Back
CVE-2018-1000140
CRITICAL
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
Published: Mar 23, 2018
Modified: Jun 17, 2026
CWE-787
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (25)
| Vendor | Product | Version |
|---|---|---|
| rsyslog | librelp | * |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| canonical | ubuntu_linux | 14.04 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 6.6 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 6.7 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_tus | 6.6 |
| redhat | enterprise_linux_server_tus | 7.2 |
…and 5 more
GitHub Security Advisory GHSA-m73v-c2p6-943p
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the...
References (26)
- http://packetstormsecurity.com/files/172829/librelp-Remote-Code-Execution.html
- https://access.redhat.com/errata/RHSA-2018:1223 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1225 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1701 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1702 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1703 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1704 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1707 Third Party Advisory
- https://github.com/rsyslog/librelp/blob/532aa362f0f7a8d037505b0a27a1df452f9bac9e/src/tcp.c#L1205 Patch, Third Party Advisory
- https://lgtm.com/rules/1505913226124/ Exploit, Third Party Advisory
- https://security.gentoo.org/glsa/201804-21 Third Party Advisory
- https://usn.ubuntu.com/3612-1/ Third Party Advisory
- https://www.debian.org/security/2018/dsa-4151 Third Party Advisory
- http://packetstormsecurity.com/files/172829/librelp-Remote-Code-Execution.html
- https://access.redhat.com/errata/RHSA-2018:1223 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
9.52%
Top 5% most likely to be exploited
Threat Score
42.1 / 100
Data Sources
NVD
EPSS
GitHub