First published: Thu Mar 09 2006(Updated: )
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Log4net | =1.2.9_beta | |
Apache log4net | =1.2.9_beta | |
nuget/log4net | <=1.2.9 | 1.2.10 |
=1.2.9_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0743 is classified as a medium severity vulnerability due to its potential for denial of service.
To fix CVE-2006-0743, upgrade to log4net version 1.2.10 or later.
CVE-2006-0743 can lead to memory corruption and application termination, causing a denial of service.
CVE-2006-0743 affects log4net version 1.2.9 and earlier.
Yes, CVE-2006-0743 allows remote attackers to exploit the vulnerability, leading to a denial of service.