|
|
Subscribe / Log in / New account

Debian alert DLA-2211-1 (log4net)

From:  "Chris Lamb" <lamby@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2211-1] log4net security update
Date:  Fri, 15 May 2020 08:05:28 -0400 (EDT)
Message-ID:  <20200515120528.05EDC14200A2@mailuser.nyi.internal>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : log4net Version : 1.2.10+dfsg-6+deb8u1 It was discovered that there was an XML external entity vulnerability in log4net, a logging API for the ECMA Common Language Infrastructure (CLI), sometimes referred to as "Mono". This type of attack occurs when XML input containing a reference to an internet-faced entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery as well as other system impacts. For Debian 8 "Jessie", this issue has been fixed in log4net version 1.2.10+dfsg-6+deb8u1. We recommend that you upgrade your log4net packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Regards, - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `- -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl6+hVAACgkQHpU+J9Qx HliIxA//X56ewLJ88ReaLJ0tR1UVCpc2ZxvO8kYhu9YDL1bsyxmCGMu3TV8lOgKa t+RIhQNtlBMnVurgn/dRsx6yiV/6p9/afL6xEjlL2kmgC/rBL8C7zb6gCc6HIkPH E+u2wI3yl5mtMCVPx2U+7xuv+6wa6tizf8KgTlJQhw9hETNjKzzhuMXYtt3bpH6M 4oWLbFHFDOr8X/SvFOn+AjipgahGCx9jTjuL4x7a+E0CoCGO4IS2fZKOvRZPojWw Sb2g8ODNoxqmEibZu5CY3U4daetit9tCdOruxFPqeaXe1bjA8b9QDddhviQhZpcm 9K1tjW5E7SrGNCNz6/JvMcKpVEFVAZFGjptP7fiIz06WcL/O2Ikh6kUQpFiANN5C oApKGQ1ZRfXoPP9gUZYa6LCF/FMH2Iks3WjXSATZfNNFp+QM/btLzBcEB2r3Rebj ugNvPoblGUdOht2alnYZkXOX2f4EhxTxPxsl43YZZf8AUKO+fsP+dtyJx0b8svGu SpvuQVGpXSRIicF3wjQfQPhwoIEVHsZkDzriE3fJ332eQ+iA0sf2so64tP9g6Pfz pHCWCD9qI6bRXyrYJe8rkjIG06o7gaSDCpldP3QoBHU9Mrx98hKUclQsHijwE2Ro hUd+TgoYlttbBNaDCjySUuniJM4aVHl1ZpAJ914wUKsRVnJXNyE= =OD0V -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds