CVE-2017-5645
published 2017-04-17CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially…
PriorityP186critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
89.04%
99.8th percentile
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Affected
171 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | >= 2.0 < 2.8.2 | 2.8.2 |
| apache | logging | — | — |
| apache_software_foundation | apache_log4j | — | — |
| debian | apache-log4j2 | < apache-log4j2 2.7-2 (bookworm) | apache-log4j2 2.7-2 (bookworm) |
| oracle | api_gateway | — | — |
| oracle | application_testing_suite | — | — |
| oracle | autovue_vuelink_integration | — | — |
| oracle | autovue_vuelink_integration | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | bi_publisher | — | — |
| oracle | bi_publisher | — | — |
| oracle | bi_publisher | — | — |
| oracle | bi_publisher | — | — |
| oracle | communications_converged_application_server_service_controller | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | communications_interactive_session_recorder | 6.0 – 6.2 | — |
| oracle | communications_messaging_server | < 8.0.2 | 8.0.2 |
| oracle | communications_network_integrity | 7.3.2 – 7.3.6 | — |
| oracle | communications_online_mediation_controller | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | communications_service_broker | — | — |
| oracle | communications_webrtc_session_controller | < 7.2 | 7.2 |
Detection & IOCsextracted from sources · hover to see the quote
port4712
- →The vulnerability is triggered by sending a specially crafted serialized binary payload over TCP or UDP to Log4j's socket server. Detection should focus on unexpected or malformed Java serialized objects arriving on Log4j TCP socket server ports (default 4712). ↗
- →The Nuclei template for this CVE uses an OAST/interactsh DNS callback to confirm exploitation — monitor for unexpected outbound DNS queries originating from Log4j socket server processes as a sign of successful deserialization RCE.
- →The Nuclei template targets port 4712 as the Log4j TCP socket server port; network-level detection should alert on inbound connections to this port carrying Java serialized object magic bytes.
- ·Affected versions are Apache Log4j 2.x before 2.8.2. The vulnerability only exists when the TCP socket server or UDP socket server feature is explicitly enabled to receive serialized log events — it is not active by default in all deployments. ↗
- ·The Nuclei template sends two requests (max-request: 2) — one to the primary hostname and one specifically to port 4712 — meaning scanners should probe both the standard service port and 4712 to achieve full coverage.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_apache9.8HIGH
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Deserialization of Untrusted Data in Log4j
ghsa·2020-01-06
CVE-2017-5645 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Log4j
Deserialization of Untrusted Data in Log4j
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
OSV
Deserialization of Untrusted Data in Log4j
osv·2020-01-06
CVE-2017-5645 [CRITICAL] Deserialization of Untrusted Data in Log4j
Deserialization of Untrusted Data in Log4j
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
OSV
CVE-2017-5645: In Apache Log4j 2
osv·2017-04-17·CVSS 9.8
CVE-2017-5645 [CRITICAL] CVE-2017-5645: In Apache Log4j 2
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache Log4j) — CVE-2017-5645
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2017-5645 [CRITICAL] Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache Log4j) — CVE-2017-5645
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Install (Apache Log4j) vulnerability
CVE: CVE-2017-5645
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Cartridge Management (Log4j) — CVE-2017-5645
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2017-5645 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Cartridge Management (Log4j) — CVE-2017-5645
Oracle Oracle Communications Applications Risk Matrix: Cartridge Management (Log4j) vulnerability
CVE: CVE-2017-5645
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Logging (Log4j) — CVE-2017-5645
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2017-5645 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Logging (Log4j) — CVE-2017-5645
Oracle Oracle Construction and Engineering Risk Matrix: Logging (Log4j) vulnerability
CVE: CVE-2017-5645
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Log4j) — CVE-2017-5645
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2017-5645 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Core (Log4j) — CVE-2017-5645
Oracle Oracle Communications Applications Risk Matrix: Core (Log4j) vulnerability
CVE: CVE-2017-5645
CVSS: 9.8
Protocol: XMPP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Red Hat
log4j: deserialization of untrusted data in SocketServer
vendor_redhat·2019-12-20·CVSS 9.8
CVE-2019-17571 [CRITICAL] CWE-502 log4j: deserialization of untrusted data in SocketServer
log4j: deserialization of untrusted data in SocketServer
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
A flaw was discovered in Log4j, where a vulnerable SocketServer class may lead to the deserialization of untrusted data. This flaw allows an attacker to remotely execute arbitrary code when combined with a deserialization gadget.
