Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:1294-1 Critical: Rsyslog Remote DoS Vulnerability Fix

suse
Calendar Grey October 15, 2014
Scroller Suse
Important announcement for SUSE users: Addressing remote Denial of Service vulnerability in rsyslog. Safeguard your system's integrity and performance.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

rsyslog has been updated to fix a remote denial of service issue: * Under certain configurations, a local or remote attacker able to send syslog messages to the server could have crashed the log server due to an array overread. (CVE-2014-3634, CVE-2014-3683) Security Issues: * CVE-2014-3634 * CVE-2014-3683 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-rsyslog-9840 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-rsyslog-9840

References

#890228 #897262 #899756

Cross- CVE-2014-3634 CVE-2014-3683

Affected Products:

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

https://www.suse.com/security/cve/CVE-2014-3634.html

https://www.suse.com/security/cve/CVE-2014-3683.html

https://bugzilla.suse.com/show_bug.cgi?id=890228

https://bugzilla.suse.com/show_bug.cgi?id=897262

https://bugzilla.suse.com/show_bug.cgi?id=899756

https://scc.suse.com:443/patches/

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1294-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.