Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian LTS DLA-2852-1: Apache Log4j2 DoS Threat Security Advisory

debian lts
Calendar Grey December 26, 2021
Dist Debian Esm H88
Enhance the security of Apache Log4j2 in Debian LTS due to various vulnerabilities. Refer to advisory DLA-2852-1 for comprehensive information.
Several security vulnerabilities were found in Apache Log4j2, a Logging Framework for Java, which could lead to a denial of service or information disclosure

Summary

Improper validation of certificate with host mismatch in Apache Log4j SMTP
appender. This could allow an SMTPS connection to be intercepted by a
man-in-the-middle attack which could leak any log messages sent through
that appender.

CVE-2021-45105

Apache Log4j2 did not protect from uncontrolled recursion from
self-referential lookups. This allows an attacker with control over Thread
Context Map data to cause a denial of service when a crafted string is
interpreted.

For Debian 9 stretch, these problems have been fixed in version
2.12.3-0+deb9u1.

We recommend that you upgrade your apache-log4j2 packages.

For the detailed security status of apache-log4j2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/apache-log4j2

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: apache-log4j2
Version: 2.12.3-0+deb9u1
CVE ID: CVE-2020-9488 CVE-2021-45105
Debian Bug: 959450 1001891

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here