CVE-2018-16881

A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
rsyslogrsyslog
𝑥
< 8.27.0
redhatvirtualization_manager
4.3
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_for_ibm_z_systems
7.0
redhatenterprise_linux_for_power_big_endian
7.0
redhatenterprise_linux_for_power_little_endian
7.0
redhatenterprise_linux_for_scientific_computing
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
redhatvirtualization
4.0
redhatvirtualization_host
4.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rsyslog
bookworm
8.2302.0-1
fixed
bullseye
8.2102.0-2+deb11u1
fixed
bullseye (security)
8.2102.0-2+deb11u1
fixed
jessie
not-affected
sid
8.2410.0-1
fixed
trixie
8.2410.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rsyslog
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
needed
xenial
Fixed 8.16.0-1ubuntu3.1+esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
rsyslog
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-diag-tools
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-doc
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-gssapi
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-gtls
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-mmnormalize
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-mysql
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-pgsql
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-relp
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-snmp
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
rsyslog-module-udpspoof
suse enterprise sap 12 SP3
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP4
8.24.0-3.19.1
fixed
suse enterprise sap 12 SP5
8.24.0-3.28.2
fixed
suse enterprise server 12 SP3
8.24.0-3.19.1
fixed
suse enterprise server 12 SP4
8.24.0-3.19.1
fixed
suse enterprise server 12 SP5
8.24.0-3.28.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
rsyslog
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-crypto
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-doc
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-elasticsearch
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-gnutls
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-gssapi
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-kafka
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-libdbi
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mmaudit
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mmjsonparse
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mmkubernetes
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mmnormalize
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mmsnmptrapd
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-mysql
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-pgsql
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-relp
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-snmp
RHEL 7
0:8.24.0-38.el7
fixed
rsyslog-udpspoof
RHEL 7
0:8.24.0-38.el7
fixed