CVE-2019-0980: High severity microsoft .net core runtime vulnerability
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
Other sources
An infinite loop flaw related to URI.TryCreate when processing certain web requests can be exploited by unauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-0980
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0980?
CVE-2019-0980 is a denial of service vulnerability in .NET Framework and .NET Core.
How does CVE-2019-0980 affect Microsoft .NET Core?
CVE-2019-0980 affects Microsoft .NET Core versions 1.0, 1.1, 2.1, and 2.2.
How does CVE-2019-0980 affect Microsoft .NET Framework?
CVE-2019-0980 affects Microsoft .NET Framework versions 2.0-sp2, 3.0-sp2, and 3.5.
What is the severity of CVE-2019-0980?
The severity of CVE-2019-0980 is high, with a CVSS score of 7.5.
How can I fix CVE-2019-0980?
To fix CVE-2019-0980, it is recommended to apply the necessary security updates provided by Microsoft.