CVE-2019-0657: Input Validation
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
Other sources
It was found that the IdnHost property of System.Uri in .NET core insufficiently validates input. Certain Unicode characters can incorrectly change the meaning of the URI when IDN encoding is applied.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0657?
CVE-2019-0657 is a vulnerability in certain .Net Framework APIs and Visual Studio that allows for URL spoofing.
What is the severity of CVE-2019-0657?
CVE-2019-0657 has a severity level of medium (5.9).
Which software is affected by CVE-2019-0657?
The affected software includes Microsoft .NET Core 1.0, 2.1, and 2.2, Microsoft PowerShell Core 6.0 and 6.1, Microsoft Visual Studio 2017, and Microsoft .NET Framework 2.0 SP2, 3.0 SP2, and 3.5.
How can I fix CVE-2019-0657?
To fix CVE-2019-0657, it is recommended to install the latest security updates provided by Microsoft for the affected software.
Where can I find more information about CVE-2019-0657?
You can find more information about CVE-2019-0657 on Red Hat's website and GitHub.