First published: Thu Nov 09 2023(Updated: )
<a href="https://access.redhat.com/security/cve/CVE-2023-36049">CVE-2023-36049</a> - Arbitrary File Write and Deletion Vulnerability: FormatFtpCommand Microsoft .NET FormatFtpCommand CRLF Injection Arbitrary File Write and Deletion Vulnerability Affected versions: .NET 6.0 .NET 7.0 .NET 8.0
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft .NET Framework | >=6.0<=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2248883 is classified as a high severity vulnerability due to its potential for arbitrary file write and deletion.
To fix REDHAT-BUG-2248883, upgrade to a patched version of .NET, either .NET 8.0, .NET 7.0, or .NET 6.0 that addresses CVE-2023-36049.
REDHAT-BUG-2248883 affects .NET versions 6.0, 7.0, and 8.0.
REDHAT-BUG-2248883 can facilitate attacks that allow an attacker to write and delete files arbitrarily on a vulnerable system.
CVE-2023-36049 is the specific identifier for the arbitrary file write and deletion vulnerability described in REDHAT-BUG-2248883.