Statement: This is the same issue as CVE-2017-5645. MITRE has CVE-2017-5645 to a similar flaw found in log4j-2.x. The flaw found in log4j-1.2 has been assigned CVE-2019-17571. CVE-2019-17571 has b
Red Hat
log4j: Socket receiver deserialization vulnerability
vendor_redhat·2017-04-02·CVSS 9.8
CVE-2017-5645 [CRITICAL] CWE-502 log4j: Socket receiver deserialization vulnerability
log4j: Socket receiver deserialization vulnerability
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
It was found that when using remote logging with log4j socket server the log4j server would deserialize any log event received via TCP or UDP. An attacker could use this flaw to send a specially crafted log event that, during deserialization, would execute arbitrary code in the context of the logger application.
Statement: The flaw in Log4j-1.x is now identified by CVE-2019-17571. CVE-2017-5645 has been assigned by MITRE to a similar flaw identified in Log4j-2.x
Package: hawtio-osgi (Red Hat
Debian
CVE-2017-5645: apache-log4j2 - In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket...
vendor_debian·2017·CVSS 9.8
CVE-2017-5645 [CRITICAL] CVE-2017-5645: apache-log4j2 - In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket...
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2.7-2)
bullseye: resolved (fixed in 2.7-2)
forky: resolved (fixed in 2.7-2)
sid: resolved (fixed in 2.7-2)
trixie: resolved (fixed in 2.7-2)
Apache
Apache logging: CVE-2017-5645
vendor_apache·CVSS 9.8
CVE-2017-5645 [HIGH] Apache logging: CVE-2017-5645
Apache logging: CVE-2017-5645
Summary TCP/UDP socket servers can be exploited to execute arbitrary code CVSS 2.0 Score & Vector 7.5 HIGH (AV:N/AC:L/Au:N/C:P/I:P/A:P) Components affected log4j-core Versions affected [2.0-alpha1, 2.8.2) Versions fixed 2.8.2 (for Java 7 and later)
Severity: high
Affected versions: 2.8.2
No detection rules found.
Nuclei
Apache Log4j Server - Deserialization Command Execution
nuclei·CVSS 9.8
CVE-2017-5645 [CRITICAL] Apache Log4j Server - Deserialization Command Execution
Apache Log4j Server - Deserialization Command Execution
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Template:
id: CVE-2017-5645
info:
name: Apache Log4j Server - Deserialization Command Execution
author: princechaddha
severity: critical
description: |
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
impact: |
Successful exploitation of this vulnerability could allow remote attackers to execut
Bugzilla
CVE-2019-17571 log4j: deserialization of untrusted data in SocketServer
bugzilla·2019-12-20·CVSS 9.8
CVE-2019-17571 [CRITICAL] CVE-2019-17571 log4j: deserialization of untrusted data in SocketServer
CVE-2019-17571 log4j: deserialization of untrusted data in SocketServer
Included in Log4j 1.2 is a SocketServer class that is vulnerable to
deserialization of untrusted data which can be exploited to remotely
execute arbitrary code when combined with a deserialization gadget
when listening to untrusted network traffic for log data.
