Bug#804525: rsyslog: does not clean TLS contexts on connection loss

2015-12-17 Thread David Lang
A quibble on the definition of the classification as being a Security/DoS issue. If an attacker can break TCP connections at will between two systems, the attacker has the ability to DoS those systems. Period, no further qualifiers needed. Now, this does look like it may be an issue that need

Bug#804525: rsyslog: does not clean TLS contexts on connection loss

2015-11-09 Thread Dominik George
Package: rsyslog Version: 8.4.2-1 Severity: important Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 We are using rsyslog to send logs from machine A to machine B through a TLS-authenticated TCP connection. Sometimes, the network between the two machines becomes unreliable. If th