First published: Mon Aug 17 2020(Updated: )
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.osx-x64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-x64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.App.Runtime.linux-arm | >=3.1.0<3.1.7 | 3.1.7 |
nuget/Microsoft.AspNetCore.All | >=2.1.0<2.1.21 | 2.1.21 |
nuget/Microsoft.AspNetCore.App | >=2.1.0<2.1.21 | 2.1.21 |
Microsoft ASP.NET Core | =2.1 | |
Microsoft ASP.NET Core | =3.1 | |
Microsoft Visual Studio 2017 | >=15.0<=15.8 | |
Microsoft Visual Studio 2019 | >=16.0<=16.3 | |
Microsoft Visual Studio 2019 | >=16.5<=16.6 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1597 is a denial of service vulnerability in ASP.NET Core.
CVE-2020-1597 affects Microsoft ASP.NET Core versions 2.1 and 3.1.
CVE-2020-1597 affects Microsoft Visual Studio 2017 (versions 15.0 to 15.8) and Microsoft Visual Studio 2019 (versions 16.0 to 16.6).
CVE-2020-1597 affects Fedora versions 32 and 33.
CVE-2020-1597 has a severity rating of 7.5 (high).
You can find more information about CVE-2020-1597 on the following links: [Link 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT/), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZW4CBI26KSO3PRL3HLVVISXPPOYUHSXO/), [Link 3](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1597).