← Back

CVE-2014-3683

nvd nist
Published: Nov 2, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

Affected (26)

1 product
Rsyslog
Sysklogd
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Rsyslog
Up to 7.6.6
Version 8.1.0
Version 8.1.1
Version 8.1.2
Version 8.1.3
Version 8.1.4
Version 8.1.5
Version 8.1.6
Version 8.2.0
Version 8.2.1
Version 8.2.2
Version 8.2.3
Version 8.3.0
Version 8.3.1
Version 8.3.2
Version 8.3.3
Version 8.3.4
Version 8.3.5
Version 8.4.0
Version 8.4.1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Sysklogd Project
Up to 1.5
Version 1.1
Version 1.2
Version 1.3
Version 1.4.1
Version 1.4

Related CWEs

References (20)

Source: secalert@redhat.com
Source: secalert@redhat.com
ExploitPatchVendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.