Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-38725


An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.


Published

2023-01-23T16:15:10.567

Last Modified

2025-04-03T15:15:42.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-190
  • Type: Secondary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oneidentity syslog-ng < 3.38.1 Yes
Application oneidentity syslog-ng < 7.0.32 Yes
Application oneidentity syslog-ng_store_box < 6.0.5 Yes
Application oneidentity syslog-ng_store_box < 7.0 Yes

References