Login
Newsletter
Werbung

Sicherheit: Denial of Service in rsyslog
Aktuelle Meldungen Distributionen
Name: Denial of Service in rsyslog
ID: USN-1338-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.04
Datum: Di, 24. Januar 2012, 08:18
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4623
Applikationen: rsyslog

Originalnachricht


--===============7937935882551862127==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-R2Q5+biJ8lm/1SZVYAWF"


--=-R2Q5+biJ8lm/1SZVYAWF
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1338-1
January 23, 2012

rsyslog vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04

Summary:

Rsyslog could be made to crash if it processed a specially crafted log
message.

Software Description:
- rsyslog: Enhanced syslogd

Details:

Peter Eisentraut discovered that Rsyslog would not properly perform input
validation when configured to use imfile. If an attacker were able to
craft messages in a file that Rsyslog monitored, an attacker could cause a
denial of service. The imfile module is disabled by default in Ubuntu.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
rsyslog 4.6.4-2ubuntu4.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1338-1
CVE-2011-4623

Package Information:
https://launchpad.net/ubuntu/+source/rsyslog/4.6.4-2ubuntu4.2



--Û2Q5+biJ8lm/1SZVYAWF
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPHci0AAoJEFHb3FjMVZVzWoYQALbCWtbzOjGCidkO1se7WSwJ
qgJ8sa4zqCC/BUy7q5tWA0ajgelQKTFMSa0c7gRbOBXx9mwq0Gb2rDFCz6NLxTN/
JkX4WIocn8CP7Z2+rVGDhzcdpWlrGoT9FR4WkDLlAtDqhPxy7shMabCiUmbaTg0C
iMIjL6TLdjbmXaMm4rPvbF+vXFmfd/6v7hyx4lZoUP5cb7eqJSEv2A3tLtlkIoFO
oMQt3pqGlmUkEJShSzzX5kGuykHAqB+15G2a7Ql34Vi9SCnQEHH0ByoxCuUIpZwU
iN+MPJpxAI9badlafDb9fPQ/sAcoWppo57hEzaN9I4Z57dpgOFRrXO6A1E8Bxh0c
LQnL3OxiBqx3EqtlTLVJ3Ff86pQCflwNYgkU2tn8Px68HzKYxN1ZwKsUXcg/ho4W
A1wsqLP4NgxnubwubosO58Phy/J55PTIYTLomawxVMaeBRAeT2WDpmZlBnJH4NN7
VjRhJcxgvEMNY1heAsZ7ocP3Ij7o58lA9whtapKcxsHCq/UW/aerbxXyRmHF8H6N
++cPPxLHLk+i8anoGger+CFVtsPXGWZg4itqO/G/5B9d3Ov6rziUu+2a0DupEiVU
VvkK5RTl9iv6JsX7cmZeKH+pxr1t26R4M0urxYnCEwGsutU66DvtFVxL8GnuLwfW
XmnsDZV2jgd/NK1PjBhL
=36so
-----END PGP SIGNATURE-----

--=-R2Q5+biJ8lm/1SZVYAWF--



--===============7937935882551862127==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============7937935882551862127==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung