CVE-2018-16881: Integer Overflow
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash.
Other sources
An issue was found in rsyslog. When imtcp module and Octet-Counted TCP Framing ("on" by default) are enabled, Rsyslog can be crashed remotely when sending an crafted (improperly formatted) message to "imptcp" listening socket.
Upstream Patch: https://github.com/rsyslog/rsyslog/commit/0381a0de64a5a048c3d48b79055bd9848d0c7fc2
— Red Hat
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-16881?
CVE-2018-16881 is classified as a denial of service vulnerability, which can cause the rsyslog service to crash.
How do I fix CVE-2018-16881?
To fix CVE-2018-16881, upgrade rsyslog to version 8.27.0 or later.
Which versions of rsyslog are affected by CVE-2018-16881?
Versions prior to 8.27.0 of rsyslog are affected by CVE-2018-16881.
What can an attacker do with CVE-2018-16881?
An attacker can potentially crash the rsyslog service by sending specially crafted messages to the imptcp socket.
Is CVE-2018-16881 a remote vulnerability?
Yes, CVE-2018-16881 can be exploited remotely by sending malicious data to the vulnerable rsyslog service.