summaryrefslogtreecommitdiffstats
path: root/ChangeLog
diff options
context:
space:
mode:
authorRainer Gerhards <rgerhards@adiscon.com>2011-08-30 14:53:31 +0200
committerRainer Gerhards <rgerhards@adiscon.com>2011-08-30 14:53:31 +0200
commit581daa5418548dda4c9b5438878559a1bbd4b087 (patch)
tree1898549f1911901d716d171f9745c68dbb0a7403 /ChangeLog
parente4c44a77fd36539ff80f7d8b1257f70fd2e46ea5 (diff)
parentd654e51e2c54e6042a73ee6c95062c916161cdbe (diff)
downloadrsyslog-581daa5418548dda4c9b5438878559a1bbd4b087.tar.gz
rsyslog-581daa5418548dda4c9b5438878559a1bbd4b087.tar.xz
rsyslog-581daa5418548dda4c9b5438878559a1bbd4b087.zip
Merge branch 'v4-stable' into v4-beta
Conflicts: ChangeLog
Diffstat (limited to 'ChangeLog')
-rw-r--r--ChangeLog8
1 files changed, 5 insertions, 3 deletions
diff --git a/ChangeLog b/ChangeLog
index 73648ab3..381d729a 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,5 +1,6 @@
---------------------------------------------------------------------------
-Version 4.7.5 [v4-beta] (al), 2011-??-??
+Version 4.7.5 [v4-beta] (al), 2011-09-01
+- bugfix/security: off-by-two bug in legacy syslog parser, CVE-2011-3200
- bugfix: potential misadressing in property replacer
- bugfix: The NUL-Byte for the syslogtag was not copied in MsgDup (msg.c)
---------------------------------------------------------------------------
@@ -79,9 +80,10 @@ Version 4.7.0 [v4-devel] (rgerhards), 2010-04-14
(bugs require certain non-standard settings to appear)
Thanks to varmojfekoj for the patch [imported from 4.5.8]
---------------------------------------------------------------------------
-Version 4.6.8 [v4-stable] (rgerhards), 2011-??-??
+Version 4.6.8 [v4-stable] (rgerhards), 2011-09-01
+- bugfix/security: off-by-two bug in legacy syslog parser, CVE-2011-3200
- bugfix: potential misadressing in property replacer
-- bugfix: memcpy overflow can occur in allowed sender checkig
+- bugfix: memcpy overflow can occur in allowed sender checking
if a name is resolved to IPv4-mapped-on-IPv6 address
Found by Ismail Dönmez at suse
- bugfix: The NUL-Byte for the syslogtag was not copied in MsgDup (msg.c)