Alerts This Week
Warning Icon 1 1,109
Alerts This Week
Warning Icon 1 1,109

Ubuntu 14.04 LTS USN-7590-1 important: apache-log4j code execution

ubuntu
Calendar Grey June 23, 2025
Dist Ubuntu Esm H88
Apache Log4j on Ubuntu 14.04 LTS poses a risk of unprivileged code execution through specially crafted files. Immediate update is advised.
Apache Log4j could be made to run programs as your login if it opened a specially crafted file.

Summary

Apache Log4j could be made to run programs as your login if it opened a

specially crafted file.

Software Description:

- apache-log4j1.2: Java-based open-source logging tool

Details:

It was discovered that several deserialization issues existed within Apache

Log4j. An attacker could possibly use these issues to enable the execution

of arbitrary code. (CVE-2022-23302, CVE-2022-23305, CVE-2022-23307)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS
  liblog4j1.2-java                1.2.17-4ubuntu3+esm2
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7590-1

CVE-2022-23302, CVE-2022-23305, CVE-2022-23307

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7590-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here