References:
https://logging.apache.org/log4j/1.2/
https://issues.apache.org/jira/browse/LOG4J2-1863
https://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3E
Discussion:
Created log4j tracking bugs for this issue:
Affects: fedora-all [bug 1785617]
Created log4j12 tracking bugs for this issue:
Affects: fedora-all [bug 1785618]
---
There is no SocketServer in nodejs-log4js, setting Quay to
Bugzilla
CVE-2019-17571 log4j12: log4j: deserialization of untrusted data in SocketServer [fedora-all]
bugzilla·2019-12-20·CVSS 9.8
CVE-2019-17571 [CRITICAL] CVE-2019-17571 log4j12: log4j: deserialization of untrusted data in SocketServer [fedora-all]
CVE-2019-17571 log4j12: log4j: deserialization of untrusted data in SocketServer [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2017-5645 log4j12: log4j: Socket receiver deserialization vulnerability [fedora-all]
bugzilla·2017-06-01·CVSS 9.8
CVE-2017-5645 [CRITICAL] CVE-2017-5645 log4j12: log4j: Socket receiver deserialization vulnerability [fedora-all]
CVE-2017-5645 log4j12: log4j: Socket receiver deserialization vulnerability [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1443635
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users restart after up
Bugzilla
CVE-2017-5645 log4j: Socket receiver deserialization vulnerability [fedora-all]
bugzilla·2017-04-19·CVSS 9.8
CVE-2017-5645 [CRITICAL] CVE-2017-5645 log4j: Socket receiver deserialization vulnerability [fedora-all]
CVE-2017-5645 log4j: Socket receiver deserialization vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2017-5645 log4j: Socket receiver deserialization vulnerability
bugzilla·2017-04-19·CVSS 9.8
CVE-2017-5645 [CRITICAL] CVE-2017-5645 log4j: Socket receiver deserialization vulnerability
CVE-2017-5645 log4j: Socket receiver deserialization vulnerability
When using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
References:
http://seclists.org/oss-sec/2017/q2/78
Upstream bug:
https://issues.apache.org/jira/browse/LOG4J2-1863
Discussion:
Created log4j tracking bugs for this issue:
Affects: fedora-all [bug 1443637]
---
JBoss fuse ships log4j in, karaf/pax logging, cxf, fabric8, activemq and hawtio components.
---
Both EAP 5 and JON3 don't have the affect Tcp and Udp SocketServer classes
---
Created log4j12 tracking bugs for this issue:
Affects: fedora-all [bug 1457722]
---
This issue has been addressed in th
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking o
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 9.8
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Threat Research Center
Threat Research
Vulnerabilities
## Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Tao Yan
Qi Deng
Haozhe Zhang
Yu Fu
Josh Grunzweig
Mike Harbison
Robert Falcone
Published: December 10, 2021
Threat Research
Vulnerabilities
Apache Log4j
CVE-2017-5645
CVE-2019-17571
CVE-2021-44228
CVE-2021-44832
CVE-2021-45046
CVE-2021-45105
Denial of service
Exploit
Log4j
Log4j 2
RCE
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vu
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15·CVSS 9.8
[CRITICAL] Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Blog / Cyber Exposure Alerts
Subscribe
# Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Satnam Narang
January 15, 2019
2 Min Read
Oracle addresses nearly 300 vulnerabilities in the first Critical Patch Update of 2019.
## Background
On January 15, Oracle released its Critical Patch Update, a quarterly publication of fixes for vulnerabilities. This month’s update contains nearly 300 fixes across a number of Oracle products.
