=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2011/VULN176
_____________________________________________________________________

DATE                      : 03/03/2011

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running syslog-ng 3, 4 version prior to 3.0.7a, 3.2.1b, 4.0.1a.

======================================================================
https://lists.balabit.hu/pipermail/syslog-ng-announce/2011-February/000107.html
https://lists.balabit.hu/pipermail/syslog-ng-announce/2011-February/000108.html
https://lists.balabit.hu/pipermail/syslog-ng-announce/2011-February/000111.html
______________________________________________________________________

------------------------------------------------------------------------------
PACKAGE             : syslog-ng Premium Edition
VERSION             : 3.0.7a
SUMMARY             : new stable release
DATE                : Feb 24, 2011
------------------------------------------------------------------------------

DESCRIPTION:

   A new stable version of  Premium Edition (3.0.7a) has been
   released. For latest fixes in the 3.0.x branch you are recommended to
   upgrade to this version.

CHANGES:

3.0.7a
         Thu, 24 Feb 2011 12:00:00 +0100

Security updates:
	CVE-2008-4316, CVE-2008-7270, CVE-2009-3555,
	CVE-2010-4180

DOWNLOAD:

   Download the latest binaries from:

   http://www.balabit.com/network-security/syslog-ng/central-syslog-server/upgrades/

   Note that to download the binaries, you have to login into your MyBalaBit
   account.

   The documentation of the syslog-ng application is available in
   The syslog-ng 3.0 Administrator Guide at:
   http://www.balabit.com/support/documentation/?product=syslog-ng&type=all&language[en]=en&

___________________________________________________________________________

------------------------------------------------------------------------------
PACKAGE             : syslog-ng Premium Edition
VERSION             : 4.0.1a
SUMMARY             : new stable release
DATE                : Feb 24, 2011
------------------------------------------------------------------------------

DESCRIPTION:

   A new stable version of syslog-ng Premium Edition (4.0.1a) has been
   released. For a full description on stable and feature releases,
   see Section 2.16. Stable and feature releases of syslog-ng PE in The syslog-ng
   Premium Edition 4.0.1a Administrator Guide.

CHANGES:

4.0.1a

	Security updates:

	CVE-2008-7270, CVE-2010-3555, CVE-2010-4180

DOWNLOAD:

   Download the latest binaries from:

   http://www.balabit.com/network-security/syslog-ng/central-syslog-server/upgrades/

   Note that to download the binaries, you have to login into your MyBalaBit
   account.

   The documentation of the syslog-ng application is available in
   The syslog-ng Premium Edition 4.0.1a Administrator Guide at:
   http://www.balabit.com/support/documentation/

_________________________________________________________________________

------------------------------------------------------------------------------
PACKAGE             : syslog-ng Premium Edition
VERSION             : 3.2.1b
SUMMARY             : new feature release
DATE                : Feb 24, 2011
------------------------------------------------------------------------------

DESCRIPTION:

   A new feature version of syslog-ng Premium Edition (3.2.1b) has been
   released. For a full description on stable and feature releases,
   see Section 2.16. Stable and feature releases of syslog-ng PE in The syslog-ng
   Premium Edition 3.2.1b Administrator Guide.

CHANGES:

3.2.1b

	Security updates:

	CVE-2008-7270, CVE-2010-3555, CVE-2010-4180

DOWNLOAD:

   Download the latest binaries from:

   http://www.balabit.com/network-security/syslog-ng/central-syslog-server/upgrades/

   Note that to download the binaries, you have to login into your MyBalaBit
   account.

   The documentation of the syslog-ng application is available in
   The syslog-ng Premium Edition 3.2.1b Administrator Guide at:
   http://www.balabit.com/support/documentation/



======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================

