Instalar Steam
iniciar sesión
|
idioma
简体中文 (Chino simplificado)
繁體中文 (Chino tradicional)
日本語 (Japonés)
한국어 (Coreano)
ไทย (Tailandés)
български (Búlgaro)
Čeština (Checo)
Dansk (Danés)
Deutsch (Alemán)
English (Inglés)
Español - España
Ελληνικά (Griego)
Français (Francés)
Italiano
Bahasa Indonesia (indonesio)
Magyar (Húngaro)
Nederlands (Holandés)
Norsk (Noruego)
Polski (Polaco)
Português (Portugués de Portugal)
Português - Brasil (Portugués - Brasil)
Română (Rumano)
Русский (Ruso)
Suomi (Finés)
Svenska (Sueco)
Türkçe (Turco)
Tiếng Việt (Vietnamita)
Українська (Ucraniano)
Informar de un error de traducción
https://www.reddit.com/r/Steam/comments/rd68yp/a_vulnerability_in_log4jjava_logging_package/ho1yyaa/
Even if a program or game uses Java then that's no guarantee that it also relies on Log4j. It's not as if this issue applies to everything that uses the Java runtime. Heck, even if a Java program does rely on Log4j then that by itself is also no guarantee that it's open to attack because.. Using Java doesn't automatically imply that remote network connections are a thing.
This was a fairly big issue for Java Minecraft because Java Minecraft is still extremely popular due to its ability to mod, and it was very bad that both servers and clients could execute the code simply by an attacker typing in public chat which would get logged by the server and clients and run the exploit
They already released a new version, though I'm still on 1.16.5, since my critical mods haven't been updated yet. But it's a simple manual fix.
https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-from-new-code-execution-bug/
For those who can't install the fix right away, Spigot and other sources have said that adding the JVM flag -Dlog4j2.formatMsgNoLookups=true neutralizes the threat for most Java versions. Spigot and many other services have already inserted the flag into the games they make available to users.
To add the flag users should go to their launcher, open the installations tab, select the installation in use and click "..." > "Edit" > "MORE OPTIONS", and paste -Dlog4j2.formatMsgNoLookups=true at the end of the JVM flags.
Might have to search around for that config file, since I'm on MultiMC. Microsoft can go cram their nagware launcher where the sun don't shine. I'm never using their stinking walled garden store.
if also like to know if there is anything going on with steam.
If you look above you'd see the answer was already given that there is no problem in regards to Steam.
No because there was never a need to provide one.
They would have patched their websites.
The steam client itself was never vunlerable