.NET Core & .NET Framework Denial of Service Vulnerability
Published May 21, 2020
7.5
HIGHCVSS 3.1
EPSS 6.41%
Description
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
Affected products
-
- Version 2.0.0StatusaffectedConstraints<publication
- Version
-
- Version 3.0.0StatusaffectedConstraints<publication
- Version
-
- Version 3.5.0StatusaffectedConstraints<publication
- Version
-
- Version 3.0.0.0StatusaffectedConstraints<publication
- Version
-
- Version 3.5.0StatusaffectedConstraints<publication
- Version
-
- Version 3.0StatusaffectedConstraints<publication
- Version
-
- Version 4.7.0StatusaffectedConstraints<publication
- Version
-
- Version 4.8.0StatusaffectedConstraints<publication
- Version
-
- Version 3.5.0StatusaffectedConstraints<publication
- Version
-
- Version 4.0.0.0StatusaffectedConstraints<publication
- Version
-
- Version 4.0.0.0StatusaffectedConstraints<publication
- Version
-
- Version 4.0.0.0StatusaffectedConstraints<publication
- Version
-
- Version 4.8.0StatusaffectedConstraints<publication
- Version
- Vendor Microsoft Product Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) Defaultn/a
- Version 15.9.0StatusaffectedConstraints<publication
- Version
-
- Version 16.0StatusaffectedConstraints<publication
- Version
- Vendor Microsoft Product Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3) Defaultn/a
- Version 16.0StatusaffectedConstraints<publication
- Version
-
- Version 16.0StatusaffectedConstraints<publication
- Version
-
- Version 7.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.0StatusaffectedConstraints<publication
- Version
-
- Version 2.1StatusaffectedConstraints<publication
- Version 3.1StatusaffectedConstraints<publication
- Version 5.0.0StatusaffectedConstraints<publication
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework 2.0 Service Pack 2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 3.5.1 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 4.5.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 4.6 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 | n/a |
| ||||||||||||
| Microsoft | Microsoft .NET Framework 4.8 | n/a |
| ||||||||||||
| Microsoft | Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) | n/a |
| ||||||||||||
| Microsoft | Microsoft Visual Studio 2019 version 16.0 | n/a |
| ||||||||||||
| Microsoft | Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3) | n/a |
| ||||||||||||
| Microsoft | Microsoft Visual Studio 2019 version 16.5 | n/a |
| ||||||||||||
| Microsoft | PowerShell 7.0 | n/a |
| ||||||||||||
| Microsoft | PowerShell Core 6.2 | n/a |
| ||||||||||||
| Microsoft | n/a | n/a |
|
Configuration 1
Configuration 2
- 2.0
- 3.0
- 4.6
Running on/with
- n/a
- n/a
Configuration 3
- 3.5
Running on/with
- n/a
- n/a
Configuration 4
- 3.5
- 4.5.2
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- n/a
- r2
Configuration 5
- 3.5
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- 1607
- 1607
Configuration 6
- 3.5
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- n/a
Configuration 7
- 3.5
- 4.6
- 4.6.1
- 4.6.2
Running on/with
- n/a
- n/a
Configuration 8
- 3.5
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- 1709
- 1709
Configuration 9
- 3.5
- 4.7.1
- 4.7.2
Running on/with
- 1709
Configuration 10
- 3.5
- 4.7.2
- 4.8
Running on/with
- 1803
- 1803
Configuration 11
- 3.5
- 4.7.2
- 4.8
Running on/with
- 1809
- n/a
Configuration 12
- 3.5
- 4.8
Running on/with
- 1909
- 1909
Configuration 13
- 3.5
- 4.8
Running on/with
- 1903
- 1903
Configuration 14
- 3.5
- 4.8
Running on/with
- 1903
- 1909
Configuration 15
- 3.5.1
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Configuration 16
- 4.5.2
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
Running on/with
- n/a
Configuration 17
- 4.5.2
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- n/a
Configuration 18
- 4.5.2
Running on/with
- n/a
- r2
Configuration 19
- 4.5.2
Running on/with
- n/a
Configuration 20
- 3.5
- 4.7.2
Running on/with
- 1803
Configuration 21
Configuration 22
- 4.5.2
- 4.6
- 4.6.1
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
- 4.8
Running on/with
- n/a
Configuration 23
- 2.1
- 3.1
- 15.9
- 16.0
- 16.4
- 16.5
Configuration 24
- 7.0
- 6.2
No data.
.NET Core on Red Hat Enterprise Linux
rh-dotnet21-0:2.1-17.el7
Fixed · RHSA-2020:2146
.NET Core on Red Hat Enterprise Linux
rh-dotnet21-0:2.1-18.el7
Fixed · RHSA-2020:2476
.NET Core on Red Hat Enterprise Linux
rh-dotnet21-dotnet-0:2.1.514-2.el7
Fixed · RHSA-2020:2146
.NET Core on Red Hat Enterprise Linux
rh-dotnet21-dotnet-0:2.1.515-1.el7
Fixed · RHSA-2020:2476
.NET Core on Red Hat Enterprise Linux
rh-dotnet31-dotnet-0:3.1.104-2.el7
Fixed · RHSA-2020:2249
.NET Core on Red Hat Enterprise Linux
rh-dotnet31-dotnet-0:3.1.105-1.el7
Fixed · RHSA-2020:2475
Red Hat Enterprise Linux 8
dotnet-0:2.1.514-2.el8_2
Fixed · RHSA-2020:2143
Red Hat Enterprise Linux 8
dotnet-0:2.1.515-1.el8_2
Fixed · RHSA-2020:2471
Red Hat Enterprise Linux 8
dotnet3.1-0:3.1.104-2.el8_2
Fixed · RHSA-2020:2250
Red Hat Enterprise Linux 8
dotnet3.1-0:3.1.105-2.el8_2
Fixed · RHSA-2020:2450
Red Hat Enterprise Linux 8
dotnet3.0
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet21-0:2.1-17.el7 | Fixed | RHSA-2020:2146 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet21-0:2.1-18.el7 | Fixed | RHSA-2020:2476 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet21-dotnet-0:2.1.514-2.el7 | Fixed | RHSA-2020:2146 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet21-dotnet-0:2.1.515-1.el7 | Fixed | RHSA-2020:2476 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet31-dotnet-0:3.1.104-2.el7 | Fixed | RHSA-2020:2249 |
| .NET Core on Red Hat Enterprise Linux | rh-dotnet31-dotnet-0:3.1.105-1.el7 | Fixed | RHSA-2020:2475 |
| Red Hat Enterprise Linux 8 | dotnet-0:2.1.514-2.el8_2 | Fixed | RHSA-2020:2143 |
| Red Hat Enterprise Linux 8 | dotnet-0:2.1.515-1.el8_2 | Fixed | RHSA-2020:2471 |
| Red Hat Enterprise Linux 8 | dotnet3.1-0:3.1.104-2.el8_2 | Fixed | RHSA-2020:2250 |
| Red Hat Enterprise Linux 8 | dotnet3.1-0:3.1.105-2.el8_2 | Fixed | RHSA-2020:2450 |
| Red Hat Enterprise Linux 8 | dotnet3.0 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2020-1108 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1827643 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2252 Advisory
- https://github.com/advisories/GHSA-3w5p-jhp5-c29q Advisory
- https://github.com/dotnet/announcements/issues/157
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1108 vendor-advisorypatch
- https://nvd.nist.gov/vuln/detail/CVE-2020-1108
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1108 PatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1108
Change history (0)
No recorded changes yet.