Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 28: FEDORA-2018-749f2bae28 Critical: Rsyslog Buffer Overflow

fedora
Calendar Grey August 11, 2018
Dist Fedora Esm H88
The recent rsyslog update for Fedora resolves multiple concerns, improving both the reliability and safety of logging services within the system.
rebase to 8.37.0 ---------------------- - few fixes and enhancements handling journal input - now requires librelp at least 1.2.16, adding support for setting address to bind - var...

Summary

Rsyslog is an enhanced, multi-threaded syslog daemon. It supports MySQL,

syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part,

and fine grain output format control. It is compatible with stock sysklogd

and can be used as a drop-in replacement. Rsyslog is simple to set up, with

advanced features suitable for enterprise-class, encryption-protected syslog

relay chains.

rebase to 8.37.0 ---------------------- - few fixes and enhancements handling

journal input - now requires librelp at least 1.2.16, adding support for setting

address to bind - various other rsyslog core bugfixes and stability fixes

* Wed Aug 8 2018 Jiri Vymazal - 8.37.0-1

- rebase to upstream version 8.37.0

resolves: rhbz#1612079

resolves: rhbz#1598217

resolves: rhbz#1544139

- dropped needless libee dependency

* Wed Jul 25 2018 Jiri Vymazal - 8.36.0-3

- fixed a typo in commented-out part of default conf + reordered it

resolves: rhbz#1579592

* Tue Jul 24 2018 Jason L Tibbitts III - 8.36.0-3

- Rebuild for unannounced net-snmp soversion bump.

- Use python3-docutils because rst2man has moved there.

* Mon Jul 23 2018 Jiri Vymazal - 8.36.0-2

- added gcc to buildrequires following f29 system-wide change

* Sat Jul 14 2018 Fedora Release Engineering - 8.36.0-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

* Mon Jul 2 2018 Jiri Vymazal - 8.36.0-1

- rebase to 8.36.0

- removed stdlog dependency as upstream is going to drop it

- following upstream naming of pidfile

- removed needless conditionals

* Fri Jun 8 2018 Remi Collet - 8.35.0-4

- rebuild with libbson and libmongc 1.10.2 (soname back to 0)

* Mon May 28 2018 Remi Collet - 8.35.0-3

- rebuild with libbson and libmongc 1.10.0

* Thu May 17 2018 Radovan Sroka - 8.35.0-2

- rebase to 8.35.0

[ 1 ] Bug #1598217 - rsyslog: Buffer overflow in SanitizeMsg() function in runtime/parser.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1598217

[ 2 ] Bug #1544139 - rsyslogd: imjournal: open on state file `/var/lib/rsyslog/imjournal.state' failed [v8.32.0 try https://www.rsyslog.com/ ]

https://bugzilla.redhat.com/show_bug.cgi?id=1544139

[ 3 ] Bug #1612079 - rsyslog-8.37.0 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1612079

[ 4 ] Bug #1579592 - SELinux is preventing in:imjournal from using the 'dac_override' capabilities.

https://bugzilla.redhat.com/show_bug.cgi?id=1579592

su -c 'dnf upgrade --advisory FEDORA-2018-749f2bae28' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OUMCAI6AR6Y7QYDY4WNTRCRVKY7PCM53/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 8.37.0
Release: 1.fc28
Summary: Enhanced system logging and kernel message trapping daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here