Описание
.NET and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. In System.Text.Json, applications that deserialize input to a model with an [ExtensionData] property can be vulnerable to an algorithmic complexity attack, resulting in a denial of service.
Отчет
.NET 6.0 (dotnet6.0) was released for RHEL 8 starting with RHEL 8.5. Therefore, this .NET version is not affected in RHEL 8.4 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 8 starting with RHEL 8.9. Therefore, this .NET version is not affected in RHEL 8.8 and previous versions. .NET 8.0 (dotnet8.0) was released for RHEL 9 starting with RHEL 9.3. Therefore, this .NET version is not affected in RHEL 9.2 and previous versions.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 9 | dotnet7.0 | Not affected | ||
Red Hat Enterprise Linux 9 | dotnet9.0 | Not affected | ||
Red Hat Enterprise Linux 8 | dotnet6.0 | Fixed | RHSA-2024:7851 | 09.10.2024 |
Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2024:7868 | 09.10.2024 |
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | dotnet6.0 | Fixed | RHSA-2024:8082 | 14.10.2024 |
Red Hat Enterprise Linux 8.6 Telecommunications Update Service | dotnet6.0 | Fixed | RHSA-2024:8082 | 14.10.2024 |
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | dotnet6.0 | Fixed | RHSA-2024:8082 | 14.10.2024 |
Red Hat Enterprise Linux 8.8 Extended Update Support | dotnet6.0 | Fixed | RHSA-2024:8036 | 14.10.2024 |
Red Hat Enterprise Linux 9 | dotnet6.0 | Fixed | RHSA-2024:7867 | 09.10.2024 |
Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2024:7869 | 09.10.2024 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Microsoft Security Advisory CVE-2024-43485 | .NET Denial of Service Vulnerability
Уязвимость программной платформы Microsoft .NET и редактора исходного кода Visual Studio, связанная с алгоритмической сложностью, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3