CVE-2014-3683
Publication date 2 October 2014
Last updated 24 July 2024
Ubuntu priority
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
Status
Package | Ubuntu Release | Status |
---|---|---|
rsyslog | ||
16.04 LTS xenial |
Fixed 7.4.4-1ubuntu11
|
|
14.04 LTS trusty |
Fixed 7.4.4-1ubuntu2.3
|
|
sysklogd | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2381-1
- Rsyslog vulnerabilities
- 9 October 2014