Buffer overflow in rsyslog - CVE-2019-17041
Published: November 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in "contrib/pmaixforwardedfrom/pmaixforwardedfrom.c" due to a boundary error in the parser for AIX log messages. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Isolation Segment
VMware Tanzu Application Service for VMs
Juniper Cloud Native Router
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization Manager
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Opensuse
Ubuntu
Fedora
rsyslog (Red Hat package)
rsyslog (Alpine package)
rsyslog (Ubuntu package)
rsyslog
Junos cRPD
How to mitigate CVE-2019-17041
rsyslog (Red Hat package) - addressed in versions 8.24.0-52.el7, 8.1911.0-3.el8
rsyslog (Alpine package) - update to 8.31.0-r1
rsyslog (Ubuntu package) - update to 8.16.01ubuntu3.1+esm1
rsyslog - addressed in versions 8.1911.0-1.fc30, 8.1911.0-1.fc31
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
External References
Related Security Bulletins
- OpenSUSE Linux update for rsyslog
- OpenSUSE Linux update for rsyslog
- Multiple vulnerabilities in Rsyslog
- Red Hat Enterprise Linux 7 update for rsyslog
- Red Hat Enterprise Linux 8 update for rsyslog
- Buffer overflow in rsyslog (Alpine package)
- Ubuntu update for rsyslog
- VMware Tanzu products update for Rsyslog
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Fedora 31 update for rsyslog
- Fedora 30 update for rsyslog