Описание
Bond Denial of Service Vulnerability
A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input. An attacker who successfully exploited the vulnerability could cause a process using Bond to stop responding.
To exploit this vulnerability, an attacker would need to upload specially crafted content to a Bond parser.
The update addresses the vulnerability by correcting the way Bond processes input.
FAQ
Which versions of Bond contain the vulnerability?
All previously released versions of Bond are vulnerable. This includes the first version release 3.x through 9.0. The update is in Bond 9.0.1.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
DOS
EPSS
Связанные уязвимости
A denial of service vulnerability exists when the .NET implementation of Bond improperly parses input, aka 'Bond Denial of Service Vulnerability'.
Уязвимость программной платформы Microsoft .NET Bond, связанная с недостаточноой проверкой вводимых данный, позволяющая нарушителю вызвать отказ в обслуживании
EPSS