CVE-2022-38725

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
23/01/2023
Last modified:
03/04/2025

Description

An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:-:*:*:* 3.38.1 (excluding)
cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:premium:*:*:* 7.0.32 (excluding)
cpe:2.3:a:oneidentity:syslog-ng_store_box:*:*:*:*:-:*:*:* 6.0.5 (excluding)
cpe:2.3:a:oneidentity:syslog-ng_store_box:*:*:*:*:lts:*:*:* 7.0 (excluding)