Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1b48c1a920 2025-10-12 01:09:51.211551+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 41 Version : 1.5.0 Release : 1.fc41 URL : https://logging.apache.org/log4cxx/1.5.0/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2025 Till Hofmann - 1.5.0-1 - Update to 1.5.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393061 - CVE-2025-54812 log4cxx: Log4cxx HTMLLayout XSS Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393061 [ 2 ] Bug #2393132 - CVE-2025-54813 log4cxx: Log4cxx: Improper JSON Output Neutralization [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393132 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1b48c1a920' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-14573 http://linux.oracle.com/errata/ELSA-2025-14573.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aide-0.16-15.el8_10.2.x86_64.rpm aarch64: aide-0.16-15.el8_10.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/aide-0.16-15.el8_10.2.src.rpm Related CVEs: CVE-2025-54389 Description of changes: [0.16.15.2] - CVE-2025-54389 aide: improper output neutralization enables bypassing resolves: RHEL-109907 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.