We believe that the bug you reported is fixed in the latest version of
log4net, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1133360@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
James Montgomery <james_montgomery@disroot.org> (supplier of updated log4net package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 22 May 2026 19:39:08 -0400
Source: log4net
Architecture: source
Version: 1.2.10+dfsg-10
Distribution: unstable
Urgency: medium
Maintainer: Debian .NET Team <debian-cli@lists.debian.org>
Changed-By: James Montgomery <james_montgomery@disroot.org>
Closes: 1102176 1112150 1133360 1137352
Changes:
log4net (1.2.10+dfsg-10) unstable; urgency=medium
.
* Team upload. Adopt into the Debian .NET Team.
- Update Maintainer to Debian .NET Team <debian-cli@lists.debian.org>
- Add James Montgomery <james_montgomery@disroot.org> to Uploaders
- Bump Standards-Version to 4.7.2 (no changes required)
- Set Rules-Requires-Root: no
- Update Homepage to use https://
(Closes: #1137352)
* Remove cli-common build and runtime integration:
- Drop cli-common-dev from Build-Depends-Indep and obsolete ${cli:Depends}
- Remove dh_installcligac, dh_cligacpolicy, dh_clifixperms, dh_makeclilibs,
dh_clideps calls from debian/rules
- Delete debian/cligacpolicy and debian/installcligac
- Add explicit Mono runtime dependencies for liblog4net1.2-cil
- Keep built log4net.dll non-executable (chmod 0644)
(Closes: #1112150, #1102176)
* Fix XmlLayout invalid character handling (CVE-2026-40021):
- Backport upstream fix from PR #280 (merged in log4net 3.3.0):
wrap WriteAttributeString calls on user-controlled fields with
Transform.MaskXmlInvalidCharacters() in XMLLayout.cs and
XmlLayoutSchemaLog4j.cs
(Closes: #1133360)
Checksums-Sha1:
df48c871751c6359ab48c7f7cbe7fd4fb73cfc70 1935 log4net_1.2.10+dfsg-10.dsc
bd0fea831de4d5c636e5b0993987c1d6590518a7 6716 log4net_1.2.10+dfsg-10.debian.tar.xz
9e4e2d6017f286d8504f819896061fe6fbc4e3e6 5561 log4net_1.2.10+dfsg-10_source.buildinfo
Checksums-Sha256:
d6ec8efd0fe8e9c169609bc38874e3d525bba777169f122d6ef8b281a3a9169b 1935 log4net_1.2.10+dfsg-10.dsc
04871115b545f349afe92ea744b1d741e5a6ef48f6fb8b427170c44f5c77a99f 6716 log4net_1.2.10+dfsg-10.debian.tar.xz
16b94659c2d70eff7c40363c20e88fe039a3544ed0293779c6acefae7ca3a695 5561 log4net_1.2.10+dfsg-10_source.buildinfo
Files:
287694b4e359924f9db2daa3966a8c35 1935 libs optional log4net_1.2.10+dfsg-10.dsc
30dfe40069469a2b0e4019a0e43931c7 6716 libs optional log4net_1.2.10+dfsg-10.debian.tar.xz
4b81dae2aec6b542c565c39daa3cb6da 5561 libs optional log4net_1.2.10+dfsg-10_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmokZTQQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFDLTDADlKM8NOA67Gr+XlcMur/1tLCJ2CD0m3QaY
QbiKfQzJs5GDfTyYZqi8cMQnbtLS5DNCFHlmUttKhffdQKAcH1C0H9kWqpB+wDSr
hEMIhI9e+PWdyArrL1LezO4nzem/0fmZpQpGgwVsm+uQ2pDBaURN6TFzEVu0/WZ3
HMeE8l1r7EMgMslsukJcMp679itzXyuDLG9DcZfSeYqKkb2loqlCk5Dzs7kUSY7G
daGUmHFWWsqO5Ho6HEtLp4d7gxRIeQDZz5iHhL8sxmQud4MovEDKisalVLNK+k+6
ERliXI18GUUeNsQhtMWL8hzS36neZHTxoeHIuu6F4UK1kZWZb1cCYNIArllyH3Ng
SKWjYXV0f80xFxAeaaZ8xP/XXzqgQAfhjs5CbzY1I/9TLIQR/gI5emKDDPXJht7k
lDxcfg5e6OFA7qqaHaAhufn3YRs4iE8vMllH/Rw9MtgVq9bdCujDT8LvRMW8UnSF
wwrvV21nzj5SA+29KhoMbOBxR0MR2/Q=
=1wU4
-----END PGP SIGNATURE-----