A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
2019-01-25T18:29:00.257
2024-11-21T03:53:31.293
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rsyslog | rsyslog | < 8.27.0 | Yes |
Application | redhat | virtualization_manager | 4.3 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_big_endian | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 7.0 | Yes |
Operating System | redhat | enterprise_linux_for_scientific_computing | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | redhat | virtualization | 4.0 | Yes |
Application | redhat | virtualization_host | 4.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | debian | debian_linux | 9.0 | Yes |