Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-8421

Опубликовано: 13 сент. 2018
Источник: redhat
CVSS3: 7.8

Описание

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10Not affected
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-dotnetcoreNot affected
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11Not affected
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-dotnetcoreNot affected
.NET Core 2.0 on Red Hat Enterprise Linuxrh-dotnet20Not affected
.NET Core 2.0 on Red Hat Enterprise Linuxrh-dotnet20-dotnetNot affected
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21Not affected
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-dotnetNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1629953NET: RCE when processing untrusted input

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.

msrc
больше 7 лет назад

.NET Framework Remote Code Execution Vulnerability

CVSS3: 9.8
github
больше 3 лет назад

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.

CVSS3: 8.8
fstec
больше 7 лет назад

Уязвимость программной платформы Microsoft.NET Framework, связанная недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3