Bug 31901 - log4cxx possible new security issue CVE-2023-31038
Summary: log4cxx possible new security issue CVE-2023-31038
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-05-09 16:16 CEST by David Walser
Modified: 2024-01-12 10:49 CET (History)
2 users (show)

See Also:
Source RPM: log4cxx-0.10.0-14.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 1.1.0


Attachments

Description David Walser 2023-05-09 16:16:38 CEST
Apache has issued an advisory on May 7:
https://www.openwall.com/lists/oss-security/2023/05/07/3

The issue is fixed upstream in 1.1.0.

It is only affected if ODBC support is enabled in the build; I am not sure if this is the case for our package.

If it is, Mageia 8 is also affected.
David Walser 2023-05-09 16:16:49 CEST

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 1.1.0

Comment 1 Lewis Smith 2023-05-10 21:26:28 CEST
This SRPM is scarcely touched, so no packager in view. Assigning globally.

Assignee: bugsquad => pkg-bugs

Comment 2 David GEIGER 2023-07-03 05:07:48 CEST
fixed for cauldron updating to latest 1.1.0 release!

Whiteboard: MGA8TOO => (none)
CC: (none) => geiger.david68210
Version: Cauldron => 8

Comment 3 Nicolas Salguero 2024-01-12 10:49:59 CET
Mageia 8 EOL

CC: (none) => nicolas.salguero
Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.