MGASA-2014-0411

Source
https://advisories.mageia.org/MGASA-2014-0411.html
Import Source
https://advisories.mageia.org/MGASA-2014-0411.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0411
Related
Published
2014-10-09T14:39:32Z
Modified
2014-10-09T14:20:44Z
Summary
Updated rsyslog packages fix CVE-2014-3634
Details

Updated rsyslog packages fix security vulnerability:

Rainer Gerhards, the rsyslog project leader, reported a vulnerability in Rsyslog. As a consequence of this vulnerability an attacker can send malformed messages to a server, if this one accepts data from untrusted sources, and trigger a denial of service attack (CVE-2014-3634).

References
Credits

Affected packages

Mageia:3 / rsyslog

Package

Name
rsyslog
Purl
pkg:rpm/mageia/rsyslog?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.1-2.2.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / rsyslog

Package

Name
rsyslog
Purl
pkg:rpm/mageia/rsyslog?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.1-3.2.mga4

Ecosystem specific

{
    "section": "core"
}