CVE-2018-1000140
CRITICALrsyslog librelp <1.2.14 - Buffer Overflow
Title source: llmDescription
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
Exploits (2)
References (13)
Scores
CVSS v3
9.8
EPSS
0.2716
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (25)
canonical/ubuntu_linux
14.04
debian/debian_linux
8.0
debian/debian_linux
9.0
redhat/enterprise_linux_desktop
6.0
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_server
6.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_server_aus
6.6
redhat/enterprise_linux_server_aus
7.2
redhat/enterprise_linux_server_aus
7.3
... and 15 more
Published
Mar 23, 2018
Tracked Since
Feb 18, 2026