USN-7105-1: .NET vulnerabilities
It was discovered that the NrbfDecoder component in .NET did not properly handle an instance of a type confusion vulnerability. An authenticated attacker could possibly use this issue to gain the privileges of another user and execute arbitrary code. (CVE-2024-43498) It was discovered that the NrbfDecoder component in .NET did not properly perform input validation. An unauthenticated remote attacker could possibly use this issue to cause a denial of service. (CVE-2024-43499)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7105-1?
USN-7105-1 addresses a type confusion vulnerability in .NET that could allow an authenticated attacker to execute arbitrary code.
How do I fix USN-7105-1?
To mitigate USN-7105-1, update the affected packages to the latest version, specifically to 9.0.0-rtm-0ubuntu1~24.10.1 or higher.
What products are affected by USN-7105-1?
USN-7105-1 affects multiple .NET packages including aspnetcore-runtime-9.0, dotnet-host-9.0, dotnet-runtime-9.0, and others on Ubuntu 24.10.
Who is vulnerable to the USN-7105-1 flaw?
Only authenticated users who can exploit the type confusion vulnerability in the NrbfDecoder component of .NET are vulnerable to USN-7105-1.
What impact can an attacker have if USN-7105-1 is exploited?
If exploited, an attacker could gain elevated privileges and potentially execute arbitrary code, compromising the security of the system.