Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Mageia: 2020-0233 Moderate: Log4net XML Processing Risk

mageia
Calendar Grey May 27, 2020
Dist Mageia Esm H88
Recent updates to log4net packages resolve an XML security flaw within the Mageia operating system. Key information regarding the critical security patch has been provided.
Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram

Summary

Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use this as an attack vector if he could modify the XML configuration file.

References

- https://bugs.mageia.org/show_bug.cgi?id=26608

- https://lists.debian.org/debian-lts-announce/2020/05/msg00014.html

- https://github.com/apache/logging-log4net/commit/d0b4b0157d4af36b23c24a23739c47925c3bd8d7

- https://www.cve.org/CVERecord?id=CVE-2018-1285

Resolution

SRPMS

- 7/core/log4net-2.0.8-2.1.mga7

Publication date: 27 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0233.html
Type: security
CVE: CVE-2018-1285

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here