USN-6578-1: .NET vulnerabilities
Vishal Mishra and Anita Gaud discovered that .NET did not properly validate X.509 certificates with malformed signatures. An attacker could possibly use this issue to bypass an application's typical authentication logic. (CVE-2024-0057) Morgan Brown discovered that .NET did not properly handle requests from unauthenticated clients. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-21319)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6578-1?
The severity of USN-6578-1 is high due to its potential to allow attackers to bypass authentication mechanisms.
How do I fix USN-6578-1?
To fix USN-6578-1, update to the recommended package versions provided in the security notice.
What software is affected by USN-6578-1?
USN-6578-1 affects multiple packages in the .NET runtime ecosystem on Ubuntu 23.10.
What vulnerabilities are addressed in USN-6578-1?
USN-6578-1 addresses issues related to improper validation of X.509 certificates with malformed signatures.
Is there a workaround for USN-6578-1?
There are no recommended workarounds for USN-6578-1; mitigation involves applying the security updates.