Java Log4j vulnerability

This forum is dedicated to advanced help and support :

Ask here your questions about advanced usage of Mageia. For example you may post here all your questions about network and automated installs, complex server configurations, kernel tuning, creating your own Mageia mirrors, and all tasks likely to be touchy even for skilled users.

Java Log4j vulnerability

Postby brm » Dec 15th, '21, 23:30

Hi all. Should we be worried about the java log4j vulnerability? Any suggestions for Mageia users about this?

I came across this script and include it for others. Use at your own risk. It will search your system for log4j files.
https://raw.githubusercontent.com/rubo77/log4j . . . (snip}

Disclaimer.
Mid Level Linux user here.
I am not a developer.

Feel free to move this post to a better forum if necessary.
brm
 
Posts: 60
Joined: Sep 2nd, '18, 09:45

Re: Java Log4j vulnerability

Postby sturmvogel » Dec 15th, '21, 23:32

For such stuff it is always recommended to follow our bugtracker. The latest secured log4j version 2.16 is already in our testing repo and QA process.
https://bugs.mageia.org/show_bug.cgi?id=29766
sturmvogel
 
Posts: 741
Joined: Jul 30th, '12, 00:39

Re: Java Log4j vulnerability

Postby brm » Dec 15th, '21, 23:40

I look forward to this fix coming through our updates.
Thanks
brm
 
Posts: 60
Joined: Sep 2nd, '18, 09:45

Re: Java Log4j vulnerability

Postby doktor5000 » Dec 15th, '21, 23:45

brm wrote:Hi all. Should we be worried about the java log4j vulnerability? Any suggestions for Mageia users about this?

Nothing specific for Mageia, as this basically affects nearly everyone in some kind of way, even when it's not directly on your own Mageia install.
BTW your link seems to be incomplete, probably this one: https://github.com/rubo77/log4j_checker_beta

If you're not a developer, to understand the issue at hand and some context information and also some hints on how to avoid or fix this, have a look at e.g. https://www.youtube.com/watch?v=7qoPDq41xhQ
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18054
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: Java Log4j vulnerability

Postby papoteur » Dec 22nd, '21, 12:47

2.17 release of log4j is now available as update
papoteur
 
Posts: 93
Joined: Oct 27th, '11, 22:28


Return to Advanced support

Who is online

Users browsing this forum: Google [Bot] and 1 guest

cron