Mailing List Archive

rsyslog 3.21.8 (v3-beta) released - IMPORTANT SECURITY RELEASE
Hi all,

We have just released rsyslog 3.21.8, a member of the v3-beta branch.
Most importantly, this release addresses a security vulnerability the
renders the $AllowedSender directive useless. This issue has already
been discussed here on the list. In addition to this, the release also
contains all the bug fixes and enhancements from the stable release
3.20.1.

Security Advisory:
http://www.rsyslog.com/Article322.phtml

Download:
http://www.rsyslog.com/Downloads-req-viewdownloaddetails-lid-142.phtml

Change Log:
http://www.rsyslog.com/Article326.phtml

All users are advised to update to this release. It is urgently
recommended not only for those that would be vulnerable to the security
issue but also to anyone using TLS-based communications.

Releases for the devel branch will hopefully be posted later today. The
git archive has all relevant patches if someone has an urgent need.

As always, feedback is appreciated. We hope this release will be useful.

Florian Riedl
--
Support
=======

Improving rsyslog is costly, but you can help! We are looking for
organizations that find rsyslog useful and wish to contribute back. You
can contribute by reporting bugs, improve the software, or donate money
or equipment.

Commercial support contracts for rsyslog are available, and they help
finance continued maintenance. Adiscon GmbH, a privately held German
company, is currently funding rsyslog development. We are always looking
for interesting development projects. For details on how to help, please
see http://www.rsyslog.com/doc-how2help.html .


_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com
Re: rsyslog 3.21.8 (v3-beta) released - IMPORTANT SECURITY RELEASE [ In reply to ]
On Thu, 4 Dec 2008 13:34:08 +0100, Florian Riedl wrote:
> Hi all,
>
> We have just released rsyslog 3.21.8, a member of the v3-beta branch.
> Most importantly, this release addresses a security vulnerability the
> renders the $AllowedSender directive useless. This issue has already
> been discussed here on the list. In addition to this, the release also
> contains all the bug fixes and enhancements from the stable release
> 3.20.1.
<snip>

I believe the following is worthy of note in regards to this.

On Thu, 4 Dec 2008 17:40:43 +0100, Rainer Gerhards wrote:
> 3.21.8 has now also been replaced by 3.21.9. As with 3.20.2, links
> remain intact. 3.21.8 has probably never been downloaded, but I thought
> it is saver to use a new version number, especially as it is a security
> issue.
>
> Rainer

--
Elisamuel Resto <samuel@dragonboricua.net>
Source Mage Tome Lead / http://sourcemage.org
GPG ID: 18615F19/1024D / http://simplysam.us
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com