Synopsis:          Moderate: rsyslog security, bug fix, and enhancement update
Advisory ID:       SLSA-2020:1000-1
Issue Date:        2020-04-07
CVE Numbers:       CVE-2019-17042
                   CVE-2019-17041
--

* rsyslog: heap-based overflow in
    contrib/pmaixforwardedfrom/pmaixforwardedfrom.c
    
* rsyslog: heap-based overflow in contrib/pmcisconames/pmcisconames.c
--

SL7
  x86_64
    rsyslog-mysql-8.24.0-52.el7.x86_64.rpm
    rsyslog-relp-8.24.0-52.el7.x86_64.rpm
    rsyslog-gnutls-8.24.0-52.el7.x86_64.rpm
    rsyslog-pgsql-8.24.0-52.el7.x86_64.rpm
    rsyslog-mmjsonparse-8.24.0-52.el7.x86_64.rpm
    rsyslog-8.24.0-52.el7.x86_64.rpm
    rsyslog-kafka-8.24.0-52.el7.x86_64.rpm
    rsyslog-gssapi-8.24.0-52.el7.x86_64.rpm
    rsyslog-debuginfo-8.24.0-52.el7.x86_64.rpm
    rsyslog-crypto-8.24.0-52.el7.x86_64.rpm
    rsyslog-elasticsearch-8.24.0-52.el7.x86_64.rpm
    rsyslog-libdbi-8.24.0-52.el7.x86_64.rpm
    rsyslog-mmaudit-8.24.0-52.el7.x86_64.rpm
    rsyslog-mmkubernetes-8.24.0-52.el7.x86_64.rpm
    rsyslog-mmnormalize-8.24.0-52.el7.x86_64.rpm
    rsyslog-mmsnmptrapd-8.24.0-52.el7.x86_64.rpm
    rsyslog-snmp-8.24.0-52.el7.x86_64.rpm
    rsyslog-udpspoof-8.24.0-52.el7.x86_64.rpm
  noarch
    rsyslog-doc-8.24.0-52.el7.noarch.rpm

- Scientific Linux Development Team