openSUSE-SU-2026:20705-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20705-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20705-1
Upstream
Related
Published
2026-05-07T10:19:52Z
Modified
2026-05-09T18:25:07Z
Summary
Security update for log4cxx
Details

This update for log4cxx fixes the following issues:

Changes in log4cxx:

  • update to 1.7.0 (bsc#1261994, CVE-2026-40023):

    • Non-ascii characters incorrectly encoded in JSON output [#615]
    • XML output could contain characters not allowed by the XML 1.0 specification
    • An XML configuration file with recursive references caused program termination [#605]
    • Possible undefined behavior during a configuration change
    • Message loss when the calculation of a logged value also logs
    • ODBCAppender prepared statement value buffers had incorrect lifetimes [#581]
  • update to 1.6.0:

    • Configuration ${varname} values can be set programatically prior to loading a configuration file (see com/foo/config4.cpp) [#520]
    • The current executable's file name and its components are available for use in a configuration file and the LOG4CXX_CONFIGURATION environment variable (see log4cxx::spi::Configurator::properties). [#520]
    • Console output (Log4cxx internal logging and BasicConfigurator) use a color per message level by default [#529]
    • New logging macros that defer binary-to-text conversion until used in AsyncAppender's background thread
    • A simplified way to attach an AsyncAppender to a logger using a configuration file [#550]
References

Affected packages