Back

CRITICAL

librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c

Published Mar 23, 2018

Description

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

Affected products

Remediation

Red Hat mitigation

Users are strongly advised not to expose their logging RELP services to a public network.

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 23, 2018
Updated Aug 5, 2024
Reserved Mar 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Mar 23, 2018