Posted by Rainer Gerhards on Sep 20 Hello, We are publishing a GitHub Security Advisory for a denial-of-service vulnerability in the rsyslog mmpstrucdata module: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-2whq-6rcm-64m8 Affected configurations use mmpstrucdata to parse RFC 5424 structured data and accept messages large enough to carry an oversized parameter value. The module is not enabled by default. In affected versions, a crafted message could terminate...

Read the full article at oss-security →