High severity7.5NVD Advisory· Published Jan 23, 2023· Updated Jun 17, 2026
CVE-2022-38725
CVE-2022-38725
Description
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:-:*:*:*range: <3.38.1
- cpe:2.3:a:oneidentity:syslog-ng:*:*:*:*:premium:*:*:*range: <7.0.32
- (no CPE)range: 3.0-3.37
cpe:2.3:a:oneidentity:syslog-ng_store_box:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:oneidentity:syslog-ng_store_box:*:*:*:*:-:*:*:*range: <6.0.5
- cpe:2.3:a:oneidentity:syslog-ng_store_box:*:*:*:*:lts:*:*:*range: <7.0
- One Identity/syslog-ngdescription
- osv-coords3 versionspkg:rpm/opensuse/syslog-ng&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/syslog-ng&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/syslog-ng&distro=SUSE%20Package%20Hub%2015%20SP4
< 3.35.1-bp154.3.3.1+ 2 more
- (no CPE)range: < 3.35.1-bp154.3.3.1
- (no CPE)range: < 3.6.4-12.11.1
- (no CPE)range: < 3.35.1-bp154.3.3.1
Patches
Vulnerability mechanics
References
7- github.com/syslog-ng/syslog-ng/security/advisories/GHSA-7932-4fc6-pvmcnvdThird Party Advisory
- lists.balabit.hu/pipermail/syslog-ng/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/02/msg00043.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3TZ7U2GQTAHVHJXSSEHQS5D2Q5T6SZB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU36HCM3VZYANUYFC6XFYEYJEKQPA2Q7/nvd
- security.gentoo.org/glsa/202305-09nvd
- www.debian.org/security/2023/dsa-5369nvd
News mentions
0No linked articles in our index yet.