REDHAT-BUG-1649693: Medium severity microsoft .net core runtime vulnerability
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the files and directories.
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8416
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1649693?
The severity of REDHAT-BUG-1649693 is classified as high due to the potential for arbitrary file write by an attacker.
How do I fix REDHAT-BUG-1649693?
To fix REDHAT-BUG-1649693, you should upgrade to the latest version of the .NET Core SDK that addresses the vulnerability.
What types of systems are affected by REDHAT-BUG-1649693?
Systems running Microsoft .NET Core SDK are affected by REDHAT-BUG-1649693.
What could an attacker achieve by exploiting REDHAT-BUG-1649693?
An attacker could exploit REDHAT-BUG-1649693 to write arbitrary files and directories to certain locations on a vulnerable system.
Is there a workaround for REDHAT-BUG-1649693?
While the best practice is to apply updates, temporary workarounds might include restricting access to vulnerable components until a patch can be applied.