ALT-BU-2014-2736-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2025-04-11
CVE-2013-4758
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JSON response.
- http://www.openwall.com/lists/oss-security/2013/07/05/2
- http://www.rsyslog.com/rsyslog-7-4-2-v7-stable-released/
- http://www.rsyslog.com/rsyslog-7-5-2-v7-devel-released/
- http://www.openwall.com/lists/oss-security/2013/07/05/2
- http://www.rsyslog.com/rsyslog-7-4-2-v7-stable-released/
- http://www.rsyslog.com/rsyslog-7-5-2-v7-devel-released/
Closed vulnerabilities
Modified: 2025-04-12
CVE-2014-2915
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.
- http://www.openwall.com/lists/oss-security/2014/04/22/10
- http://www.openwall.com/lists/oss-security/2014/04/23/2
- http://www.securitytracker.com/id/1030135
- http://xenbits.xen.org/xsa/advisory-93.html
- http://www.openwall.com/lists/oss-security/2014/04/22/10
- http://www.openwall.com/lists/oss-security/2014/04/23/2
- http://www.securitytracker.com/id/1030135
- http://xenbits.xen.org/xsa/advisory-93.html
Modified: 2025-04-12
CVE-2014-2986
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.
- http://www.openwall.com/lists/oss-security/2014/04/23/3
- http://www.openwall.com/lists/oss-security/2014/04/23/4
- http://www.openwall.com/lists/oss-security/2014/04/23/5
- http://www.securityfocus.com/bid/67047
- http://www.securitytracker.com/id/1030146
- http://xenbits.xen.org/xsa/advisory-94.html
- http://www.openwall.com/lists/oss-security/2014/04/23/3
- http://www.openwall.com/lists/oss-security/2014/04/23/4
- http://www.openwall.com/lists/oss-security/2014/04/23/5
- http://www.securityfocus.com/bid/67047
- http://www.securitytracker.com/id/1030146
- http://xenbits.xen.org/xsa/advisory-94.html