Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-43483

Опубликовано: 08 окт. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

A flaw was found in dotnet. The System.Security.Cryptography.Cose, System.IO.Packaging and System.Runtime.Caching components may be exposed to hostile input, making them susceptible to hash flooding attacks, resulting in denial of service.

Отчет

.NET 6.0 (dotnet6.0) was released for RHEL 8 starting with RHEL 8.5. Therefore, this .NET version is not affected in RHEL 8.4 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 8 starting with RHEL 8.9. Therefore, this .NET version is not affected in RHEL 8.8 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 9 starting with RHEL 9.3. Therefore, this .NET version is not affected in RHEL 9.2 and previous versions.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet8.0Affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 9dotnet7.0Not affected
Red Hat Enterprise Linux 9dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet6.0FixedRHSA-2024:785109.10.2024
Red Hat Enterprise Linux 8dotnet8.0FixedRHSA-2024:786809.10.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportdotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicedotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsdotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.8 Extended Update Supportdotnet6.0FixedRHSA-2024:803614.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2315730dotnet: Multiple .NET components susceptible to hash flooding

EPSS

Процентиль: 77%
0.01052
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
nvd
10 месяцев назад

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
msrc
10 месяцев назад

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
github
10 месяцев назад

Microsoft Security Advisory CVE-2024-43483 | .NET Denial of Service Vulnerability

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость программной платформы Microsoft .NET, Microsoft .NET Framework и редактора исходного кода Visual Studio, связанная с алгоритмической сложностью, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01052
Низкий

7.5 High

CVSS3