-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 22 Dec 2007 14:33:13 +0100 Source: syslog-ng Binary: syslog-ng Architecture: source i386 Version: 2.0.5-3+lenny1 Distribution: testing-security Urgency: high Maintainer: SZALAY Attila <sasa@debian.org> Changed-By: Nico Golde <nion@debian.org> Description: syslog-ng - Next generation logging daemon Closes: 457334 Changes: syslog-ng (2.0.5-3+lenny1) testing-security; urgency=high . * Non-maintainer upload by security team. * This update addresses the following security issue: - A remote attacker can cause a denial of service (crash) via a crafted log message that is missing a whitespace at the end of the timestamp (CVE-2007-6437; Closes: #457334). Files: b6472011ab7a60d5f41d51b3accfcb54 634 admin extra syslog-ng_2.0.5-3+lenny1.dsc c161eefc450fabc246c1a10997c6c6a5 363064 admin extra syslog-ng_2.0.5.orig.tar.gz 37ef489132204adbc7223a61d11fad6e 15699 admin extra syslog-ng_2.0.5-3+lenny1.diff.gz 942f949ae3cf5cafffbeffdb5677c36f 190648 admin extra syslog-ng_2.0.5-3+lenny1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHcP74HYflSXNkfP8RAmZYAKCbD79YM1FDrzoZjgd94ltpQr2ZYgCeKnFW qd3g0Szi711/MvNAO1Q+h6E= =cRsp -----END PGP SIGNATURE----- Accepted: syslog-ng_2.0.5-3+lenny1.diff.gz to pool/main/s/syslog-ng/syslog-ng_2.0.5-3+lenny1.diff.gz syslog-ng_2.0.5-3+lenny1.dsc to pool/main/s/syslog-ng/syslog-ng_2.0.5-3+lenny1.dsc syslog-ng_2.0.5-3+lenny1_i386.deb to pool/main/s/syslog-ng/syslog-ng_2.0.5-3+lenny1_i386.deb