Mandrakelinux Advisory: sysklogdApr 29, 2004, 05:30 (0 Talkback[s])
Mandrakelinux Security Update Advisory
Package name: sysklogd
Steve Grubb discovered a bug in sysklogd where it allocates an insufficient amount of memory which causes sysklogd to write to unallocated memory. This could allow for a malicious user to crash sysklogd.
The updated packages provide a patched sysklogd using patches from Openwall to correct the problem and also corrects the use of an unitialized variable (a previous use of "count").
Corporate Server 2.1:
Corporate Server 2.1/x86_64:
Multi Network Firewall 8.2:
To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
A list of FTP mirrors can be obtained from:
All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing:
gpg --recv-keys --keyserver www.mandrakesecure.net 0x22458A98
Please be aware that sometimes it takes the mirrors a few hours to update.
You can view other update advisories for Mandrakelinux at:
Mandrakesoft has several security-related mailing list services that anyone can subscribe to. Information on these lists can be obtained by visiting:
If you want to report vulnerabilities, please contact
Type Bits/KeyID Date User ID
0 Talkback[s] (click to add your comment)