Bug 20693 - log4j and log4j12 new security issue CVE-2017-5645
Summary: log4j and log4j12 new security issue CVE-2017-5645
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Nicolas Lécureuil
QA Contact: Sec team
URL: https://security-tracker.debian.org/t...
Whiteboard:
Keywords:
: 25916 26082 (view as bug list)
Depends on:
Blocks:
 
Reported: 2017-04-17 22:35 CEST by David Walser
Modified: 2020-01-15 22:58 CET (History)
2 users (show)

See Also:
Source RPM: log4j-2.5-5.mga6.src.rpm, log4j12-1.2.17-16.mga6.src.rpm
CVE: CVE-2017-5645
Status comment:


Attachments

Description David Walser 2017-04-17 22:35:27 CEST
Upstream has issued an advisory today (April 17):
http://openwall.com/lists/oss-security/2017/04/17/2

The issue is fixed in 2.8.2.

Mageia 5 is also affected.
David Walser 2017-04-17 22:35:40 CEST

Whiteboard: (none) => MGA5TOO
CC: (none) => geiger.david68210
Severity: normal => critical

Nicolas Lécureuil 2017-04-22 21:53:20 CEST

URL: (none) => https://security-tracker.debian.org/tracker/CVE-2017-5645
CVE: (none) => CVE-2017-5645

Comment 2 Nicolas Lécureuil 2017-05-03 12:18:38 CEST
Fixed in cauldron

Version: Cauldron => 5
Whiteboard: MGA5TOO => (none)

Comment 3 David Walser 2017-06-10 01:23:08 CEST
log4j12 is also affected.

Fedora has issued an advisory for this today (June 9):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/W6J67CAARU2NKXKRHLJFICQ2KQFGZG2Z/

Summary: log4j new security issue CVE-2017-5645 => log4j and log4j12 new security issue CVE-2017-5645
Version: 5 => Cauldron
Whiteboard: (none) => MGA5TOO
Source RPM: log4j-2.5-5.mga6.src.rpm => log4j-2.5-5.mga6.src.rpm, log4j12-1.2.17-16.mga6.src.rpm

Comment 4 David Walser 2017-06-13 16:25:02 CEST
Fixed in log4j12-1.2.17-17.mga6 in Cauldron.

Whiteboard: MGA5TOO => (none)
Version: Cauldron => 5

Comment 5 David Walser 2017-12-27 05:01:55 CET
We won't be fixing this type of package for Mageia 5.

Status: NEW => RESOLVED
Resolution: (none) => OLD

Comment 6 David Walser 2019-12-20 21:57:33 CET
*** Bug 25916 has been marked as a duplicate of this bug. ***
Comment 7 David Walser 2020-01-13 23:44:11 CET
Just noting this is also being called CVE-2019-17571:
http://lists.suse.com/pipermail/sle-security-updates/2020-January/006316.html
Comment 8 David Walser 2020-01-15 22:58:53 CET
*** Bug 26082 has been marked as a duplicate of this bug. ***

CC: (none) => zombie.ryushu


Note You need to log in before you can comment on or make changes to this bug.