安全公告详情

NS-SA-2023-0093

2023-05-30 09:08:34

简介

important: rsyslog/aide security update

严重级别

important

主题

An update for rsyslog/aide is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

rsyslog: Rsyslog is an enhanced, multi-threaded syslog daemon. It supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part, and fine grain output format control. It is compatible with stock sysklogd and can be used as a drop-in replacement. Rsyslog is simple to set up, with advanced features suitable for enterprise-class, encryption-protected syslog relay chains.
aide: AIDE (Advanced Intrusion Detection Environment) is a file integrity checker and intrusion detection program.


Security Fix(es):
rsyslog: A flaw was found in rsyslog's reception TCP modules. This flaw allows an attacker to craft a malicious message leading to a heap-based buffer overflow. This issue allows the attacker to corrupt or access data stored in memory, leading to a denial of service in the rsyslog or possible remote code execution.(CVE-2022-24903)
rsyslog: bugfix
aide: A heap-based buffer overflow vulnerability in the base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL.(CVE-2021-45417)
aide: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.02B5.

影响组件

  • rsyslog
  • aide

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["rsyslog-8.2102.0-7.zncgsl6_6.1.t1.0.x86_64.rpm","rsyslog-mmjsonparse-8.2102.0-7.zncgsl6_6.1.t1.0.x86_64.rpm"],"source":"rsyslog-8.2102.0-7.zncgsl6_6.1.t1.0.src.rpm"},{"binary":["aide-0.16-14.zncgsl6_5.1.x86_64.rpm"],"source":"aide-0.16-14.zncgsl6_5.1.src.rpm"}]}]}

CVE

参考