RHSA-2019:2110: Moderate: rsyslog security and bug fix update
The rsyslog packages provide an enhanced, multi-threaded syslog daemon. It supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part, and fine-grained control over output format.<br>Security Fix(es):<br><li> rsyslog: imptcp: integer overflow when Octet-Counted TCP Framing is enabled (CVE-2018-16881)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2110?
The severity of RHSA-2019:2110 is classified as Important due to the potential integer overflow vulnerability.
How do I fix RHSA-2019:2110?
You can fix RHSA-2019:2110 by updating to the rsyslog packages version 8.24.0-38.el7 or later.
What is the impact of RHSA-2019:2110?
The impact of RHSA-2019:2110 includes potential denial of service and security breaches due to an integer overflow.
Which systems are affected by RHSA-2019:2110?
RHSA-2019:2110 affects systems running vulnerable versions of the rsyslog package prior to 8.24.0-38.el7.
Is there a workaround for RHSA-2019:2110?
There are no official workarounds for RHSA-2019:2110, and upgrading to the latest version is recommended.