Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.2.17-7ubuntu1+esm1", "binary_name": "liblog4j1.2-java" }, { "binary_version": "1.2.17-7ubuntu1+esm1", "binary_name": "liblog4j1.2-java-doc" } ] }