Integer overflow in One Identity products - CVE-2022-38725
Published: February 13, 2023
Vulnerability identifier: #VU72142
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38725
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in the RFC3164 parser. A remote attacker can send specially crafted data to the service, trigger an integer overflow and perform a denial of service (DoS) attack.
Affected software
syslog-ng
syslog-ng Store Box
syslog-ng Premium Edition
Debian Linux
Gentoo Linux
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
IBM Qradar SIEM
syslog-ng
syslog-ng-debuginfo
syslog-ng-debugsource
syslog-ng (Debian package)
app-admin/syslog-ng
IBM QRadar Incident Forensics
syslog-ng Store Box
syslog-ng Premium Edition
Debian Linux
Gentoo Linux
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
IBM Qradar SIEM
syslog-ng
syslog-ng-debuginfo
syslog-ng-debugsource
syslog-ng (Debian package)
app-admin/syslog-ng
IBM QRadar Incident Forensics
How to mitigate CVE-2022-38725
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
syslog-ng - update to 3.38.1
syslog-ng Store Box - update to 7.0.0
syslog-ng Premium Edition - update to 7.0.32
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
syslog-ng - update to 3.6.4-12.11.1
syslog-ng-debuginfo - update to 3.6.4-12.11.1
syslog-ng-debugsource - update to 3.6.4-12.11.1
syslog-ng - addressed in versions 3.23.1-3.el8, 3.35.1-4.fc36, 3.35.1-6.el9, 3.37.1-2.fc37
syslog-ng (Debian package) - update to 3.28.1-2+deb11u1
app-admin/syslog-ng - update to 3.38.1
IBM QRadar Incident Forensics - update to 7.5.0.10
syslog-ng Store Box - update to 7.0.0
syslog-ng Premium Edition - update to 7.0.32
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
syslog-ng - update to 3.6.4-12.11.1
syslog-ng-debuginfo - update to 3.6.4-12.11.1
syslog-ng-debugsource - update to 3.6.4-12.11.1
syslog-ng - addressed in versions 3.23.1-3.el8, 3.35.1-4.fc36, 3.35.1-6.el9, 3.37.1-2.fc37
syslog-ng (Debian package) - update to 3.28.1-2+deb11u1
app-admin/syslog-ng - update to 3.38.1
IBM QRadar Incident Forensics - update to 7.5.0.10
External References
Related Security Bulletins
- Denial of service in syslog-ng
- SUSE update for syslog-ng
- Debian update for syslog-ng
- Gentoo update for syslog-ng
- Fedora 37 update for syslog-ng
- Fedora 36 update for syslog-ng
- Fedora EPEL 9 update for syslog-ng
- Fedora EPEL 8 update for syslog-ng
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics