Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package log4j for openSUSE:Factory checked in at 2021-12-30 17:10:28 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/log4j (Old) and /work/SRC/openSUSE:Factory/.log4j.new.1896 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "log4j" Thu Dec 30 17:10:28 2021 rev:35 rq:943087 version:2.17.1 Changes: -------- --- /work/SRC/openSUSE:Factory/log4j/log4j.changes 2021-12-18 20:31:17.890277601 +0100 +++ /work/SRC/openSUSE:Factory/.log4j.new.1896/log4j.changes 2021-12-30 17:10:30.350855507 +0100 @@ -1,0 +2,24 @@ +Wed Dec 29 08:34:08 UTC 2021 - David Anes <david.a...@suse.com> + +- Update to 2.17.1 [bsc#1194127, CVE-2021-44832] + * Fixed bugs: + - JdbcAppender now uses JndiManager to access JNDI resources. + JNDI is only enabled when system property log4j2.enableJndiJdbc + is set to true. + - Remove unused method. + - ExtendedLoggerWrapper.logMessage no longer double-logs when + location is requested. + - log4j-to-slf4j no longer re-interpolates formatted message + contents. + - Correct SpringLookup package name in Interpolator. + - log4j-to-slf4j takes the provided MessageFactory into account. + - Fix MapLookup to lookup MapMessage before DefaultMap. + - Buffered I/O checked had inverted logic in + RollingFileAppenderBuidler. + - Fix NPE when input is null in + StrSubstitutor.replace(String, Properties). + - Lookups with no prefix only read values from the configuration + properties as expected. + - Reduce ignored package scope of KafkaAppender. + +------------------------------------------------------------------- Old: ---- apache-log4j-2.17.0-src.tar.gz apache-log4j-2.17.0-src.tar.gz.asc New: ---- apache-log4j-2.17.1-src.tar.gz apache-log4j-2.17.1-src.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ log4j.spec ++++++ --- /var/tmp/diff_new_pack.1uUB4R/_old 2021-12-30 17:10:31.094855921 +0100 +++ /var/tmp/diff_new_pack.1uUB4R/_new 2021-12-30 17:10:31.102855926 +0100 @@ -17,7 +17,7 @@ Name: log4j -Version: 2.17.0 +Version: 2.17.1 Release: 0 Summary: Java logging package License: Apache-2.0 ++++++ apache-log4j-2.17.0-src.tar.gz -> apache-log4j-2.17.1-src.tar.gz ++++++ /work/SRC/openSUSE:Factory/log4j/apache-log4j-2.17.0-src.tar.gz /work/SRC/openSUSE:Factory/.log4j.new.1896/apache-log4j-2.17.1-src.tar.gz differ: char 25, line 1 ++++++ log4j.keyring ++++++ --- /var/tmp/diff_new_pack.1uUB4R/_old 2021-12-30 17:10:31.162855959 +0100 +++ /var/tmp/diff_new_pack.1uUB4R/_new 2021-12-30 17:10:31.166855961 +0100 @@ -1033,4 +1033,76 @@ UJ9MVCU= =yL9f -----END PGP PUBLIC KEY BLOCK----- +pub rsa4096/0x47B1D6AD0E682C9C 2020-08-03 [SC] + Key fingerprint = C47B C76D F019 2CB2 9465 BBCF 47B1 D6AD 0E68 2C9C +uid [ full ] Davyd McColl <dav...@gmail.com> +sig 3 0x47B1D6AD0E682C9C 2020-08-03 Davyd McColl <dav...@gmail.com> +sig 0xD7C92B70FA1C814D 2020-09-21 Matt Sicker (Apache Software Foundation) <mattsic...@apache.org> +sub rsa4096/0x7C9D34B68B32C4AE 2020-08-03 [E] + Key fingerprint = 8CEF B3E7 914C 238C 44F5 37D6 7C9D 34B6 8B32 C4AE +sig 0x47B1D6AD0E682C9C 2020-08-03 Davyd McColl <dav...@gmail.com> + +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQINBF8oTHsBEACtTmXDTFTPaJoqnWjhsN1qY20kVPRLdPNrdJqTL8KeUAFtw/R8 +cop8P3sSbMX4UcR9kZrk4TLQSzxcJ02MllUCrusl6XklWWrfprJMzheX1eX8ZD2A +rjFS2s6dIKRAO0PsCGPs43LGA5mK2NENdy+Tjv18UzeX/329psAkzZFtdJeq9FH4 +qE9GPbyEDIDbd1taFhfwguF8ED5XZiqOUvQwevjOecHD93hTEI2q0MdDSfmP/yud +xCHxk7uC0g0qVt5O9hopimbB1A4U3dmyg11OUdf0QHuaHTcpHQcGPlOq05EiL8h/ +1In+L91MNgfMr36l9Mm8pB6uxDLpzVdU8HgHb4X1WngapqgpXfvdvf0I4f4B8SG4 +xF53NEy2ERiH2vouxGcqujyIsiTT3ChkD5VoMkdw2KCU2sw/yGJcCVq/FJuhayBw +SR/cmKOGNGsbKLav8k3ni8T6PcUP90V/yEwPP0rKuEFInEVMSNk5vFo4SwW4V8ei +Hni/KRhblyPb4dM6VADXEkh6MMxmlBkvQWOWWWTeST+PgLJWQElfQaz+iqHS/zE8 +/ls8Fwxs2dep2JF50trbHwWDOE7beGYfERBBYeJTipM023pRUztTFwXvY73DII9f +rBQ885YcQYO3V1n01HB78q0B2nVavgf60Nklbj1KW/9OQIMsLiHdjVBsIQARAQAB +tB9EYXZ5ZCBNY0NvbGwgPGRhdnlkbUBnbWFpbC5jb20+iQJOBBMBCAA4FiEExHvH +bfAZLLKUZbvPR7HWrQ5oLJwFAl8oTHsCGwMFCwkIBwIGFQoJCAsCBBYCAwECHgEC +F4AACgkQR7HWrQ5oLJyLWRAAnj3BIjtjvvnRjJswCGR88AVR+C62Wuk8EuZtO2P6 +LTRSROlIdDgNgdodHhURfGtpJ3haxnm5dFA3Y5JD57ujbWZle30xKLcxb29cFDEG +w9y+DA406kO5E4Wp7uv3vNW77slrVlqB24NT3fke1jhhLiToqj6D37W4pmGDCfGY +w82Im2jmC4NVdf1SUd8IyY2G/M+3zBHqUYqAiD5njsXiG9Jlea9s0/MoGriresNR +AKx9PlzYTaNuTe1pLORyW7fr9rtFBdoxcKNO+zmX4yYSvzpaAKB8QPFegXKMLXFw +/72iFUHfp4cSmllgla4T+y8x6JmY8jgL+/kSIKRykzoJdzhSTjxuOiC66TpVGwAM +zRF6efYAb97/7qaV4Idfp6MGJVJKymF7lkH4ogeUGBXM79gqBt3Coyrc8RJYyDLH +HQwGTTaELUXHiYLZOIRbuXbVr9lSq1ZT9czF9im7WTgnfI+6s5Si+o7F5LuMFw88 +rRQDhL4Xt66xd5YGM1DHLDbAmDZECOjMGyhnPysgXPxMiDr24x1TIA2e4DIr5/zo +CPyEqKka0lROiAa9oIESOuU3QCVv0tBLvwjQLMlaOrwVq5jgnLA66yNgW6AGxMUk +fYb1V3uuZde5q2SUgYJfGzS5eBNDaB3z7Jbvd58L28tjgnGUpjNUEP/V533y7C1u +k+GJAjMEEAEKAB0WIQR0jxWyz5uo8CQVXm7XyStw+hyBTQUCX2jKOwAKCRDXyStw ++hyBTRyBD/9dRf5juxM+e68wT0wDga64HvNDIx7RooVmuQg4Dg/9M8hU4ZMhifp1 +aViX0EEQ6iMjDHC/gJd62WGgcFW09tL98NsRE/mnUanxZHrEuUGA1H2mrx9CQYwR +/u8LFJOrISF0zv8fpgwbpsEgH5DP3ffuVyPI+adlms8EoJ8xY1udciIFWI5w/pXx +elHor9y2uXJqm/tYEz+nt1iwdkYh51rM8KP2ISHTPWt0QTeO0Bd5R985M4SwfpOg +SuX1sipj2Y+145Q8vgiBlAbKF6DbzfoO+1EiSbm6lxppFSAoiEhjkfMVgEtpbaZs +xwXk9d9EQ3uuuVqvEd2rVCJ7z9CYSsXI/CxchqANkQUMuSw5XuD11jpMCmRffRLU +O9s9RG6qhioPLCVR00csbBAMx0gNOa0pmX4hn126c2QgDM74PdQ3nGjpzkp+/L1k +XSOjXsbwi8ypdo2Esl8ueOxVP4rm+kOqRkxxlhQOqQ/dQ7iQfuc+cQBxA8PKVg4Y +5bwheSBtZ41zpdrAfY7fCdrktzmNrR6lwu7oWXuJkEVMux8vr1m+dAIDQ1SLk+lK +aZfmNDGDZXxFVJqxC4bjVAiScczicv3dqMcdKVQiqXSZUW8d0SszRvviwwrSY41D +GXj+TJv1k0i8I3L/Gnuxyyw1JHSLooOXlGUTcK5Q4NBlww5RFXzkArkCDQRfKEx7 +ARAAxaYrEWmSLH4yyxFx4IIz9HiwrlGpUmcegAOx9KRqNmxF8ADm39/K9UyxPRj1 +eWf1xqboXqAI8x4uK/PjKnWGNY6OMZSrTT0Z8NESlLafxSQzvgrup3LQmmrT2pHV +48FcEwDT5Y7I4RGWtj11wyPLbZhheWVJo7rKNSHZMmm5fNwWuBfRPl0+5XialOZn +NbYlmxWEeuoj6Gb24/ewYA1enHm1+jjrOfbjaJx152VayCL/+CqdNqDciRLA/Xwn +HiR2AUyNDwV5utcKLsF88r4iRlMZuz9YN96rcMscyjl9ulonMYdahXEkY66GkYVA +7k7bhs4pW3Adn5wE43rR6QYN7KnhatmBFeD3wCDtSV+C/EIGcbGil9lYlPekeux5 +hdlGcqs/VlPqQOcGKBf3N9ArL5sXk0dvqgY+oCMEJGwgYjmuWPP1GE/KB8LATE+M +AzJFIMdowy0xD3D+dSAucjcdylNzzvYLVp22ofkuiB8yikpyolBh7Xk+GzEUVUPC +O0tnniaOgJ88+TS+89087Bht7NBsAAnfg39Daozs0PBt5kjzt/oRo0rcpKInnsAD +n8TBMOOJGPQ2G5MwEOMf6ezAbqOAFrD96V6urUrxn2jg2rbyTJFrLi2gQrSf7PMW +a7mzBOn8BY0vKtnFaV39dWhEZJrlCME1QPpN0gBalrwmeakAEQEAAYkCNgQYAQgA +IBYhBMR7x23wGSyylGW7z0ex1q0OaCycBQJfKEx7AhsMAAoJEEex1q0OaCycOMwP +/jsabCnOQO8RrRMMZxz8vjgjk5Ff0cpq93C1a+0eTC0Xca3dUpfjoh5yXVHh7GBj +xYk5p4J3qaBa2tP4pVKBZJxG9R5yra3GTqkEjg78jLCHecK0IJwK5fkJiW8ygsPp +7e/nXs4i1nwm9uKzSrWI4iaua5kFyIK0M+UTN4pvygzBhY4GllDjCAT5j5ceDRsu +FhMRBFZaTXswQS4IGf9FdrlRj0EN0WRFMyvwkXJnDqM2vgnhyknc1ZYoBGdVpAzB +IbrJkyjE3K7LkyS5yeO78dla6b4rNepNekVF+CCdmKj6Sqq5c2qhIfPMmessOgRE +p+uHjQJNlruFYe/WJMFzpxcuf0jDb8qo8rirPCjiRpZyREZwWFB6uR2RtXhACPvo +XbfCpDBFadFptbY0q/7WT68iC83kryVua5bGWTJ49HS2Lj8o+L7tXaKKXTxSwlKq +prMFRdhAUJUnFUc3zFYjZUjnyZ50pGTOoEm9p835bRN46dUIKdcquSPyXj4MpzjN +svFu3wrm9c1+nV3bvBifIeTfW1xI6wQX3WeAX/+4ltsisijwph+sr74PpGd136Hu +75mDGFRQNbKy3xyya0TPe8KI2/t5pj2Leef43xkcg45w/XUqxGT+mdbedovi+UPi ++owaSa+HENWCk/rfNLKCrwVFSKOUJgHuYmeq3rTYN2RZ +=hEmT +-----END PGP PUBLIC KEY BLOCK-----