rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "librelp-dev", "binary_version": "1.2.9-1ubuntu0.1~esm1" }, { "binary_name": "librelp0", "binary_version": "1.2.9-1ubuntu0.1~esm1" }, { "binary_name": "librelp0-dbgsym", "binary_version": "1.2.9-1ubuntu0.1~esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "librelp-dev", "binary_version": "1.2.14-3ubuntu0.1~esm1" }, { "binary_name": "librelp0", "binary_version": "1.2.14-3ubuntu0.1~esm1" }, { "binary_name": "librelp0-dbgsym", "binary_version": "1.2.14-3ubuntu0.1~esm1" } ] }