rsyslog: mmpstrucdata denial of service fixed in 8.2606.0
rsyslog 8.2606.0 fixes a denial-of-service flaw in the mmpstrucdata module parsing RFC 5424 structured data with oversized parameter values.
Rainer Gerhards announced rsyslog 8.2606.0, fixing a denial-of-service issue tracked as GHSA-2whq-6rcm-64m8. Only configurations with the mmpstrucdata module enabled, which parses RFC 5424 structured data and accepts sufficiently large messages, are affected; the module is not enabled by default. In affected versions, a crafted message carrying an oversized parameter value could terminate the rsyslog daemon.
- Fix released in rsyslog 8.2606.0, tracked as GHSA-2whq-6rcm-64m8
- Affects only setups with mmpstrucdata module enabled, which is non-default
- Crafted oversized RFC 5424 parameter values can crash the daemon
Posted by Rainer Gerhards on Sep 20 Hello, https://github.com/rsyslog/rsyslog/security/advisories/GHSA-2whq-6rcm-64m8 Affected configurations use mmpstrucdata to parse RFC 5424 structured data and accept messages large enough to carry an oversized parameter value. The module is not enabled by default. In affected versions, a crafted message could terminate...
This source does not provide full text. Read it at seclists.org.