Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:2937-1 Moderate: Rsyslog Heap Overflow Threat Update

suse
Calendar Grey November 8, 2019
Dist Suse Esm H88
SUSE has released a security update for rsyslog, which resolves moderate vulnerabilities. The update includes detailed instructions for patch installation.
An update that solves two vulnerabilities and has one errata is now available

Summary

This update for rsyslog fixes the following issues: Security issues fixed: - CVE-2019-17041: Fixed a heap overflow in the parser for AIX log messages (bsc#1153451). - CVE-2019-17042: Fixed a heap overflow in the parser for Cisco log messages (bsc#1153459). Other issue addressed: - Fixed an issue where rsyslog was SEGFAULT due to a mutex double-unlock (bsc#1141063). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2019-2937=1 - SUSE Linux Enterprise Module for Server Applications 15:

References

#1141063 #1153451 #1153459

Cross- CVE-2019-17041 CVE-2019-17042

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP1

SUSE Linux Enterprise Module for Server Applications 15

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15-SP1

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2019-17041.html

https://www.suse.com/security/cve/CVE-2019-17042.html

https://bugzilla.suse.com/1141063

https://bugzilla.suse.com/1153451

https://bugzilla.suse.com/1153459

Announcement ID: SUSE-SU-2019:2937-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here