Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-38725
HistoryJan 23, 2023 - 12:00 a.m.

CVE-2022-38725

2023-01-2300:00:00
ubuntu.com
ubuntu.com
33
integer overflow
one identity syslog-ng
dos
tcp mishandling
cve-2022-38725
rfc3164
syslog-ng premium edition 7.0.30
syslog-ng store box 6.10.0
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.015

Percentile

87.1%

An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0
through 3.37 allows remote attackers to cause a Denial of Service via
crafted syslog input that is mishandled by the tcp or network function.
syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also
affected.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.015

Percentile

87.1%