Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-8409

Опубликовано: 11 сент. 2018
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-dotnetcoreNot affected
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-dotnetcoreNot affected
.NET Core 2.0 on Red Hat Enterprise Linuxrh-dotnet20-dotnetNot affected
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-dotnetNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1626263NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory

EPSS

Процентиль: 93%
0.06558
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 8 лет назад

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

msrc
почти 8 лет назад

System.IO.Pipelines Denial of Service

CVSS3: 7.5
github
почти 8 лет назад

Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость библиотеки System.IO.Pipelines программных платформ .NET Core и ASP.NET Core, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 93%
0.06558
Низкий

5.1 Medium

CVSS3