Input validation error in rsyslog - CVE-2018-16881
Published: February 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists in the imptcp module due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted message to the imptcp socket that submits malicious input and cause the affected software to crash, resulting in a DoS condition.
Affected software
VMware Tanzu Application Service for VMs
Isolation Segment
Red Hat Virtualization
Red Hat Virtualization Host
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Ubuntu
Opensuse
rsyslog (Ubuntu package)
How to mitigate CVE-2018-16881
rsyslog (Ubuntu package) - update to 8.16.01ubuntu3.1+esm1