MGASA-2020-0233

Source
https://advisories.mageia.org/MGASA-2020-0233.html
Import Source
https://advisories.mageia.org/MGASA-2020-0233.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0233
Related
Published
2020-05-27T09:52:46Z
Modified
2020-05-27T09:21:18Z
Summary
Updated log4net packages fix security vulnerability
Details

Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use this as an attack vector if he could modify the XML configuration file.

References
Credits

Affected packages

Mageia:7 / log4net

Package

Name
log4net
Purl
pkg:rpm/mageia/log4net?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.8-2.1.mga7

Ecosystem specific

{
    "section": "core"
}