<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="a04c9d58d09b512f61f28547476596ba"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="367">
  <id>dbg111-rsyslog</id>
  <title>rsyslog security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1229548493"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=457273" id="457273" title="bug number 457273" type="bugzilla"/>
  </references>
  <description>rsyslog ignored the $AllowedSender configuration directive,
therefore accepting log messages from anyone
(CVE-2008-5617).

Additionally imudp logged a message when unauthorized
senders tried to send to it, therefore allowing attackers
to flood the log CVE-2008-5618).
</description>
  <pkglist>
    <collection>
        <package name="rsyslog" arch="i586" version="3.18.3" release="4.2">
          <filename>rsyslog-3.18.3-4.2.i586.rpm</filename>
        </package>
        <package name="rsyslog-debuginfo" arch="ppc" version="3.18.3" release="4.2">
          <filename>rsyslog-debuginfo-3.18.3-4.2.ppc.rpm</filename>
        </package>
        <package name="rsyslog-debuginfo" arch="x86_64" version="3.18.3" release="4.2">
          <filename>rsyslog-debuginfo-3.18.3-4.2.x86_64.rpm</filename>
        </package>
        <package name="rsyslog-debugsource" arch="ppc" version="3.18.3" release="4.2">
          <filename>rsyslog-debugsource-3.18.3-4.2.ppc.rpm</filename>
        </package>
        <package name="rsyslog-debugsource" arch="x86_64" version="3.18.3" release="4.2">
          <filename>rsyslog-debugsource-3.18.3-4.2.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
