CVE-2019-0981: High severity microsoft .net core runtime vulnerability
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
Other sources
An error related to IPAddress.TryCreate when processing certain web requests can be exploited by unauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0981
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0981?
CVE-2019-0981 is a denial of service vulnerability in .NET Framework and .NET Core.
How severe is CVE-2019-0981?
CVE-2019-0981 has a severity level of 7.5 (high).
What software is affected by CVE-2019-0981?
CVE-2019-0981 affects Microsoft .NET Core versions 1.0, 1.1, 2.1, and 2.2, as well as Microsoft .NET Framework versions 2.0-sp2, 3.0-sp2, and 3.5.
How can I fix CVE-2019-0981 vulnerability?
To fix the CVE-2019-0981 vulnerability, update your .NET Core and .NET Framework installations to the latest available versions.
Where can I find more information about CVE-2019-0981?
You can find more information about CVE-2019-0981 on the Red Hat and Microsoft security advisories provided in the references.