Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:0512-1 Moderate: Rsyslog Heap Overflow Issues

suse
Calendar Grey February 27, 2020
Dist Suse Esm H88
SUSE releases a critical security notice for rsyslog, tackling heap overflow vulnerabilities along with various other important corrections. Discover further details on this.
An update that solves two vulnerabilities and has four fixes is now available

Summary

This update for rsyslog fixes the following issues: Security issues fixed: - CVE-2019-17041: Fixed a heap overflow in the parser for AIX log messages (bsc#1153451). - CVE-2019-17042: Fixed a heap overflow in the parser for Cisco log messages (bsc#1153459). Non-security issues fixed: - Handle multiline messages correctly when using the imfile module. (bsc#1015203) - Fix a race condition in the shutdown sequence in wtp that was causing rsyslog not to shutdown properly. (bsc#1022804) - Fixed a rsyslogd SIGABORT crash if a path does not exists (bsc#1087920). - Fixed an issue where configuration templates where not consistently flushed (bsc#1084682). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1015203 #1022804 #1084682 #1087920 #1153451

#1153459

Cross- CVE-2019-17041 CVE-2019-17042

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2019-17041.html

https://www.suse.com/security/cve/CVE-2019-17042.html

https://bugzilla.suse.com/1015203

https://bugzilla.suse.com/1022804

https://bugzilla.suse.com/1084682

https://bugzilla.suse.com/1087920

https://bugzilla.suse.com/1153451

https://bugzilla.suse.com/1153459

Announcement ID: SUSE-SU-2020:0512-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here