Headline
Ubuntu Security Notice USN-5419-1
Ubuntu Security Notice 5419-1 - It was discovered that Rsyslog improperly handled certain invalid input. An attacker could use this issue to cause Rsyslog to crash.
==========================================================================Ubuntu Security Notice USN-5419-1May 12, 2022rsyslog vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 16.04 ESMSummary:Rsyslog could be made to crash if it received specially crafted input.Software Description:- rsyslog: Enhanced syslogdDetails:It was discovered that Rsyslog improperly handled certain invalid input. An attacker could use this issue to cause Rsyslog to crash.Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 16.04 ESM: rsyslog 8.16.0-1ubuntu3.1+esm1In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-5419-1 CVE-2018-16881, CVE-2019-17041, CVE-2019-17042
Related news
CVE-2018-16881: Invalid Bug ID
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.