Back to bug 727644
| Who | When | What | Removed | Added |
|---|---|---|---|---|
| Martin Osvald 🛹 | 2011-08-02 18:04:57 UTC | Priority | unspecified | high |
| Severity | unspecified | medium | ||
| Vincent Danen | 2011-08-02 20:35:15 UTC | CC | vdanen | |
| Vincent Danen | 2011-08-02 20:44:20 UTC | Group | rhn, qa, support, featuretracker, devel, suseng | security |
| Version | 6.0 | unspecified | ||
| Component | rsyslog | vulnerability | ||
| CC | security-response-team | |||
| Assignee | theinric | security-response-team | ||
| QA Contact | qe-baseos-security | |||
| Target Milestone | rc | --- | ||
| Product | Red Hat Enterprise Linux 6 | Security Response | ||
| Vincent Danen | 2011-08-02 21:18:13 UTC | Blocks | 727687 | |
| Vincent Danen | 2011-08-02 21:18:45 UTC | Whiteboard | impact=moderate,public=no,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=new,fedora-all/rsyslog=new | |
| Tomas Heinrich | 2011-08-03 14:04:35 UTC | CC | theinric | |
| Vincent Danen | 2011-08-04 15:58:43 UTC | Whiteboard | impact=moderate,public=no,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=new,fedora-all/rsyslog=new | impact=moderate,public=no,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=new |
| Vincent Danen | 2011-08-08 14:29:05 UTC | CC | rgerhards | |
| Vincent Danen | 2011-08-09 16:46:36 UTC | CC | alorbach | |
| Vincent Danen | 2011-08-10 20:23:50 UTC | CC | mbiebl | |
| Rainer Gerhards | 2011-08-11 12:29:17 UTC | Attachment #517785 Attachment is patch | 0 | 1 |
| Attachment #517785 Attachment mime type | application/octet-stream | text/plain | ||
| Tomas Hoger | 2011-08-12 18:33:08 UTC | Summary | rsyslog doesn't correctly parse legacy-formatted messages which can lead to overwriting ssp guard variable | rsyslog: parseLegacySyslogMsg off-by-two buffer overflow |
| Tomas Hoger | 2011-08-26 11:11:24 UTC | Depends On | 733647 | |
| Tomas Hoger | 2011-08-26 11:11:33 UTC | Depends On | 733648 | |
| Tomas Hoger | 2011-08-26 14:08:15 UTC | Summary | rsyslog: parseLegacySyslogMsg off-by-two buffer overflow | CVE-2011-3200 rsyslog: parseLegacySyslogMsg off-by-two buffer overflow |
| Alias | CVE-2011-3200 | |||
| Whiteboard | impact=moderate,public=no,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=new | impact=moderate,public=20110901,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected | ||
| Tomas Hoger | 2011-09-01 16:22:18 UTC | Group | redhat, security | |
| Vincent Danen | 2011-09-01 19:43:42 UTC | Depends On | 735205 | |
| Vincent Danen | 2011-09-01 19:54:32 UTC | Fixed In Version | rsyslog 4.6.8, rsyslog 5.8.5 | |
| Mark J. Cox | 2011-09-08 08:56:15 UTC | CC | mjc | |
| Whiteboard | impact=moderate,public=20110901,reported=20110802,source=bugzilla,cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected | impact=moderate,public=20110901,reported=20110802,source=bugzilla,cvss2=2.9/AV:A/AC:M/Au:N/C:N/I:N/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected | ||
| Tomas Hoger | 2011-10-06 12:27:55 UTC | Status | NEW | CLOSED |
| Resolution | --- | ERRATA | ||
| Last Closed | 2011-10-06 08:27:55 UTC | |||
| Adam Mariš | 2015-07-31 14:22:06 UTC | CC | amaris | |
| Whiteboard | impact=moderate,public=20110901,reported=20110802,source=bugzilla,cvss2=2.9/AV:A/AC:M/Au:N/C:N/I:N/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected | impact=moderate,public=20110901,reported=20110802,source=redhat,cvss2=2.9/AV:A/AC:M/Au:N/C:N/I:N/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected | ||
| Ján Rusnačko | 2015-08-19 09:12:01 UTC | Priority | high | medium |
| Adam Mariš | 2016-11-08 16:22:10 UTC | CC | amaris | |
| Product Security DevOps Team | 2019-09-29 12:46:32 UTC | Whiteboard | impact=moderate,public=20110901,reported=20110802,source=redhat,cvss2=2.9/AV:A/AC:M/Au:N/C:N/I:N/A:P,rhel-6/rsyslog=affected,rhel-5/rsyslog=notaffected,fedora-all/rsyslog=affected |
Back to bug 727644