First published: Thu Oct 19 2023(Updated: )
Kevin Jones discovered that .NET did not properly process certain X.509 certificates. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-36799) It was discovered that the .NET Kestrel web server did not properly handle HTTP/2 requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-44487)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/aspnetcore-runtime-6.0 | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/aspnetcore-runtime-7.0 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-host | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-host-7.0 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-hostfxr-6.0 | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-hostfxr-7.0 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-runtime-6.0 | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-runtime-7.0 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-sdk-6.0 | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet-sdk-7.0 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet6 | <6.0.123-0ubuntu1 | 6.0.123-0ubuntu1 |
=23.10 | ||
All of | ||
ubuntu/dotnet7 | <7.0.112-0ubuntu1 | 7.0.112-0ubuntu1 |
=23.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is USN-6438-1.
The severity of the vulnerability is not mentioned in the provided information.
This vulnerability can be exploited by an attacker to cause a denial of service or perform remote attacks.
The affected software includes aspnetcore-runtime-6.0, aspnetcore-runtime-7.0, dotnet-host, dotnet-host-7.0, dotnet-hostfxr-6.0, dotnet-hostfxr-7.0, dotnet-runtime-6.0, dotnet-runtime-7.0, dotnet-sdk-6.0, dotnet-sdk-7.0, dotnet6, and dotnet7.
To fix this vulnerability, update the affected software packages to versions 6.0.123-0ubuntu1 (for 6.0 packages) or 7.0.112-0ubuntu1 (for 7.0 packages) or higher.