyslog 7.x, execute arbitrary code as the user running the rsyslog daemon.
Package: rsyslog (Red Hat Enterprise Linux 5) - Will not fix
Package: sysklogd (Red Hat Enterprise Linux 5) - Will not fix
Package: rsyslog7 (Red Ha
Debian
CVE-2014-3634: inetutils - rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows re...
vendor_debian·2014·CVSS 7.5
CVE-2014-3634 [HIGH] CVE-2014-3634: inetutils - rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows re...
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
Scope: local
bookworm: resolved (fixed in 2:1.9.2.39.3a460-1)
bullseye: resolved (fixed in 2:1.9.2.39.3a460-1)
forky: resolved (fixed in 2:1.9.2.39.3a460-1)
sid: resolved (fixed in 2:1.9.2.39.3a460-1)
trixie: resolved (fixed in 2:1.9.2.39.3a460-1)
Debian
CVE-2014-3683: rsyslog - Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 a...
vendor_debian·2014·CVSS 7.5
CVE-2014-3683 [HIGH] CVE-2014-3683: rsyslog - Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 a...
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
Scope: local
bookworm: resolved (fixed in 8.4.2-1)
bullseye: resolved (fixed in 8.4.2-1)
forky: resolved (fixed in 8.4.2-1)
sid: resolved (fixed in 8.4.2-1)
trixie: resolved (fixed in 8.4.2-1)
GHSA
GHSA-h4gg-9gq4-7c4h: rsyslog before 7
ghsa_unreviewed·2022-05-17
CVE-2014-3634 [HIGH] CWE-119 GHSA-h4gg-9gq4-7c4h: rsyslog before 7
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
GHSA
GHSA-cj25-wc2v-fhxm: Integer overflow in rsyslog before 7
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-3683 [HIGH] GHSA-cj25-wc2v-fhxm: Integer overflow in rsyslog before 7
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
OSV
CVE-2014-3683: Integer overflow in rsyslog before 7
osv·2014-11-02·CVSS 7.5
CVE-2014-3683 [HIGH] CVE-2014-3683: Integer overflow in rsyslog before 7
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
OSV
CVE-2014-3634: rsyslog before 7
osv·2014-11-02·CVSS 7.5
CVE-2014-3634 [HIGH] CVE-2014-3634: rsyslog before 7
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
OSV
rsyslog vulnerabilities
osv·2014-10-09·CVSS 7.5
CVE-2014-3634 [HIGH] rsyslog vulnerabilities
rsyslog vulnerabilities
It was discovered that Rsyslog incorrectly handled invalid PRI values. An
attacker could use this issue to send malformed messages to the Rsyslog
server and cause it to stop responding, resulting in a denial of service
and possibly message loss. (CVE-2014-3634, CVE-2014-3683)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3683 rsyslog: integer overflow in PRI parsing
bugzilla·2014-10-03·CVSS 7.5
CVE-2014-3683 [HIGH] CVE-2014-3683 rsyslog: integer overflow in PRI parsing
CVE-2014-3683 rsyslog: integer overflow in PRI parsing
An integer overflow flaw was found in the way rsyslog and sysklogd daemons parsed PRI (priority value, that combines values for facility (such as mail, cron, or authpriv) and severity/level (such as crit, info, debug)) values form the log message provided to the syslog daemon. This problem could lead to bypass of the CVE-2014-3634 (bug 1142373) fix.
The rsyslog upstream fixed this issue in version 7.6.7 and 8.4.2:
http://lists.adiscon.net/pipermail/rsyslog/2014-October/038516.html
http://lists.adiscon.net/pipermail/rsyslog/2014-October/038515.html
A proposed fix for sysklogd is attached in bug 1142373 comment 16.
Acknowledgment:
Red Hat would like to thank the rsyslog upstream for reporting this issue. Upstream acknowledges manch
Bugzilla
CVE-2014-3634 sysklogd: rsyslog: remote syslog PRI vulnerability [fedora-all]
bugzilla·2014-10-02·CVSS 7.5
CVE-2014-3634 [HIGH] CVE-2014-3634 sysklogd: rsyslog: remote syslog PRI vulnerability [fedora-all]
CVE-2014-3634 sysklogd: rsyslog: remote syslog PRI vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2014-3634 rsyslog: remote syslog PRI vulnerability [fedora-all]
bugzilla·2014-10-02·CVSS 7.5
CVE-2014-3634 [HIGH] CVE-2014-3634 rsyslog: remote syslog PRI vulnerability [fedora-all]
CVE-2014-3634 rsyslog: remote syslog PRI vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2014-3634 rsyslog: remote syslog PRI vulnerability
bugzilla·2014-09-16·CVSS 7.5
CVE-2014-3634 [HIGH] CVE-2014-3634 rsyslog: remote syslog PRI vulnerability
CVE-2014-3634 rsyslog: remote syslog PRI vulnerability
A flaw was reported in rsyslogd, as well as sysklogd from which it was forked, that could lead to a denial of service for rsyslogd daemons that collect remote logs from untrusted sources.
In syslog.h, LOG_NFACILITIES is used to size arrays for facility processing. In sysklogd, this is used by an array for selector matching; in rsyslogd an additional array is used. The LOG_FAC() macro is used to extract the facility from a syslog PRI, which is used to address the arrays. Unfortunately, the LG_FACMASK permits values up to 0x3f8 (1016 dec), which translates to 128 facilities. As a result, any PRI values above 191 cause the LOG_NFACILITIES arrays to be overrun.
If a remote attacker is able to send unconditional data to the logging serve
http://advisories.mageia.org/MGASA-2014-0411.htmlhttp://linux.oracle.com/errata/ELSA-2014-1654http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1397.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1654.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1671.htmlhttp://secunia.com/advisories/61494http://secunia.com/advisories/61720http://secunia.com/advisories/61930http://www.debian.org/security/2014/dsa-3040http://www.mandriva.com/security/advisories?name=MDVSA-2015:130http://www.openwall.com/lists/oss-security/2014/09/30/15http://www.openwall.com/lists/oss-security/2014/10/03/1http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.rsyslog.com/remote-syslog-pri-vulnerability/http://www.ubuntu.com/usn/USN-2381-1http://advisories.mageia.org/MGASA-2014-0411.htmlhttp://linux.oracle.com/errata/ELSA-2014-1654http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00020.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1397.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1654.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1671.htmlhttp://secunia.com/advisories/61494http://secunia.com/advisories/61720http://secunia.com/advisories/61930http://www.debian.org/security/2014/dsa-3040http://www.mandriva.com/security/advisories?name=MDVSA-2015:130http://www.openwall.com/lists/oss-security/2014/09/30/15http://www.openwall.com/lists/oss-security/2014/10/03/1http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.rsyslog.com/remote-syslog-pri-vulnerability/http://www.ubuntu.com/usn/USN-2381-1
2014-11-02
Published