Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-43485

Опубликовано: 08 окт. 2024
Источник: redhat
CVSS3: 7.5

Описание

.NET and Visual Studio Denial of Service Vulnerability

A flaw was found in dotnet. In System.Text.Json, applications that deserialize input to a model with an [ExtensionData] property can be vulnerable to an algorithmic complexity attack, resulting in a denial of service.

Отчет

.NET 6.0 (dotnet6.0) was released for RHEL 8 starting with RHEL 8.5. Therefore, this .NET version is not affected in RHEL 8.4 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 8 starting with RHEL 8.9. Therefore, this .NET version is not affected in RHEL 8.8 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 9 starting with RHEL 9.3. Therefore, this .NET version is not affected in RHEL 9.2 and previous versions.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9dotnet7.0Not affected
Red Hat Enterprise Linux 9dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet6.0FixedRHSA-2024:785109.10.2024
Red Hat Enterprise Linux 8dotnet8.0FixedRHSA-2024:786809.10.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportdotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicedotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsdotnet6.0FixedRHSA-2024:808214.10.2024
Red Hat Enterprise Linux 8.8 Extended Update Supportdotnet6.0FixedRHSA-2024:803614.10.2024
Red Hat Enterprise Linux 9dotnet6.0FixedRHSA-2024:786709.10.2024
Red Hat Enterprise Linux 9dotnet8.0FixedRHSA-2024:786909.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-407
https://bugzilla.redhat.com/show_bug.cgi?id=2315731dotnet: Denial of Service in System.Text.Json

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
nvd
8 месяцев назад

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
msrc
5 месяцев назад

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
github
8 месяцев назад

Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability

CVSS3: 7.5
fstec
8 месяцев назад

Уязвимость программной платформы Microsoft .NET и редактора исходного кода Visual Studio, связанная с алгоритмической сложностью, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3