CVE-2018-0875: High severity asp.net core vulnerability
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".
Other sources
Case insensitive string comparison uses an insecure hashing algorithm which can be compromised in .NET Core 1.x (Unix) and .NET Core 2.0. The attack vector could be a Dictionary which uses case invariant keys.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-0875?
CVE-2018-0875 is a denial of service vulnerability in .NET Core 1.0, .NET Core 1.1, .NET Core 2.0, and PowerShell Core 6.0.0 due to how specially crafted requests are handled.
What software versions are affected by CVE-2018-0875?
CVE-2018-0875 affects .NET Core 1.0, .NET Core 1.1, .NET Core 2.0, and PowerShell Core 6.0.0.
How severe is CVE-2018-0875?
CVE-2018-0875 has a severity rating of 7.5 (high).
How can I fix CVE-2018-0875?
To fix CVE-2018-0875, update to the latest versions of affected software.
Where can I find more information about CVE-2018-0875?
You can find more information about CVE-2018-0875 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/103225), [SecurityTracker](http://www.securitytracker.com/id/1040505), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:0522).