apache-log4j1.2 1.2.17-10+deb11u1 source package in Debian

Changelog

apache-log4j1.2 (1.2.17-10+deb11u1) bullseye; urgency=medium

  * Team upload.
  * Fix CVE-2021-4104, CVE-2022-23302, CVE-2022-23305 and CVE-2022-23307.
    Multiple security vulnerabilities have been discovered in
    Apache Log4j 1.2 when it is configured to use JMSSink, JDBCAppender and
    JMSAppender or Apache Chainsaw. Note that a possible attacker requires
    write access to the Log4j configuration and the aforementioned features are
    not enabled by default. In order to completely mitigate against these
    vulnerabilities the related classes have been removed from the resulting
    jar file.

 -- Markus Koschany <email address hidden>  Sat, 12 Feb 2022 10:54:14 +0100

Upload details

Uploaded by:
Debian Java Maintainers
Uploaded to:
Bullseye
Original maintainer:
Debian Java Maintainers
Architectures:
all
Section:
java
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Bullseye release main java

Builds

Downloads

File Size SHA-256 Checksum
apache-log4j1.2_1.2.17-10+deb11u1.dsc 2.4 KiB f7eb156f8a25aa5bd2894023b167eea58cb5044b14b36951c06a1c86a6e8f97a
apache-log4j1.2_1.2.17.orig.tar.gz 539.1 KiB f293c2b8cb5a68c43b8c83a41891d3ef667841c2abc4dcfb172292a49eb5336f
apache-log4j1.2_1.2.17-10+deb11u1.debian.tar.xz 26.5 KiB cb18f5702e7f7f461417b5e75a62a463f61a3f68afb0420a0fb9f0958b078e7c

No changes file available.

Binary packages built by this source