## Analysis
The Critical Patch Update for January 2019 addresses a variety of vulnerabilities. For instance, Oracle published 30 fixes for MySQL, including a fix for MySQL Workbench to address the libssh vulnerability (CVE-2018-10933). There are also several fixes for CVE-2017-5645, a deserialization vulnerability in Apache Log4j, as well as CV
CTF
20181130-pwn2winctf / README
ctf_writeups·2018
20181130-pwn2winctf / README
# Pwn2Win CTF 2018
**It's recommended to read our responsive [web version](https://balsn.tw/ctf_writeup/20181130-pwn2winctf/) of this writeup.**
- [Pwn2Win CTF 2018](#pwn2win-ctf-2018)
- [Crypto](#crypto)
- [Back to Bletchley Park](#back-to-bletchley-park)
- [GCM](#gcm)
- [Web](#web)
- [Berg’s Club](#bergs-club)
- [Identify The Function](#identify-the-function)
- [RCE](#rce)
- [Failed Attempts](#failed-attempts)
- [Message Board I (File Inclusion)](#message-board-i-file-inclusion)
- [Information Leak](#information-leak)
- [XML or JSON?](#xml-or-json)
- [Message Board II (RCE)](#message-board-ii-rce)
- [Tomcat Manager](#tomcat-manager)
- [Almighty Gopher](#almighty-gopher)
- [Gopher Pitfall (Intended Solution 1)](#gopher-pitfall-intended-solution-1)
- [jar (Possibly Intended Solution 2)]
http://www.openwall.com/lists/oss-security/2019/12/19/2http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/97702http://www.securitytracker.com/id/1040200http://www.securitytracker.com/id/1041294https://access.redhat.com/errata/RHSA-2017:1417https://access.redhat.com/errata/RHSA-2017:1801https://access.redhat.com/errata/RHSA-2017:1802https://access.redhat.com/errata/RHSA-2017:2423https://access.redhat.com/errata/RHSA-2017:2633https://access.redhat.com/errata/RHSA-2017:2635https://access.redhat.com/errata/RHSA-2017:2636https://access.redhat.com/errata/RHSA-2017:2637https://access.redhat.com/errata/RHSA-2017:2638https://access.redhat.com/errata/RHSA-2017:2808https://access.redhat.com/errata/RHSA-2017:2809https://access.redhat.com/errata/RHSA-2017:2810https://access.redhat.com/errata/RHSA-2017:2811https://access.redhat.com/errata/RHSA-2017:2888https://access.redhat.com/errata/RHSA-2017:2889https://access.redhat.com/errata/RHSA-2017:3244https://access.redhat.com/errata/RHSA-2017:3399https://access.redhat.com/errata/RHSA-2017:3400https://access.redhat.com/errata/RHSA-2019:1545https://issues.apache.org/jira/browse/LOG4J2-1863https://lists.apache.org/thread.html/0dcca05274d20ef2d72584edcf8c917bbb13dbbd7eb35cae909d02e9%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/277b4b5c2b0e06a825ccec565fa65bd671f35a4d58e3e2ec5d0618e1%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/44491fb9cc19acc901f7cff34acb7376619f15638439416e3e14761c%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/479471e6debd608c837b9815b76eab24676657d4444fcfd5ef96d6e6%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/6114ce566200d76e3cc45c521a62c2c5a4eac15738248f58a99f622c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/84cc4266238e057b95eb95dfd8b29d46a2592e7672c12c92f68b2917%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/8ab32b4c9f1826f20add7c40be08909de9f58a89dc1de9c09953f5ac%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/e8fb7d76a244ee997ba4b217d6171227f7c2521af8c7c5b16cba27bc%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/eea03d504b36e8f870e8321d908e1def1addda16adda04327fe7c125%40%3Cdev.logging.apache.org%3Ehttps://lists.apache.org/thread.html/r0831e2e52a390758ce39a6193f82c11c295175adce6e6307de28c287%40%3Cissues.beam.apache.org%3Ehttps://lists.apache.org/thread.html/r18f1c010b554a3a2d761e8ffffd8674fd4747bcbcf16c643d708318c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.apache.org/thread.html/r23369fd603eb6d62d3b883a0a28d12052dcbd1d6d531137124cd7f83%40%3Cgithub.beam.apache.org%3Ehttps://lists.apache.org/thread.html/r2ce8d26154bea939536e6cf27ed02d3192bf5c5d04df885a80fe89b3%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r2ff63f210842a3c5e42f03a35d8f3a345134d073c80a04077341c211%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r3784834e80df2f284577a5596340fb84346c91a2dea6a073e65e3397%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r3a85514a518f3080ab1fc2652cfe122c2ccf67cfb32356acb1b08fe8%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r3d666e4e8905157f3c046d31398b04f2bfd4519e31f266de108c6919%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r4b25538be50126194cc646836c718b1a4d8f71bd9c912af5b59134ad%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r61590890edcc64140e0c606954b29a063c3d08a2b41d447256d51a78%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r681b4432d0605f327b68b9f8a42662993e699d04614de4851c35ffd1%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r746fbc3fc13aee292ae6851f7a5080f592fa3a67b983c6887cdb1fc5%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/r7bcdc710857725c311b856c0b82cee6207178af5dcde1bd43d289826%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/r94b5aae09c4bcff5d06cf641be17b00bd83ba7e10cad737bf16a1b8f%40%3Cgithub.beam.apache.org%3Ehttps://lists.apache.org/thread.html/r9d5c1b558a15d374bd5abd2d3ae3ca7e50e796a0efdcf91e9c5b4cdd%40%3Cgithub.beam.apache.org%3Ehttps://lists.apache.org/thread.html/ra38785cfc0e7f17f8e24bebf775dd032c033fadcaea29e5bc9fffc60%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/ra9a682bc0a8dff1c5cefdef31c7c25f096d9121207cf2d74e2fc563d%40%3Ccommits.logging.apache.org%3Ehttps://lists.apache.org/thread.html/raedd12dc24412b3780432bf202a2618a21a727788543e5337a458ead%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb1b29aee737e1c37fe1d48528cb0febac4f5deed51f5412e6fdfe2bf%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rbfa7a0742be4981a3f9356a23d0e1a5f2e1eabde32a1a3d8e41420f8%40%3Cgithub.beam.apache.org%3Ehttps://lists.apache.org/thread.html/rc1eaed7f7d774d5d02f66e49baced31e04827a1293d61a70bd003ca7%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/rca24a281000fb681d7e26e5c031a21eb4b0593a7735f781b53dae4e2%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/rcbb79023a7c8494cb389cd3d95420fa9e0d531ece0b780b8c1f99422%40%3Ccommits.doris.apache.org%3Ehttps://lists.apache.org/thread.html/rd5dbeee4808c0f2b9b51479b50de3cc6adb1072c332a200d9107f13e%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rdbd579dc223f06af826d7de340218ee2f80d8b43fa7e4decb2a63f44%40%3Cgithub.beam.apache.org%3Ehttps://lists.apache.org/thread.html/rdec0d8ac1f03e6905b0de2df1d5fcdb98b94556e4f6cccf7519fdb26%40%3Cdev.tika.apache.org%3Ehttps://lists.apache.org/thread.html/re8c21ed9dd218c217d242ffa90778428e446b082b5e1c29f567e8374%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rf2567488cfc9212b42e34c6393cfa1c14e30e4838b98dda84d71041f%40%3Cdev.tika.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20180726-0002/https://security.netapp.com/advisory/ntap-20181107-0002/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://www.openwall.com/lists/oss-security/2019/12/19/2http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/97702http://www.securitytracker.com/id/1040200http://www.securitytracker.com/id/1041294https://access.redhat.com/errata/RHSA-2017:1417https://access.redhat.com/errata/RHSA-2017:1801https://access.redhat.com/errata/RHSA-2017:1802https://access.redhat.com/errata/RHSA-2017:2423https://access.redhat.com/errata/RHSA-2017:2633https://access.redhat.com/errata/RHSA-2017:2635https://access.redhat.com/errata/RHSA-2017:2636https://access.redhat.com/errata/RHSA-2017:2637https://access.redhat.com/errata/RHSA-2017:2638https://access.redhat.com/errata/RHSA-2017:2808
+ 64 more references
2017-04-17
Published