Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16937

Опубликовано: 21 окт. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.

To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.

The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21Not affected
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31Not affected
Red Hat Enterprise Linux 8dotnetNot affected
Red Hat Enterprise Linux 8dotnet3.1Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1906421dotnet: .NET Framework improperly handles objects in memory which could result in Information Disclosure

EPSS

Процентиль: 87%
0.03288
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
почти 6 лет назад

<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability, an authenticated attacker would need to run a specially crafted application.</p> <p>The update addresses the vulnerability by correcting how the .NET Framework handles objects in memory.</p>

CVSS3: 4.7
msrc
почти 6 лет назад

.NET Framework Information Disclosure Vulnerability

CVSS3: 4.7
debian
почти 6 лет назад

<p>An information disclosure vulnerability exists when the .NET Framew ...

CVSS3: 4.7
github
около 4 лет назад

An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory, aka '.NET Framework Information Disclosure Vulnerability'.

CVSS3: 4.7
fstec
почти 6 лет назад

Уязвимость программной платформы Microsoft .NET Framework, связанная с ошибками обработки объектов в памяти, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 87%
0.03288
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2020-16937