Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 361219 - <app-admin/rsyslog-5.6.5: Multiple vulnerabilities
Summary: <app-admin/rsyslog-5.6.5: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 359765
Blocks:
  Show dependency tree
 
Reported: 2011-03-30 03:42 UTC by Tim Sammut (RETIRED)
Modified: 2011-10-08 21:22 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
my emerge --info (emerge.info,4.15 KB, text/plain)
2011-05-13 08:55 UTC, Ian Delaney (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-03-30 03:42:38 UTC
From $URL:

The $RepeatedMsgReduction option could cause a memory leak:
http://bugzilla.adiscon.com/show_bug.cgi?id=225
http://git.adiscon.com/?p=rsyslog.git;a=commitdiff;h=8083bd1433449fd2b1b79bf759f782e0f64c0cd2

Multiple rulesets that are used by multiple inputs could cause a
memory leak or crash:
http://bugzilla.adiscon.com/show_bug.cgi?id=226
http://bugzilla.adiscon.com/show_bug.cgi?id=218
http://git.adiscon.com/?p=rsyslog.git;a=commitdiff;h=1ef709cc97d54f74d3fdeb83788cc4b01f4c6a2a

Alexys or Tiziano, I believe these are fixed in 5.6.5 which is in the tree, but looks to be much newer than the current stable ebuild. How would you like to proceed? Thank you.
Comment 1 Ultrabug gentoo-dev 2011-03-30 17:07:18 UTC
Hi Tim,

As seen with you, I have marked this bug as depending of #359765, so we'll stabilize 5.6.4 first and then proceed quickly when 5.6.5 reaches the 30 days mark.

Thanks
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-05-01 03:11:58 UTC
(In reply to comment #1)
> Hi Tim,
> 
> As seen with you, I have marked this bug as depending of #359765, so we'll
> stabilize 5.6.4 first and then proceed quickly when 5.6.5 reaches the 30 days
> mark.
> 
> Thanks

Hi, Alexys.

Looks like we're just past 30 days with 5.6.5 in the tree. Can we move to stabilize that now? Thank you.
Comment 3 Ultrabug gentoo-dev 2011-05-12 16:24:02 UTC
Hi Tim, sure please proceeed.

Thanks !
Comment 4 Tim Sammut (RETIRED) gentoo-dev 2011-05-13 03:40:59 UTC
(In reply to comment #3)
> Hi Tim, sure please proceeed.
> 

Great, thank you.

Arches, please test and mark stable:
=app-admin/rsyslog-5.6.5
Target keywords : "amd64 hppa x86"
Comment 5 Ian Delaney (RETIRED) gentoo-dev 2011-05-13 08:26:06 UTC
amd64

emerged, passed all
gentoo64 / # /usr/sbin/rsyslogd &
[1] 28914
all good
Comment 6 Thomas Kahle (RETIRED) gentoo-dev 2011-05-13 08:37:08 UTC
x86 stable. Thanks
Comment 7 Ian Delaney (RETIRED) gentoo-dev 2011-05-13 08:55:30 UTC
Created attachment 273035 [details]
my emerge --info
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2011-05-13 14:12:40 UTC
Stable for HPPA.
Comment 9 Markos Chandras (RETIRED) gentoo-dev 2011-05-13 22:10:28 UTC
amd64 done. Thanks Ian
Comment 10 Tim Sammut (RETIRED) gentoo-dev 2011-05-13 22:16:15 UTC
Thanks, folks.

GLSA Vote: no.
Comment 11 Pierre-Yves Rofes (RETIRED) gentoo-dev 2011-10-08 21:22:12 UTC
voting no too, and closing.