First published: Thu May 02 2019(Updated: )
It was discovered that RegEx strings were not properly processed, which can be exploited by anauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application. External references: <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Core Runtime |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1705506 is considered to have a high severity due to its potential to cause Denial of Service attacks.
To fix REDHAT-BUG-1705506, you need to apply the latest patches or updates provided by Microsoft for the .NET Core SDK.
REDHAT-BUG-1705506 enables unauthenticated remote attackers to perform Denial of Service attacks on .NET Core applications.
REDHAT-BUG-1705506 affects Microsoft .NET Core SDK applications that handle RegEx strings.
No, authentication is not required to exploit REDHAT-BUG-1705506, making it particularly concerning.