security

remote syslog PRI vulnerability – CVE: CVE-2014-3683

remote syslog PRI vulnerability =============================== CVE: CVE-2014-3683 Status of this report ——————— FINAL Updated 2014-10-06: effect on sysklogd milder than in initial assesment Reporter ——- mancha , intial detection and analysis Rainer Gerhards , rsyslog project lead Affected ——– – rsyslog, most probably all versions (checked v3-stable and above) – sysklogd (checked most recent versions) […]

remote syslog PRI vulnerability – CVE: CVE-2014-3634

=============================== CVE: CVE-2014-3634 Status of this report ——————— FINAL Reporter ——- Rainer Gerhards, rsyslog project lead Affected ——– – rsyslog, most probably all versions (checked 5.8.6+) – sysklogd (checked most recent versions) – potentially others (see root cause) Root Cause ———- Note: rsyslogd was forked from sysklogd, and the root cause applies to both. For […]

Changelog for 5.8.5 (v5-stable)

Version 5.8.5  [V5-stable] (rgerhards/al), 2011-09-01 bugfix: security: off-by-two bug in legacy syslog parser, CVE-2011-3200 bugfix: mark message processing did not work correctly bugfix: potential hang condition during tag emulation bugfix: too-early string termination during tag emulation bugfix: The NUL-Byte for the syslogtag was not copied in MsgDup (msg.c) bugfix: fixed incorrect state handling for Discard […]

Scroll to top