| Summary: | syslog-ng new use-after-free security issue | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Guillaume Rousse <guillomovitch> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | marja11 |
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | syslog-ng-3.14.1-5.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-12-23 17:02:25 CET
Assigning to the registered maintainer. CC:
(none) =>
marja11 Fixed in syslog-ng-3.19.1-2.mga7 in Cauldron by Guillaume. Version:
Cauldron =>
6 Fedora has issued an advisory for this today (January 20): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/633LADK5VQ23OD6OTIAGHQ6P6ZEWMRGA/ I had a look at the code of syslog-ng 3.9.1, shipped in mageia 6. According to my understanding, the problem doesn't exist in that version, as there is no use of the freed pointer, contrarily to more recent version. Resolution:
(none) =>
FIXED |