CVE-2014-3634
Publication date 1 October 2014
Last updated 24 July 2024
Ubuntu priority
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
Status
Package | Ubuntu Release | Status |
---|---|---|
rsyslog | ||
16.04 LTS xenial |
Fixed 7.4.4-1ubuntu11
|
|
14.04 LTS trusty |
Fixed 7.4.4-1ubuntu2.3
|
|
sysklogd | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Notes
Patch details
Package | Patch details |
---|---|
rsyslog |
References
Related Ubuntu Security Notices (USN)
- USN-2381-1
- Rsyslog vulnerabilities
- 9 October 2014