[ubuntu/groovy-security] log4net 1.2.10+dfsg-7ubuntu0.20.10.1 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Tue Jan 19 13:04:42 UTC 2021


log4net (1.2.10+dfsg-7ubuntu0.20.10.1) groovy-security; urgency=medium

  * SECURITY UPDATE: XXE-based attacks
    - XmlConfigurator: do longer allow dtd processing across all
      platforms in src/Config/XmlConfigurator.cs.
    - CVE-2018-1285

Date: 2021-01-18 18:13:17.919812+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/log4net/1.2.10+dfsg-7ubuntu0.20.10.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Groovy-changes mailing list