Integer overflow in One Identity products - CVE-2022-38725

 

Integer overflow in One Identity products - CVE-2022-38725

Published: February 13, 2023


Vulnerability identifier: #VU72142
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38725
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in the RFC3164 parser. A remote attacker can send specially crafted data to the service, trigger an integer overflow and perform a denial of service (DoS) attack.


Affected software

syslog-ng
syslog-ng Store Box
syslog-ng Premium Edition
Debian Linux
Gentoo Linux
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
IBM Qradar SIEM
syslog-ng
syslog-ng-debuginfo
syslog-ng-debugsource
syslog-ng (Debian package)
app-admin/syslog-ng
IBM QRadar Incident Forensics

How to mitigate CVE-2022-38725

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

syslog-ng - update to 3.38.1
syslog-ng Store Box - update to 7.0.0
syslog-ng Premium Edition - update to 7.0.32
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
syslog-ng - update to 3.6.4-12.11.1
syslog-ng-debuginfo - update to 3.6.4-12.11.1
syslog-ng-debugsource - update to 3.6.4-12.11.1
syslog-ng - addressed in versions 3.23.1-3.el8, 3.35.1-4.fc36, 3.35.1-6.el9, 3.37.1-2.fc37
syslog-ng (Debian package) - update to 3.28.1-2+deb11u1
app-admin/syslog-ng - update to 3.38.1
IBM QRadar Incident Forensics - update to 7.5.0.10

External References

Related Security Bulletins