sysklogd: Update to 1.5.1

...and now to something completely different... ;-)

Changelog:

- Bugfix against invalid PRI values (CVE-2014-3634)

CVE-2014-3634:
"...sysklogd 1.5 and earlier allows remote attackers to cause a
denial of service (crash), possibly execute arbitrary code,
or have other unspecified impact via a crafted priority (PRI)
value that triggers an out-of-bounds array access."

Nothing good for a firewall...and besides, 'sysklogd' wasn't updated since 2010.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
This commit is contained in:
Matthias Fischer
2017-01-29 14:37:43 +01:00
committed by Michael Tremer
parent a8f9804a76
commit 8d07810dce
2 changed files with 5 additions and 6 deletions

View File

@@ -1,6 +1,8 @@
usr/sbin/klogd
usr/sbin/syslogd
#usr/share/man/man5/syslog.conf.5
#usr/share/man/man8/klogd.8
#usr/share/man/man8/sysklogd.8
#usr/share/man/man8/syslogd.8
var/log/dhcpcd.log
var/log/messages