Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 32 FEDORA-2020-73d380e9b9 Critical: log4net XXE Issue

fedora
Calendar Grey May 23, 2020
Dist Fedora Esm H88
Important log4net security update resolves XXE vulnerability in Fedora 32. Key improvement to bolster overall system defense.
Security fix for CVE-2018-1285

Summary

log4net is a tool to help the programmer output log statements to a

variety of output targets. log4net is a port of the excellent log4j

framework to the .NET runtime

Security fix for CVE-2018-1285

* Fri May 15 2020 Timotheus Pokorra - 2.0.8-10

- apply security fix for xml configurator: [CVE-2018-1285] XXE vulnerability in Apache log4net

[ 1 ] Bug #1835982 - CVE-2018-1285 log4net: XXE in applications that accept arbitrary configuration files from users

https://bugzilla.redhat.com/show_bug.cgi?id=1835982

su -c 'dnf upgrade --advisory FEDORA-2020-73d380e9b9' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 2.0.8
Release: 10.fc32
Summary: A .NET framework for logging

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here