Vulnerability Bulletins

DSA-4151 librelp - security update

   
Affected software Debian
 
Bas van Schaik and Kevin Backhouse discovered a stack-based bufferoverflow vulnerability in librelp, a library providing reliable eventlogging over the network, triggered while checking x509 certificatesfrom a peer. A remote attacker able to connect to rsyslog can takeadvantage of this flaw for remote code execution by sending a speciallycrafted x509 certificate.

More info:

https://www.debian.org/security/2018/dsa-4151