5397a7a9 by Markus Koschany at 2020-05-02T16:36:11+02:00
Import Debian changes 1.2.17-7

apache-log4j1.2 (1.2.17-7) unstable; urgency=medium

  * Team upload.
  * Transition to bnd 2.1.0.
  * Vcs-Browser: Use https.

- - - - -
a0103883 by Markus Koschany at 2020-05-02T16:38:13+02:00
Add CVE-2019-17571.patch

- - - - -
8596f85b by Markus Koschany at 2020-05-02T16:39:30+02:00
Update changelog

- - - - -
a529695e by Markus Koschany at 2022-01-31T13:16:06+01:00
Really apply the patches

- - - - -
9710d682 by Markus Koschany at 2022-01-31T13:18:33+01:00
Mitigate the impact of CVE-2022-23302 CVE-2022-23305 CVE-2022-23307

- - - - -
a21c0e08 by Markus Koschany at 2022-01-31T13:19:37+01:00
Really apply the patches

- - - - -
a8f7a6fe by Markus Koschany at 2022-01-31T13:20:05+01:00
Mitigate against CVE-2021-4104

- - - - -
4215efaf by Markus Koschany at 2022-01-31T13:28:23+01:00
Update changelog

- - - - -
feec4213 by Markus Koschany at 2022-02-12T10:39:25+01:00
Merge branch 'stretch' into buster

- - - - -
406287eb by Markus Koschany at 2022-02-12T10:43:36+01:00
Update changelog

- - - - -

6 changed files:

- debian/changelog
- + debian/patches/CVE-2021-4104.patch
- + debian/patches/CVE-2022-23302.patch
- + debian/patches/CVE-2022-23305.patch
- + debian/patches/CVE-2022-23307.patch
- debian/patches/series


@@ -1,3 +1,17 @@
+apache-log4j1.2 (1.2.17-8+deb10u2) buster; urgency=medium
+  * Team upload.
+  * Fix CVE-2021-4104, CVE-2022-23302, CVE-2022-23305 and CVE-2022-23307.
+    Multiple security vulnerabilities have been discovered in
+    Apache Log4j 1.2 when it is configured to use JMSSink, JDBCAppender and
+    JMSAppender or Apache Chainsaw. Note that a possible attacker requires
+    write access to the Log4j configuration and the aforementioned features are
+    not enabled by default. In order to completely mitigate against these
+    vulnerabilities the related classes have been removed from the resulting
+    jar file.
+ -- Markus Koschany <apo at debian.org>  Sat, 12 Feb 2022 10:40:19 +0100
 apache-log4j1.2 (1.2.17-8+deb10u1) buster-security; urgency=high
   * Team upload.

