CVE-2018-16881
published 2019-01-25CVE-2018-16881: A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.24%
80.9th percentile
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rsyslog | < rsyslog 8.27.0-2 (bookworm) | rsyslog 8.27.0-2 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_scientific_computing | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization | — | — |
| redhat | virtualization_host | — | — |
| redhat | virtualization_manager | — | — |
| rsyslog | rsyslog | < 8.27.0 | 8.27.0 |
| rsyslog | rsyslog | >= 0 < 8.27.0-2 | 8.27.0-2 |
| rsyslog | rsyslog | >= 0 < 8.27.0-2 | 8.27.0-2 |
| rsyslog | rsyslog | >= 0 < 8.27.0-2 | 8.27.0-2 |
| rsyslog | rsyslog | >= 0 < 8.27.0-2 | 8.27.0-2 |
| the_rsyslog_project | rsyslog | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Rsyslog vulnerabilities
vendor_ubuntu·2022-05-12
CVE-2018-16881 Rsyslog vulnerabilities
Title: Rsyslog vulnerabilities
Summary: Rsyslog could be made to crash if it received specially crafted input.
It was discovered that Rsyslog improperly handled certain invalid input. An
attacker could use this issue to cause Rsyslog to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-16881: rsyslog - A denial of service vulnerability was found in rsyslog in the imptcp module. An ...
vendor_debian·2018·CVSS 7.5
CVE-2018-16881 [HIGH] CVE-2018-16881: rsyslog - A denial of service vulnerability was found in rsyslog in the imptcp module. An ...
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
Scope: local
bookworm: resolved (fixed in 8.27.0-2)
bullseye: resolved (fixed in 8.27.0-2)
forky: resolved (fixed in 8.27.0-2)
sid: resolved (fixed in 8.27.0-2)
trixie: resolved (fixed in 8.27.0-2)
Red Hat
rsyslog: imptcp: integer overflow when Octet-Counted TCP Framing is enabled
vendor_redhat·2017-04-19·CVSS 7.5
CVE-2018-16881 [HIGH] CWE-190 rsyslog: imptcp: integer overflow when Octet-Counted TCP Framing is enabled
rsyslog: imptcp: integer overflow when Octet-Counted TCP Framing is enabled
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash.
Mitigation: This vulnerability requires the "imptcp" module to be enabled, and listening on a port that can potentially be reached by attackers. This module is not enabled by default in Red Hat Enterprise Linux 7. To check if imptcp is enabled, look for the string `$InputPTCPServerRun`in your rsyslog configur
GHSA
GHSA-hg54-w573-5vvv: A denial of service vulnerability was found in rsyslog in the imptcp module
ghsa_unreviewed·2022-05-13
CVE-2018-16881 [HIGH] CWE-190 GHSA-hg54-w573-5vvv: A denial of service vulnerability was found in rsyslog in the imptcp module
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
OSV
CVE-2018-16881: A denial of service vulnerability was found in rsyslog in the imptcp module
osv·2019-01-25·CVSS 7.5
CVE-2018-16881 [HIGH] CVE-2018-16881: A denial of service vulnerability was found in rsyslog in the imptcp module
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHBA-2019:2501https://access.redhat.com/errata/RHSA-2019:2110https://access.redhat.com/errata/RHSA-2019:2437https://access.redhat.com/errata/RHSA-2019:2439https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16881https://lists.debian.org/debian-lts-announce/2022/05/msg00028.htmlhttps://access.redhat.com/errata/RHBA-2019:2501https://access.redhat.com/errata/RHSA-2019:2110https://access.redhat.com/errata/RHSA-2019:2437https://access.redhat.com/errata/RHSA-2019:2439https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16881https://lists.debian.org/debian-lts-announce/2022/05/msg00028.html
2019-01-25
Published