Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 23 Mar 2018 12:44:09 -0600
From: Kurt Seifried <>
To: oss-security <>
Subject: CVE-2018-1000140 - rsyslog librelp X.509 parsing issue

This was embargoed but then it got sent to the PUBLIC cve request page, so
the cat is out of the bag as it were, so notifying oss-sec.

librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability
in the checking of x509 certificates from a peer that can result in Remote
code execution. This attack appear to be exploitable a remote attacker that
can connect to rsyslog and trigger a stack buffer overflow by sending a
specially crafted x509

Kurt Seifried -- Red Hat -- Product Security -- Cloud
PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Red Hat Product Security contact:

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.