sysklogd

2014-10-06: New version 1.5.1 released

We're pleased to announce a bugfix release of sysklogd that fixes a recently found vulnerability by Rainer Gerhards:

Many thanks to Rainer Gerhards, rsyslog project lead, for identifying a problem with how rsyslog's rsyslogd and sysklogd's syslogd check for invalid priority values (CVE-2014-3634). For details please refer to Rainer's well-written issue description.

In sysklogd's syslogd, invalid priority values between 192 and 1023 (directly or arrived at via overflow wraparound) can propagate through code causing out-of-bounds access to the f_pmask array within the 'filed' structure by up to 104 bytes past its end. Though most likely insufficient to reach unallocated memory because there are around 544 bytes past f_pmask in 'filed' (mod packing and other differences), incorrect access of fields at higher positions of the 'filed' structure definition can cause unexpected behavior including message mis-classification, forwarding issues, message loss, or other.

Joey

 

News
2007-07-29 New version 1.5 released more2001-03-11 New version 1.4.1 released more2000-12-31 Second trial to get web pages up and running more

Download

Contributors
John Haxby
Herbert Thielen
Greg Wettstein
Matthew Fischer
Eric Tucker