SuSE: 2014:1294-1: important: rsyslog
Summary
rsyslog has been updated to fix a remote denial of service issue:
* Under certain configurations, a local or remote attacker able to
send syslog messages to the server could have crashed the log server
due to an array overread. (CVE-2014-3634, CVE-2014-3683)
Security Issues:
* CVE-2014-3634
References
#890228 #897262 #899756
Cross- CVE-2014-3634 CVE-2014-3683
Affected Products:
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
https://www.suse.com/security/cve/CVE-2014-3634.html
https://www.suse.com/security/cve/CVE-2014-3683.html
https://bugzilla.suse.com/show_bug.cgi?id=890228
https://bugzilla.suse.com/show_bug.cgi?id=897262
https://bugzilla.suse.com/show_bug.cgi?id=899756
https://scc.suse.com:443/patches/