CVE-2022-38725
Title: Oneidentity Syslog-Ng Memory Corruption
Memory Corruption
Proof Of Concept
PoC Available for CVE-2022-38725
CWE Category
CWE-190
Published Date
Jan 23, 2023
Modified Date
Apr 03, 2025
Exploit Status
Available
Score
7.5
CVSS v3.1
Exploit Probability (EPSS)
2.38%
Vulnerability Summary
CVE-2022-38725: An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
Impacted Vendors
Reference Links
https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-7932-4fc6-pvmc
https://lists.balabit.hu/pipermail/syslog-ng/
https://lists.debian.org/debian-lts-announce/2023/02/msg00043.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3TZ7U2GQTAHVHJXSSEHQS5D2Q5T6SZB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU36HCM3VZYANUYFC6XFYEYJEKQPA2Q7/
https://security.gentoo.org/glsa/202305-09
https://www.debian.org/security/2023/dsa-5369
https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-7932-4fc6-pvmc
https://lists.balabit.hu/pipermail/syslog-ng/
https://lists.debian.org/debian-lts-announce/2023/02/msg00043.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3TZ7U2GQTAHVHJXSSEHQS5D2Q5T6SZB/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU36HCM3VZYANUYFC6XFYEYJEKQPA2Q7/
https://security.gentoo.org/glsa/202305-09
https://www.debian.org/security/2023/dsa-5369
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v3.1
Source Entity
134c704f-9b21-4f2e-91b3-4a467353bcc0
Severity
HIGH
7.5
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
UNCHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2022-38725 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/wdahlenburg/CVE-2022-38725
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Stack
No specific products linked.