Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-8409

Опубликовано: 11 сент. 2018
Источник: msrc
EPSS Средний

Описание

System.IO.Pipelines Denial of Service

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines. The vulnerability can be exploited remotely, without authentication.

A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application.

The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.

Обновления

ПродуктСтатьяОбновление
ASP.NET Core 2.1
.NET Core 2.1
System.IO.Pipelines

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 94%
0.14749
Средний

Связанные уязвимости

CVSS3: 5.1
redhat
больше 7 лет назад

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

CVSS3: 7.5
nvd
больше 7 лет назад

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

CVSS3: 7.5
github
больше 7 лет назад

Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость библиотеки System.IO.Pipelines программных платформ .NET Core и ASP.NET Core, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.14749
Средний