Oval Definition:oval:org.mitre.oval:def:26816
Revision Date:2014-12-08Version:9
Title:RHSA-2014:1671 -- rsyslog5 and rsyslog security update (Moderate)
Description:The rsyslog packages provide an enhanced, multi-threaded syslog daemonthat supports writing to relational databases, syslog/TCP, RFC 3195,permitted sender lists, filtering on any message part, and fine grainedoutput format control.A flaw was found in the way rsyslog handled invalid log message priorityvalues. In certain configurations, a local attacker, or a remote attackerable to connect to the rsyslog port, could use this flaw to crash thersyslog daemon. (CVE-2014-3634)Red Hat would like to thank Rainer Gerhards of rsyslog upstream forreporting this issue.All rsyslog5 and rsyslog users are advised to upgrade to these updatedpackages, which contain a backported patch to correct this issue. Afterinstalling the update, the rsyslog service will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1671
CVE-2014-3634
RHSA-2014:1671
Platform(s):CentOS Linux 5
CentOS Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s):rsyslog
rsyslog5
Definition Synopsis
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • rsyslog5 is earlier than 0:5.8.12-5.el5_11
  • OR rsyslog5-gnutls is earlier than 0:5.8.12-5.el5_11
  • OR rsyslog5-gssapi is earlier than 0:5.8.12-5.el5_11
  • OR rsyslog5-mysql is earlier than 0:5.8.12-5.el5_11
  • OR rsyslog5-pgsql is earlier than 0:5.8.12-5.el5_11
  • OR rsyslog5-snmp is earlier than 0:5.8.12-5.el5_11
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND rsyslog5-debuginfo is earlier than 0:5.8.12-5.el5_11
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • rsyslog is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-gnutls is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-gssapi is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-mysql is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-pgsql is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-relp is earlier than 0:5.8.10-9.el6_6
  • OR rsyslog-snmp is earlier than 0:5.8.10-9.el6_6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND rsyslog-debuginfo is earlier than 0:5.8.10-9.el6_6
  • BACK