Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 8 Jessie: DLA-2065-1 Critical: Apache-Log4j1.2 Remote Code Execution

debian lts
Calendar Grey January 12, 2020
Dist Debian Esm H88
Enhance apache-log4j1.2 version to mitigate remote execution vulnerability referenced in CVE-2019-17571 within Debian LTS.
Included in Log4j 1.2, a logging library for Java, is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitr...

Summary

We recommend that you upgrade your apache-log4j1.2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache-log4j1.2
Version: 1.2.17-5+deb8u1
CVE ID: CVE-2019-17571
Debian Bug: 947124

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here