Bug#1001478: apache-log4j2: CVE-2021-44228:: Remote code injection via crafted log messages

2021-12-11 Thread Markus Koschany
Am Samstag, dem 11.12.2021 um 10:52 -0800 schrieb tony mancill: > On Fri, Dec 10, 2021 at 10:42:24PM +0100, Markus Koschany wrote: > > Control: owner -1 ! > > > > I am currently investigating the fix for CVE-2021-44228. > > Hi Markus, > > Thank you both for the quick turn-around on this and for

Bug#1001478: apache-log4j2: CVE-2021-44228:: Remote code injection via crafted log messages

2021-12-11 Thread tony mancill
On Fri, Dec 10, 2021 at 10:42:24PM +0100, Markus Koschany wrote: > Control: owner -1 ! > > I am currently investigating the fix for CVE-2021-44228. Hi Markus, Thank you both for the quick turn-around on this and for claiming ownership of the bug in the BTS. I had started looking at the update

Bug#1001478: apache-log4j2: CVE-2021-44228:: Remote code injection via crafted log messages

2021-12-10 Thread Markus Koschany
Control: owner -1 ! I am currently investigating the fix for CVE-2021-44228. Markus signature.asc Description: This is a digitally signed message part

Bug#1001478: apache-log4j2: CVE-2021-44228:: Remote code injection via crafted log messages

2021-12-10 Thread Salvatore Bonaccorso
Source: apache-log4j2 Version: 2.13.3-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://issues.apache.org/jira/browse/LOG4J2-3198 https://github.com/apache/logging-log4j2/pull/608 X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1