Lucene search

K
broadcomBroadcom Security ResponseBSNSA21215
HistoryNov 08, 2022 - 12:00 a.m.

CVE-2022-24903: A flaw in rsyslog TCP module could allow an attacker to craft a malicious message leading to a heap-based buffer overflow. (BSA-2022-2127)

2022-11-0800:00:00
Broadcom Security Response
support.broadcom.com
12
rsyslog
remote code execution
input data validation
software vulnerability
heap-based buffer overflow

AI Score

8

Confidence

Low

EPSS

0.191

Percentile

96.3%

Security Advisory ID: BSA-2022-2127

Component: Rsyslog

Revision: 1.0

Rsyslog is vulnerable to remote code execution (RCE) due to improper validation of input data when octet-counted framing is used. An attacker could exploit this vulnerability by supplying a system with maliciously crafted messages.