Logo
vulnerabilityCVE-2022-38725
Name
CVE-2022-38725
Source
NVD ( link)Debian ( link)
Description
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
syslog-ng
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
4.11.0
Exploitable
openwrt
master
4.11.0-r1
Exploitable
openwrt
openwrt-25.12
4.11.0-r1
Exploitable
yocto
kirkstone
3.36.1
Exploitable
yocto
master
4.11.0
False Positive
yocto
scarthgap
4.6.0
False Positive