← Vulnerability feed

Vulnerability record · CVE-2014-3634 · published 2 November 2014

CVE-2014-3634: Sysklogd project sysklogd memory buffer overflow vulnerability

SSysklogd Project · Sysklogd

rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.

7.5 CVSS 2.0 High EPSS 7.5% · top 5.7% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
7.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
36References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://advisories.mageia.org/MGASA-2014-0411.html
http://linux.oracle.com/errata/ELSA-2014-1654
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00005.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00020.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00021.html
http://rhn.redhat.com/errata/RHSA-2014-1397.html
http://rhn.redhat.com/errata/RHSA-2014-1654.html
http://rhn.redhat.com/errata/RHSA-2014-1671.html
http://secunia.com/advisories/61494
http://secunia.com/advisories/61720
http://secunia.com/advisories/61930
http://www.debian.org/security/2014/dsa-3040
http://www.mandriva.com/security/advisories?name=MDVSA-2015:130
http://www.openwall.com/lists/oss-security/2014/09/30/15
http://www.openwall.com/lists/oss-security/2014/10/03/1 Patch
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.rsyslog.com/remote-syslog-pri-vulnerability/ ExploitPatchVendor Advisory
http://www.ubuntu.com/usn/USN-2381-1
http://advisories.mageia.org/MGASA-2014-0411.html
http://linux.oracle.com/errata/ELSA-2014-1654
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00005.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00020.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00021.html
http://rhn.redhat.com/errata/RHSA-2014-1397.html
http://rhn.redhat.com/errata/RHSA-2014-1654.html
http://rhn.redhat.com/errata/RHSA-2014-1671.html
http://secunia.com/advisories/61494
http://secunia.com/advisories/61720
http://secunia.com/advisories/61930
http://www.debian.org/security/2014/dsa-3040
http://www.mandriva.com/security/advisories?name=MDVSA-2015:130
http://www.openwall.com/lists/oss-security/2014/09/30/15
http://www.openwall.com/lists/oss-security/2014/10/03/1 Patch
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.rsyslog.com/remote-syslog-pri-vulnerability/ ExploitPatchVendor Advisory
http://www.ubuntu.com/usn/USN-2381-1

Track CVE-2014-3634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-17041Rsyslog out-of-bounds write vulnerabilityAn issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages.…EPSS 4.4%9.8CVE-2019-17042Rsyslog improper input validation vulnerabilityAn issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parse…EPSS 3.1%9.8CVE-2019-17040Rsyslog out-of-bounds read vulnerabilitycontrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.EPSS 2.4%9.8CVE-2017-12588Rsyslog vulnerabilityThe zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack…EPSS 2.8%8.5CVE-2008-5617Rsyslog permissions and access controls vulnerabilityThe ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass inte…EPSS 2.2%8.1CVE-2022-24903Rsyslog classic buffer overflow vulnerabilityRsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing…EPSS 3.9%7.5CVE-2026-19654Rsyslog out-of-bounds read vulnerabilityA unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame …EPSS 0.47%7.5CVE-2018-16881Rsyslog integer overflow vulnerabilityA denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket,…EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2014-3634), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.