Описание
Remote code execution in ASP.NET Core
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-0603
- https://github.com/aspnet/Announcements/issues/403
- https://github.com/github/advisory-database/issues/302
- https://access.redhat.com/errata/RHSA-2020:0130
- https://access.redhat.com/errata/RHSA-2020:0134
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
Пакеты
Microsoft.AspNetCore.All
>= 2.1.0, < 2.1.15
2.1.15
Microsoft.AspNetCore.App
= 3.1.0
3.1.1
Microsoft.AspNetCore.App
= 3.0.0
3.0.1
Microsoft.AspNetCore.App
>= 2.1.0, < 2.1.15
2.1.15
Microsoft.AspNetCore.Http.Connections
>= 1.0.0, < 1.0.15
1.0.15
Microsoft.AspNetCore.App.Runtime.linux-arm
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.linux-arm64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.linux-x64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.osx-x64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.win-arm
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.win-x64
>= 3.1.0, < 3.1.1
3.1.1
Microsoft.AspNetCore.App.Runtime.win-x86
>= 3.1.0, < 3.1.1
3.1.1
Связанные уязвимости
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
Уязвимость программной платформы ASP.NET Core, существующая из-за ошибок обработки объектов в памяти, позволяющая нарушителю выполнить произвольный код
ELSA-2020-0130: .NET Core on Red Hat Enterprise Linux security and bug fix update (CRITICAL)