Описание
.NET Framework and .NET Core Denial of Service Vulnerability
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET Framework (or .NET core) application.
The update addresses the vulnerability by correcting how .NET Framework and .NET Core applications handle RegEx string processing.
Обновления
Продукт | Статья | Обновление |
---|---|---|
.NET Core 1.0 | ||
.NET Core 1.1 | ||
PowerShell Core 6.1 | ||
.NET Core 2.1 | ||
.NET Core 2.2 | ||
PowerShell Core 6.2 | ||
Microsoft .NET Framework 3.5 on Windows 10 Version 1903 for x64-based Systems | ||
Microsoft .NET Framework 3.5 on Windows 10 Version 1903 for 32-bit Systems | ||
Microsoft .NET Framework 3.5 on Windows Server, version 1903 (Server Core installation) | ||
Microsoft .NET Framework 4.7.2 on Windows 10 Version 1803 for 32-bit Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
Связанные уязвимости
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Regular Expression Denial of Service in System.Text.RegularExpressions
Уязвимость программных платформ .NET Core и Microsoft .NET Framework, связанная с ошибками при обработке регулярных выражений,позволяющая нарушителю вызвать отказ в обслуживании
ELSA-2019-1259: dotnet security, bug fix, and enhancement update (IMPORTANT)
EPSS