Control: severity -1 grave Hi
On Tue, Dec 15, 2020 at 01:20:04PM +0100, Moritz Muehlenhoff wrote: > Source: log4net > Severity: important > Tags: security > X-Debbugs-Cc: Debian Security Team <[email protected]> > > Please see https://issues.apache.org/jira/browse/LOG4NET-575 > > Patch: > https://github.com/apache/logging-log4net/commit/d0b4b0157d4af36b23c24a23739c47925c3bd8d7 Altough the issue no-dsa for stable releases, it seems worth includign the fix in unstable and so future bullseye, and for that raising the severity to RC. Is log4net still maintained in Debian? We seme to have 1.2.10+dfsg-7 across all still supported suites. Regards, Salvatore

