CVE-2014-3634: Rsyslog
High severity, CVSS 7.5. EPSS: 7.5% chance of exploitation in the next 30 days.
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an out-of-bounds array access.
Affected products
- Rsyslog Rsyslog: up to and including 7.6.5; version 8.1.0 only; version 8.1.1 only; version 8.1.2 only; version 8.1.3 only; version 8.1.4 only; …
- Sysklogd Project Sysklogd: up to and including 1.5; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.4.1 only
Published 2014-11-02. Last modified 2026-06-17.