This update for rsyslog fixes the following issues:
Security issues fixed:
CVE-2019-17041: Fixed a heap overflow in the parser for AIX log messages (bsc#1153451).
CVE-2019-17042: Fixed a heap overflow in the parser for Cisco log messages (bsc#1153459).
Other issue addressed:
Fixed an issue where rsyslog was SEGFAULT due to a mutex double-unlock (bsc#1141063).
Affected Packages
rsyslog
SUSE Linux Enterprise Module for Basesystem 15SUSE Linux Enterprise Module for Basesystem 15 SP1SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-gssapi
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-gtls
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-mmnormalize
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-mysql
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-pgsql
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-relp
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-snmp
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1
Fixed in:
8.33.1-3.22.4
rsyslog-module-udpspoof
SUSE Linux Enterprise Module for Server Applications 15SUSE Linux Enterprise Module for Server Applications 15 SP1