Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-0875

Опубликовано: 15 мар. 2018
Источник: msrc
EPSS Средний

Описание

.NET Core Denial of Service Vulnerability

A denial of service vulnerability exists in the way that .NET Core handles specially crafted requests, causing a hash collision.

To exploit the vulnerability, an attacker could send a small number of specially crafted requests to an .NET Core web application, causing performance to degrade significantly enough to cause a denial of service condition.

The security update addresses the vulnerability by correcting how .NET Core handles specially crafted requests to prevent a hash collision.

Обновления

ПродуктСтатьяОбновление
.NET Core 1.0
.NET Core 1.1
.NET Core 2.0
PowerShell Core 6.0.0

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 94%
0.13893
Средний

Связанные уязвимости

CVSS3: 3.7
redhat
больше 7 лет назад

.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".

CVSS3: 7.5
nvd
больше 7 лет назад

.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".

CVSS3: 7.5
github
около 3 лет назад

.NET Core Denial of Service Vulnerability

EPSS

Процентиль: 94%
0.13893
Средний