Alerts This Week
Warning Icon 1 929
Alerts This Week
Warning Icon 1 929

SUSE Linux Enterprise Server: 2020:0424-1 Moderate: Rsyslog Heap Overflow

suse
Calendar Grey February 19, 2020
Dist Suse Esm H88
SUSE enhances network reliability by upgrading OpenSSH, resolving critical vulnerabilities to improve overall protection.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for rsyslog fixes the following issues: Security issues fixed: - CVE-2019-17041: Fixed a heap overflow in the parser for AIX log messages (bsc#1153451). - CVE-2019-17042: Fixed a heap overflow in the parser for Cisco log messages (bsc#1153459). Non-security issues fixed: - Handle multiline messages correctly when using the imfile module. (bsc#1015203) - Fix a race condition in the shutdown sequence in wtp that was causing rsyslog not to shutdown properly. (bsc#1022804) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2020-424=1

References

#1015203 #1022804 #1153451 #1153459

Cross- CVE-2019-17041 CVE-2019-17042

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

https://www.suse.com/security/cve/CVE-2019-17041.html

https://www.suse.com/security/cve/CVE-2019-17042.html

https://bugzilla.suse.com/1015203

https://bugzilla.suse.com/1022804

https://bugzilla.suse.com/1153451

https://bugzilla.suse.com/1153459

Announcement ID: SUSE-SU-2020:0424-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here