CVE-2014-3683
Publication date 2 October 2014
Last updated 24 July 2024
Ubuntu priority
Description
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rsyslog | ||
| 16.04 LTS xenial |
Fixed 7.4.4-1ubuntu11
|
|
| 14.04 LTS trusty |
Fixed 7.4.4-1ubuntu2.3
|
|
| sysklogd | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2381-1
- Rsyslog vulnerabilities
- 9 October 2014