drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in rsyslog
Name: |
Zwei Probleme in rsyslog |
|
ID: |
SUSE-SU-2019:2937-1 |
|
Distribution: |
SUSE |
|
Plattformen: |
SUSE Linux Enterprise Module for Basesystem 15, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Module for Basesystem 15-SP1 |
|
Datum: |
Fr, 8. November 2019, 23:05 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17042
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17041 |
|
Applikationen: |
rsyslog |
|
Originalnachricht |
SUSE Security Update: Security update for rsyslog ______________________________________________________________________________
Announcement ID: SUSE-SU-2019:2937-1 Rating: moderate References: #1141063 #1153451 #1153459 Cross-References: CVE-2019-17041 CVE-2019-17042 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Server Applications 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________
An update that solves two vulnerabilities and has one errata is now available.
Description:
This update for rsyslog fixes the following issues:
Security issues fixed:
- CVE-2019-17041: Fixed a heap overflow in the parser for AIX log messages (bsc#1153451). - CVE-2019-17042: Fixed a heap overflow in the parser for Cisco log messages (bsc#1153459).
Other issue addressed:
- Fixed an issue where rsyslog was SEGFAULT due to a mutex double-unlock (bsc#1141063).
Patch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Module for Server Applications 15-SP1:
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2019-2937=1
- SUSE Linux Enterprise Module for Server Applications 15:
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2019-2937=1
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1:
zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2937=1
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15:
zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2937=1
- SUSE Linux Enterprise Module for Basesystem 15-SP1:
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-2937=1
- SUSE Linux Enterprise Module for Basesystem 15:
zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-2937=1
Package List:
- SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64):
rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4 rsyslog-module-gssapi-8.33.1-3.22.4 rsyslog-module-gssapi-debuginfo-8.33.1-3.22.4 rsyslog-module-gtls-8.33.1-3.22.4 rsyslog-module-gtls-debuginfo-8.33.1-3.22.4 rsyslog-module-mmnormalize-8.33.1-3.22.4 rsyslog-module-mmnormalize-debuginfo-8.33.1-3.22.4 rsyslog-module-mysql-8.33.1-3.22.4 rsyslog-module-mysql-debuginfo-8.33.1-3.22.4 rsyslog-module-pgsql-8.33.1-3.22.4 rsyslog-module-pgsql-debuginfo-8.33.1-3.22.4 rsyslog-module-relp-8.33.1-3.22.4 rsyslog-module-relp-debuginfo-8.33.1-3.22.4 rsyslog-module-snmp-8.33.1-3.22.4 rsyslog-module-snmp-debuginfo-8.33.1-3.22.4 rsyslog-module-udpspoof-8.33.1-3.22.4 rsyslog-module-udpspoof-debuginfo-8.33.1-3.22.4
- SUSE Linux Enterprise Module for Server Applications 15 (aarch64 ppc64le s390x x86_64):
rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4 rsyslog-module-gssapi-8.33.1-3.22.4 rsyslog-module-gssapi-debuginfo-8.33.1-3.22.4 rsyslog-module-gtls-8.33.1-3.22.4 rsyslog-module-gtls-debuginfo-8.33.1-3.22.4 rsyslog-module-mmnormalize-8.33.1-3.22.4 rsyslog-module-mmnormalize-debuginfo-8.33.1-3.22.4 rsyslog-module-mysql-8.33.1-3.22.4 rsyslog-module-mysql-debuginfo-8.33.1-3.22.4 rsyslog-module-pgsql-8.33.1-3.22.4 rsyslog-module-pgsql-debuginfo-8.33.1-3.22.4 rsyslog-module-relp-8.33.1-3.22.4 rsyslog-module-relp-debuginfo-8.33.1-3.22.4 rsyslog-module-snmp-8.33.1-3.22.4 rsyslog-module-snmp-debuginfo-8.33.1-3.22.4 rsyslog-module-udpspoof-8.33.1-3.22.4 rsyslog-module-udpspoof-debuginfo-8.33.1-3.22.4
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64):
rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4 rsyslog-diag-tools-8.33.1-3.22.4 rsyslog-diag-tools-debuginfo-8.33.1-3.22.4 rsyslog-doc-8.33.1-3.22.4 rsyslog-module-dbi-8.33.1-3.22.4 rsyslog-module-dbi-debuginfo-8.33.1-3.22.4 rsyslog-module-elasticsearch-8.33.1-3.22.4 rsyslog-module-elasticsearch-debuginfo-8.33.1-3.22.4 rsyslog-module-gcrypt-8.33.1-3.22.4 rsyslog-module-gcrypt-debuginfo-8.33.1-3.22.4 rsyslog-module-mmnormalize-8.33.1-3.22.4 rsyslog-module-mmnormalize-debuginfo-8.33.1-3.22.4 rsyslog-module-omamqp1-8.33.1-3.22.4 rsyslog-module-omamqp1-debuginfo-8.33.1-3.22.4 rsyslog-module-omhttpfs-8.33.1-3.22.4 rsyslog-module-omhttpfs-debuginfo-8.33.1-3.22.4 rsyslog-module-omtcl-8.33.1-3.22.4 rsyslog-module-omtcl-debuginfo-8.33.1-3.22.4
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64):
rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4 rsyslog-diag-tools-8.33.1-3.22.4 rsyslog-diag-tools-debuginfo-8.33.1-3.22.4 rsyslog-doc-8.33.1-3.22.4 rsyslog-module-dbi-8.33.1-3.22.4 rsyslog-module-dbi-debuginfo-8.33.1-3.22.4 rsyslog-module-elasticsearch-8.33.1-3.22.4 rsyslog-module-elasticsearch-debuginfo-8.33.1-3.22.4 rsyslog-module-gcrypt-8.33.1-3.22.4 rsyslog-module-gcrypt-debuginfo-8.33.1-3.22.4 rsyslog-module-gtls-8.33.1-3.22.4 rsyslog-module-gtls-debuginfo-8.33.1-3.22.4 rsyslog-module-mmnormalize-8.33.1-3.22.4 rsyslog-module-mmnormalize-debuginfo-8.33.1-3.22.4 rsyslog-module-omamqp1-8.33.1-3.22.4 rsyslog-module-omamqp1-debuginfo-8.33.1-3.22.4 rsyslog-module-omhttpfs-8.33.1-3.22.4 rsyslog-module-omhttpfs-debuginfo-8.33.1-3.22.4 rsyslog-module-omtcl-8.33.1-3.22.4 rsyslog-module-omtcl-debuginfo-8.33.1-3.22.4
- SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64):
rsyslog-8.33.1-3.22.4 rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4
- SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64):
rsyslog-8.33.1-3.22.4 rsyslog-debuginfo-8.33.1-3.22.4 rsyslog-debugsource-8.33.1-3.22.4
References:
https://www.suse.com/security/cve/CVE-2019-17041.html https://www.suse.com/security/cve/CVE-2019-17042.html https://bugzilla.suse.com/1141063 https://bugzilla.suse.com/1153451 https://bugzilla.suse.com/1153459
_______________________________________________ sle-security-updates mailing list sle-security-updates@lists.suse.com http://lists.suse.com/mailman/listinfo/sle-security-updates
|
|
|
|