--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2025-537e8b4657
2025-10-12 00:36:18.282829+00:00
--------------------------------------------------------------------------------

Name        : log4cxx
Product     : Fedora EPEL 10.2
Version     : 1.5.0
Release     : 1.el10_2
URL         : http://logging.apache.org/log4cxx/index.html
Summary     : A port to C++ of the Log4j project
Description :
Log4cxx is a popular logging package written in C++. One of its distinctive
features is the notion of inheritance in loggers. Using a logger hierarchy it
is possible to control which log statements are output at arbitrary
granularity. This helps reduce the volume of logged output and minimize the
cost of logging.

--------------------------------------------------------------------------------
Update Information:

Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct  3 2025 Till Hofmann <[email protected]> - 1.5.0-1
- Update to 1.5.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2393058 - CVE-2025-54812 log4cxx: Log4cxx HTMLLayout XSS 
Vulnerability [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2393058
  [ 2 ] Bug #2393129 - CVE-2025-54813 log4cxx: Log4cxx: Improper JSON Output 
Neutralization [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2393129
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update log4cxx' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to