[CLSA-2022:1652706309] Fix CVE(s): CVE-2019-17041, CVE-2019-17042, CVE-2018-16881
Type:
security
Severity:
moderate
Release date:
2022-05-16 13:05:09 UTC
Description:
* SECURITY UPDATE: denial of dervice - debian/patches/CVE-2018-16881.patch: introduces a frame size check in the processDataRcvd function of plugins/imptcp/imptcp.c. - CVE-2018-16881 * SECURITY UPDATE: heap-based overflow - debian/patches/CVE-2019-17041.patch: adds length checks for invalid AIX log message in contrib/pmaixforwardedfrom/pmaixforwardedfrom.c. - CVE-2019-17041 * SECURITY UPDATE: heap-based overflow - debian/patches/CVE-2019-17042.patch: adds length checks for invalid Cisco log messages in contrib/pmcisconames/pmcisconames.c. - CVE-2019-17042
Updated packages:
  • rsyslog_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:533fc7bbd15b58ce598895fd350e67a85663e327
  • rsyslog-elasticsearch_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:ed0d3acfb41e34dbce4a38511e10376b0abf3366
  • rsyslog-gnutls_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:d61a4ced9118014485eddda4f2ccfb3a5635a9bc
  • rsyslog-gssapi_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:95c7a6f7ccac9e75a59d93aa9674c97029d465a8
  • rsyslog-mysql_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:ca6ecc91dcd6a28d7ea3c5ae6a1a9ab3ceccc0df
  • rsyslog-pgsql_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:3e38a827cfcbf6e08dae1c0a78070e2f3ba59218
  • rsyslog-relp_8.16.0-1ubuntu3.1+tuxcare.els1_amd64.deb
    sha:6890c63d4df5e878bcae406cd561a5447901b20c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.