[SECURITY] [DLA 2211-1] log4net security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Package : log4net
Version : 1.2.10+dfsg-6+deb8u1
It was discovered that there was an XML external entity vulnerability
in log4net, a logging API for the ECMA Common Language Infrastructure
(CLI), sometimes referred to as "Mono".
This type of attack occurs when XML input containing a reference to
an internet-faced entity is processed by a weakly configured XML
parser. This attack may lead to the disclosure of confidential data,
denial of service, server side request forgery as well as other
system impacts.
For Debian 8 "Jessie", this issue has been fixed in log4net version
1.2.10+dfsg-6+deb8u1.
We recommend that you upgrade your log4net packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl6+hVAACgkQHpU+J9Qx
HliIxA//X56ewLJ88ReaLJ0tR1UVCpc2ZxvO8kYhu9YDL1bsyxmCGMu3TV8lOgKa
t+RIhQNtlBMnVurgn/dRsx6yiV/6p9/afL6xEjlL2kmgC/rBL8C7zb6gCc6HIkPH
E+u2wI3yl5mtMCVPx2U+7xuv+6wa6tizf8KgTlJQhw9hETNjKzzhuMXYtt3bpH6M
4oWLbFHFDOr8X/SvFOn+AjipgahGCx9jTjuL4x7a+E0CoCGO4IS2fZKOvRZPojWw
Sb2g8ODNoxqmEibZu5CY3U4daetit9tCdOruxFPqeaXe1bjA8b9QDddhviQhZpcm
9K1tjW5E7SrGNCNz6/JvMcKpVEFVAZFGjptP7fiIz06WcL/O2Ikh6kUQpFiANN5C
oApKGQ1ZRfXoPP9gUZYa6LCF/FMH2Iks3WjXSATZfNNFp+QM/btLzBcEB2r3Rebj
ugNvPoblGUdOht2alnYZkXOX2f4EhxTxPxsl43YZZf8AUKO+fsP+dtyJx0b8svGu
SpvuQVGpXSRIicF3wjQfQPhwoIEVHsZkDzriE3fJ332eQ+iA0sf2so64tP9g6Pfz
pHCWCD9qI6bRXyrYJe8rkjIG06o7gaSDCpldP3QoBHU9Mrx98hKUclQsHijwE2Ro
hUd+TgoYlttbBNaDCjySUuniJM4aVHl1ZpAJ914wUKsRVnJXNyE=
=OD0V
-----END PGP SIGNATURE-----
Reply to: