CVE-2021-44228

270 views
Skip to first unread message

mi...@witsmd.com

unread,
Dec 13, 2021, 12:00:25 PM12/13/21
to dcm4che
Can anyone elaborate on the vulnerability of the dcm4che 5.17 libs using log4j    ???

Gunter Zeilinger

unread,
Dec 13, 2021, 12:09:40 PM12/13/21
to dcm4che
dcm4che does not use log4j2. The library itself can use any logging framework which implements the slf4j api or for which a bridge to the slf4j api  is available. So you may also change the default of the dcm4che utilities using log4j 1.2.17 via slf4j-log4j12 1.7.30.

drovn...@gmail.com

unread,
Dec 13, 2021, 6:03:54 PM12/13/21
to dcm4che
Can someone elaborate on the older versions of dcm4che - like 2.x that use log4j. I have a set of field units that use 2.x. It's not clear what version of log4j is being used from what I can see - and there is different guidance out there depending on log4j versions. I realize 1.x log4j is EOL, I just need to make a plan here.

Dave

Gunter Zeilinger

unread,
Dec 14, 2021, 5:14:34 AM12/14/21
to dcm...@googlegroups.com
Major cause of security risks still using dcm4chee-2.x are cause by outdated JBoss version, and not by using log4j 1.x for logging!

‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
--
You received this message because you are subscribed to the Google Groups "dcm4che" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dcm4che+u...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/dcm4che/da6ca769-6274-4c62-bcea-0dacfc827dc0n%40googlegroups.com.
Reply all
Reply to author
Forward
0 new messages