An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-38725.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.0.32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.0"
}
]
}
]