CVE-2019-0757: Medium severity visual studio professional 2017 vulnerability
A tampering vulnerability exists in NuGet software when executed in a Linux or Mac environment. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
Other sources
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0757?
CVE-2019-0757 is a tampering vulnerability in the NuGet Package Manager for Linux and Mac that allows an authenticated attacker to modify a NuGet package's folder structure.
What is the severity of CVE-2019-0757?
The severity of CVE-2019-0757 is high, with a severity value of 6.5.
Which software is affected by CVE-2019-0757?
The affected software includes NuGet Package Manager versions 4.3.1 to 4.9.4, Microsoft Visual Studio 2017, Microsoft .NET Core SDK versions 1.1, 2.1.500, and 2.2.100, and Mono-project Mono Framework versions 5.18.0.223 and 5.20.0.
How can I fix CVE-2019-0757?
To fix CVE-2019-0757, update to NuGet Package Manager version 4.9.5 or later.
Where can I find more information about CVE-2019-0757?
You can find more information about CVE-2019-0757 in the following references: [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:1259), [Microsoft Security Guidance Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0757), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2019:0544).