Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 22: rsyslog Critical Update for Denial of Service Mitigation

fedora
Calendar Grey July 16, 2015
Dist Fedora Esm H88
Enhance system logging on Fedora 22 by upgrading the rsyslog package to address critical security vulnerabilities, ensuring better audit trails and compliance
Besides other changes, this update mitigates this vulnerability: https://access.redhat.com/security/cve/CVE-2015-3243

Summary

Rsyslog is an enhanced, multi-threaded syslog daemon. It supports MySQL,

syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part,

and fine grain output format control. It is compatible with stock sysklogd

and can be used as a drop-in replacement. Rsyslog is simple to set up, with

advanced features suitable for enterprise-class, encryption-protected syslog

relay chains.

Update Information:

Besides other changes, this update mitigates this vulnerability: https://access.redhat.com/security/cve/CVE-2015-3243

Change Log

* Thu Jul 2 2015 Tomas Heinrich 8.8.0-3 - use the right macro to specify the default pidfile resolves: rhbz#1224972 - make logrotate tolerate missing log files resolves: rhbz#1205889 - set the default service umask to 0066 resolves: rhbz#1228192 - add a patch to prevent a crash on empty messages resolves: rhbz#1224538

References


[ 1 ] Bug #1224538 - [abrt] rsyslog: SanitizeMsg(): rsyslogd killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1224538 [ 2 ] Bug #1224972 - rsyslog logrotate issue https://bugzilla.redhat.com/show_bug.cgi?id=1224972

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rsyslog' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rsyslog
Product: Fedora 22
Version: 8.8.0
Release: 3.fc22
Summary: Enhanced system logging and kernel message trapping daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here