[SECURITY] Fedora 7 Update: syslog-ng-2.0.7-1.fc7

updates at fedoraproject.org updates at fedoraproject.org
Fri Jan 18 23:56:40 UTC 2008


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-0559
2008-01-16 18:57:13
--------------------------------------------------------------------------------

Name        : syslog-ng
Product     : Fedora 7
Version     : 2.0.7
Release     : 1.fc7
URL         : http://www.balabit.com/products/syslog-ng/
Summary     : Syslog replacement daemon
Description :
syslog-ng, as the name shows, is a syslogd replacement, but with new
functionality for the new generation. The original syslogd allows
messages only to be sorted based on priority/facility pairs; syslog-ng
adds the possibility to filter based on message contents using regular
expressions. The new configuration scheme is intuitive and powerful.
Forwarding logs over TCP and remembering all forwarding hops makes it
ideal for firewalled environments.

--------------------------------------------------------------------------------
Update Information:

Contains a security fix for CVE-2007-6437/ZSA-2007-029 DoS
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jan  8 2008 Douglas E. Warner <silfreed at silfreed.net> 2.0.7-1
- updated to 2.0.7
- force regeneration to avoid broken paths from upstream (#265221)
- adding loggen binary
* Mon Dec 17 2007 Douglas E. Warner <silfreed at silfreed.net> 2.0.6-1
- updated to 2.0.6
- fixes DoS in ZSA-2007-029
* Thu Nov 29 2007 Peter Vrabec <pvrabec at redhat.com> 2.0.5-3
- add conflicts (#400661)
* Wed Aug 29 2007 Fedora Release Engineering <rel-eng at fedoraproject dot org> - 2.0.5-2
- Rebuild for selinux ppc32 issue.
* Thu Jul 26 2007 Jose Pedro Oliveira <jpo at di.uminho.pt> - 2.0.5-1
- Update to 2.0.5
* Thu Jun  7 2007 Jose Pedro Oliveira <jpo at di.uminho.pt> - 2.0.4-4
- Add support for vim 7.1.
* Thu May 31 2007 Jose Pedro Oliveira <jpo at di.uminho.pt> - 2.0.4-3
- Increase the number of unix-stream max-connections (10 -> 32).
* Sat May 26 2007 Jose Pedro Oliveira <jpo at di.uminho.pt> - 2.0.4-2
- New upstream download location
  (https://lists.balabit.hu/pipermail/syslog-ng/2007-May/010258.html)
* Tue May 22 2007 Jose Pedro Oliveira <jpo at di.uminho.pt> - 2.0.4-1
- Update to 2.0.4.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #265221 - syslog-ng fails to build due to debuginfo issue
        https://bugzilla.redhat.com/show_bug.cgi?id=265221
  [ 2 ] Bug #400661 - The syslog-ng an rsyslog packages should conflict
        https://bugzilla.redhat.com/show_bug.cgi?id=400661
  [ 3 ] Bug #426305 - CVE-2007-6437 syslog-ng crash by message with invalid timestamp separator [7]
        https://bugzilla.redhat.com/show_bug.cgi?id=426305
  [ 4 ] Bug #426173 - CVE-2007-6437 syslog-ng crash by message with invalid timestamp separator
        https://bugzilla.redhat.com/show_bug.cgi?id=426173
--------------------------------------------------------------------------------
Updated packages:

2f35ff33ef3b9017dd1a17ad3a767b0ab793806b syslog-ng-debuginfo-2.0.7-1.fc7.ppc64.rpm
4763408194f0c2ae3f700493e61c69b3b42487f2 syslog-ng-2.0.7-1.fc7.ppc64.rpm
d8809e0860d8bf55f76584a5259f3fe66547dc81 syslog-ng-debuginfo-2.0.7-1.fc7.i386.rpm
da7ed64d639fb1d2bb9d96f90cfa2cbcd927bb07 syslog-ng-2.0.7-1.fc7.i386.rpm
382ea53bcfdfd63ecb9ef7c8ebaab954c1aad7f7 syslog-ng-2.0.7-1.fc7.x86_64.rpm
8cf014c79ebb3a3872b4f408ace0d537528f7d5a syslog-ng-debuginfo-2.0.7-1.fc7.x86_64.rpm
9c62e2b28c755499b9c12e7413752c5acdb7515a syslog-ng-debuginfo-2.0.7-1.fc7.ppc.rpm
9a084cc071e8b99472e1f444d72091ebd13f731e syslog-ng-2.0.7-1.fc7.ppc.rpm
9d700680ed1efdf4f0732c259ff60b909eda1a3d syslog-ng-2.0.7-1.fc7.src.rpm

This update can be installed with the "yum" update program.  Use 
su -c 'yum update syslog-ng' 
at the command line.  For more information, refer to "Managing Software
with yum", available at http://docs.fedoraproject.org/yum/.
--------------------------------------------------------------------------------




More information about the Fedora-package-announce mailing list