QID 997194

Date Published: 2024-02-12

QID 997194: DotNet (Nuget) Security Update for log4net (GHSA-f9fr-w54q-772h)

Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Github security advisory GHSA-f9fr-w54q-772h for updates and patch information.
    Vendor References

    CVEs related to QID 997194

    Software Advisories
    Advisory ID Software Component Link
    GHSA-f9fr-w54q-772h log4net URL Logo github.com/advisories/GHSA-f9fr-w54q-772h