An update that solves three vulnerabilities and has one errata is now available. . openSUSE Security Update: Security update for log4j12 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0226-1 Rating: important References: #1193184 #1194842 #1194843 #1194844 Cross-References: CVE-2022-23302 CVE-2022-23305 CVE-2022-23307 CVSS scores: CVE-2022-23302 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-23302 (SUSE): 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-23305 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23305 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-23307 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.4 openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves three vulnerabilities and has one errata is now available. Description: This update for log4j12 fixes the following issues: - CVE-2022-23307: Fix deserialization issue by removing the chainsaw sub-package. (bsc#1194844) - CVE-2022-23305: Fix SQL injection by removing src/main/java/org/apache/log4j/jdbc/JDBCAppender.java. (bsc#1194843) - CVE-2022-23302: Fix remote code execution by removing src/main/java/org/apache/log4j/net/JMSSink.java. (bsc#1194842) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-226=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-226=1 Package List: - openSUSE Leap 15.4 (noarch): log4j12-1.2.17-4.9.1 log4j12-javadoc-1.2.17-4.9.1 log4j12-manual-1.2.17-4.9.1 - openSUSE Leap 15.3 (noarch): log4j12-1.2.17-4.9.1 log4j12-javadoc-1.2.17-4.9.1 log4j12-manual-1.2.17-4.9.1 References: https://www.suse.com/security/cve/CVE-2022-23302.html https://www.suse.com/security/cve/CVE-2022-23305.html https://www.suse.com/security/cve/CVE-2022-23307.html https://bugzilla.suse.com/1193184 https://bugzilla.suse.com/1194842 https://bugzilla.suse.com/1194843 https://bugzilla.suse.com/1194844 . The latest patch for openSUSE resolves significant vulnerabilities in log4j12, addressing concerns related to deserialization, SQL injection, and risks of remote code execution.. log4j12 update, openSUSE security, remote code execution, SQL injection, important update. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for log4j12 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1612-1 Rating: important References: #1193662 Cross-References: CVE-2021-4104 CVSS scores: CVE-2021-4104 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for log4j12 fixes the following issues: - CVE-2021-4104: Disable the JMSAppender class from log4j to protect against the log4jshell vulnerability. [bsc#1193662] This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1612=1 Package List: - openSUSE Leap 15.2 (noarch): log4j12-1.2.17-lp152.3.3.2 log4j12-javadoc-1.2.17-lp152.3.3.2 log4j12-manual-1.2.17-lp152.3.3.2 log4j12-mini-1.2.17-lp152.3.3.2 References: https://www.suse.com/security/cve/CVE-2021-4104.html https://bugzilla.suse.com/1193662 . Upgrade your openSUSE environment with essential log4j12 security patches for enhanced defense against vulnerabilities.. openSUSE Security Update, log4j12 Patch, Vulnerability Fix, Threat Protection. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2017-5645. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-7e0ff7f73a 2017-06-12 13:03:25.116756 --------------------------------------------------------------------------------Name : log4j12 Product : Fedora 24 Version : 1.2.17 Release : 19.fc24 URL : https://logging.apache.org/log4j/1.x/ Summary : Java logging package Description : Log4j is a tool to help the programmer output log statements to a variety of output targets. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-5645 --------------------------------------------------------------------------------References: [ 1 ] Bug #1443635 - CVE-2017-5645 log4j: Socket receiver deserialization vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1443635 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade log4j12' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.