========================================================================== Ubuntu Security Notice USN-7590-1 June 23, 2025 apache-log4j1.2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Apache Log4j could be made to run programs as your login if it opened a specially crafted file. Software Description: - apache-log4j1.2: Java-based open-source logging tool Details: It was discovered that several deserialization issues existed within Apache Log4j. An attacker could possibly use these issues to enable the execution of arbitrary code. (CVE-2022-23302, CVE-2022-23305, CVE-2022-23307) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS liblog4j1.2-java 1.2.17-4ubuntu3+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7590-1 CVE-2022-23302, CVE-2022-23305, CVE-2022-23307