librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c
Published Mar 23, 2018
9.8
CRITICALCVSS 3.0
EPSS 9.34%
Description
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
Affected products
No data.
Configuration 2
- 8.0
- 9.0
Configuration 3
- 14.04
Configuration 4
- 6.0
- 7.0
- 6.0
- 7.0
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 6.7
- 7.3
- 7.4
- 7.5
- 7.6
- 6.6
- 7.2
- 7.3
- 7.4
- 7.6
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6
librelp-0:1.2.7-3.el6_9.1
Fixed · RHSA-2018:1225
Red Hat Enterprise Linux 6.6 Advanced Update Support
librelp-0:1.2.7-3.el6_6.1
Fixed · RHSA-2018:1701
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
librelp-0:1.2.7-3.el6_6.1
Fixed · RHSA-2018:1701
Red Hat Enterprise Linux 6.7 Extended Update Support
librelp-0:1.2.7-3.el6_7.1
Fixed · RHSA-2018:1702
Red Hat Enterprise Linux 7
librelp-0:1.2.12-1.el7_5.1
Fixed · RHSA-2018:1223
Red Hat Enterprise Linux 7.2 Advanced Update Support
librelp-0:1.2.0-4.el7_2
Fixed · RHSA-2018:1703
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
librelp-0:1.2.0-4.el7_2
Fixed · RHSA-2018:1703
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
librelp-0:1.2.0-4.el7_2
Fixed · RHSA-2018:1703
Red Hat Enterprise Linux 7.3 Extended Update Support
librelp-0:1.2.0-4.el7_3
Fixed · RHSA-2018:1707
Red Hat Enterprise Linux 7.4 Extended Update Support
librelp-0:1.2.12-1.el7_4.1
Fixed · RHSA-2018:1704
Red Hat Enterprise Linux 8
librelp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | librelp-0:1.2.7-3.el6_9.1 | Fixed | RHSA-2018:1225 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | librelp-0:1.2.7-3.el6_6.1 | Fixed | RHSA-2018:1701 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | librelp-0:1.2.7-3.el6_6.1 | Fixed | RHSA-2018:1701 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | librelp-0:1.2.7-3.el6_7.1 | Fixed | RHSA-2018:1702 |
| Red Hat Enterprise Linux 7 | librelp-0:1.2.12-1.el7_5.1 | Fixed | RHSA-2018:1223 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | librelp-0:1.2.0-4.el7_2 | Fixed | RHSA-2018:1703 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | librelp-0:1.2.0-4.el7_2 | Fixed | RHSA-2018:1703 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | librelp-0:1.2.0-4.el7_2 | Fixed | RHSA-2018:1703 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | librelp-0:1.2.0-4.el7_3 | Fixed | RHSA-2018:1707 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | librelp-0:1.2.12-1.el7_4.1 | Fixed | RHSA-2018:1704 |
| Red Hat Enterprise Linux 8 | librelp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Users are strongly advised not to expose their logging RELP services to a public network.
References (18)
- http://packetstormsecurity.com/files/172829/librelp-Remote-Code-Execution.html
- https://access.redhat.com/errata/RHSA-2018:1223 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1225 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1701 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1702 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1703 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1704 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1707 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000140 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1560084 Issue Tracking
- https://github.com/rsyslog/librelp/blob/532aa362f0f7a8d037505b0a27a1df452f9bac9e/src/tcp.c#L1205 PatchThird Party Advisory
- https://lgtm.com/rules/1505913226124/ ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000140
- https://security.gentoo.org/glsa/201804-21 vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/3612-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1000140
- https://www.debian.org/security/2018/dsa-4151 vendor-advisoryThird Party Advisory
- https://www.rsyslog.com/cve-2018-1000140/
Change history (0)
No recorded changes yet.