USN-6889-1: .NET vulnerabilities
It was discovered that .NET did not properly handle object deserialization. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-30105) Radek Zikmund discovered that .NET did not properly manage memory. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2024-35264) It was discovered that .NET did not properly parse X.509 Content and ObjectIdentifiers. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-38095)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6889-1?
The severity of USN-6889-1 is high due to potential denial of service vulnerabilities found in .NET.
How do I fix USN-6889-1?
To fix USN-6889-1, update your affected packages to the recommended versions specified in the advisory.
What versions are affected by USN-6889-1?
USN-6889-1 affects multiple versions of .NET packages on Ubuntu 22.04 and 24.04.
Can USN-6889-1 lead to remote exploitation?
USN-6889-1 does not currently indicate remote exploitation but can cause denial of service if exploited.
Who discovered the issues in USN-6889-1?
The issues in USN-6889-1 were discovered by researchers including Radek Zikmund.