CVE-2022-38725
Published on: Not Yet Published
Last Modified on: 01/23/2023 05:17:00 PM UTC
The following vulnerability was found:
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
- CVE-2022-38725 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
An integer overflow in the RFC3164 parser allows remote attackers Denial of Service · Advisory · syslog-ng/syslog-ng · GitHub | github.com text/html |
![]() |
The syslog-ng Archives | lists.balabit.hu text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause…
There are no known software configurations (CPEs) currently associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38725 : An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote… twitter.com/i/web/status/1… | 2023-01-23 16:05:07 |
![]() |
CVE-2022-38725 | 2023-01-23 16:40:19 |