[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2211-1] log4net security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : log4net
Version        : 1.2.10+dfsg-6+deb8u1

It was discovered that there was an XML external entity vulnerability
in log4net, a logging API for the ECMA Common Language Infrastructure
(CLI), sometimes referred to as "Mono".

This type of attack occurs when XML input containing a reference to
an internet-faced entity is processed by a weakly configured XML
parser. This attack may lead to the disclosure of confidential data,
denial of service, server side request forgery as well as other
system impacts.

For Debian 8 "Jessie", this issue has been fixed in log4net version
1.2.10+dfsg-6+deb8u1.

We recommend that you upgrade your log4net packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl6+hVAACgkQHpU+J9Qx
HliIxA//X56ewLJ88ReaLJ0tR1UVCpc2ZxvO8kYhu9YDL1bsyxmCGMu3TV8lOgKa
t+RIhQNtlBMnVurgn/dRsx6yiV/6p9/afL6xEjlL2kmgC/rBL8C7zb6gCc6HIkPH
E+u2wI3yl5mtMCVPx2U+7xuv+6wa6tizf8KgTlJQhw9hETNjKzzhuMXYtt3bpH6M
4oWLbFHFDOr8X/SvFOn+AjipgahGCx9jTjuL4x7a+E0CoCGO4IS2fZKOvRZPojWw
Sb2g8ODNoxqmEibZu5CY3U4daetit9tCdOruxFPqeaXe1bjA8b9QDddhviQhZpcm
9K1tjW5E7SrGNCNz6/JvMcKpVEFVAZFGjptP7fiIz06WcL/O2Ikh6kUQpFiANN5C
oApKGQ1ZRfXoPP9gUZYa6LCF/FMH2Iks3WjXSATZfNNFp+QM/btLzBcEB2r3Rebj
ugNvPoblGUdOht2alnYZkXOX2f4EhxTxPxsl43YZZf8AUKO+fsP+dtyJx0b8svGu
SpvuQVGpXSRIicF3wjQfQPhwoIEVHsZkDzriE3fJ332eQ+iA0sf2so64tP9g6Pfz
pHCWCD9qI6bRXyrYJe8rkjIG06o7gaSDCpldP3QoBHU9Mrx98hKUclQsHijwE2Ro
hUd+TgoYlttbBNaDCjySUuniJM4aVHl1ZpAJ914wUKsRVnJXNyE=
=OD0V
-----END PGP SIGNATURE-----


Reply to: