PT-2026-107233 · Apache · Log4Net
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache log4net versions 1.2.9 through 3.4.x
Description
Improper handling of Unicode encoding in the
SmtpPickupDirAppender occurs when the mail file writer encounters content it cannot encode, such as an unpaired UTF-16 surrogate. This causes the write operation to fail, resulting in the discard of every buffered event in the batch and potentially leaving a truncated mail file in the pickup directory. An attacker capable of influencing log message content could use this behavior to suppress records of other events. Only applications utilizing the SmtpPickupDirAppender are affected.Recommendations
Upgrade to version 3.5.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Log4Net