First published: Tue Aug 08 2023(Updated: )
.NET Core and Visual Studio Denial of Service Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Microsoft.NetCore.App.Runtime.win-x86 | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.NetCore.App.Runtime.win-x64 | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.NetCore.App.Runtime.win-arm64 | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.NetCore.App.Runtime.win-arm | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x86 | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.AspNetCore.App.Runtime.win-x64 | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm | >=7.0.0<=7.0.9 | 7.0.10 |
nuget/Microsoft.AspNetCore.App.Runtime.win-arm64 | >=7.0.0<=7.0.9 | 7.0.10 |
Microsoft Visual Studio 2022 | =17.2 | |
Microsoft Visual Studio 2022 | =17.4 | |
Microsoft .NET 6.0 | ||
Microsoft .NET | =6.0.0 | |
Microsoft Visual Studio 2022 | >=17.2.0<17.2.18 | |
Microsoft Visual Studio 2022 | >=17.4.0<17.4.10 | |
=6.0.0 | ||
>=17.2.0<17.2.18 | ||
>=17.4.0<17.4.10 | ||
ubuntu/dotnet6 | <6.0.121-0ubuntu1~23.04.1 | 6.0.121-0ubuntu1~23.04.1 |
ubuntu/dotnet6 | <6.0.21 | 6.0.21 |
ubuntu/dotnet6 | <6.0.121-0ubuntu1~22.04.1 | 6.0.121-0ubuntu1~22.04.1 |
ubuntu/dotnet7 | <7.0.110-0ubuntu1~23.04.1 | 7.0.110-0ubuntu1~23.04.1 |
ubuntu/dotnet7 | <7.0.10 | 7.0.10 |
ubuntu/dotnet7 | <7.0.110-0ubuntu1~22.04.1 | 7.0.110-0ubuntu1~22.04.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38178 is high with a severity value of 7.5.
The following software is affected by CVE-2023-38178: Visual Studio 2022 (version 17.2 and 17.4) and .NET 7.0 (versions 7.0.0 to 7.0.9).
To fix CVE-2023-38178, update Visual Studio 2022 to version 17.2.18 or 17.4.10, and update .NET 7.0 to version 7.0.10.
You can find more information about CVE-2023-38178 at the following references: [1](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38178), [2](https://launchpad.net/bugs/cve/CVE-2023-38178), [3](https://security-tracker.debian.org/tracker/CVE-2023-38178).