CVE-2014-3683: Rsyslog
Medium severity, CVSS 5.0. EPSS: 4.6% chance of exploitation in the next 30 days.
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.
Affected products
- Rsyslog Rsyslog: up to and including 7.6.6; version 8.1.0 only; version 8.1.1 only; version 8.1.2 only; version 8.1.3 only; version 8.1.4 only; …
- Sysklogd Project Sysklogd: up to and including 1.5; version 1.1 only; version 1.2 only; version 1.3 only; version 1.4 only; version 1.4.1 only
Published 2014-11-02. Last modified 2026-06-17.