.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Published Jun 14, 2023
7.5
HIGHCVSS 3.1
EPSS 2.63%
Description
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Affected products
-
- Version 2.0.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.0.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 3.0.0.0StatusaffectedConstraints<10.0.14393.5989
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.4050.0
- Version
-
- Version 4.8.0StatusaffectedConstraints<4.8.4644.0
- Version
-
- Version 4.8.1StatusaffectedConstraints<4.8.9166.0
- Version
-
- Version 4.7.0StatusaffectedConstraints<10.0.10240.19983
- Version
-
- Version 3.5.0StatusaffectedConstraints<3.0.6920.8954; 2.0.50727.8970
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.04043.0
- Version
-
- Version 4.7.0StatusaffectedConstraints<4.7.04043.0
- Version
-
- Version 4.8.0StatusaffectedConstraints<4.8.4644.0
- Version
-
- Version 17.0.0StatusaffectedConstraints<17.0.22
- Version
-
- Version 17.2.0StatusaffectedConstraints<17.2.16
- Version
-
- Version 17.4.0StatusaffectedConstraints<17.4.8
- Version
-
- Version 17.6.0StatusaffectedConstraints<17.6.3
- Version
-
- Version 7.2.0StatusaffectedConstraints<7.2.12
- Version
-
- Version 7.3.0StatusaffectedConstraints<7.3.5
- Version
-
- Version 6.0.0StatusaffectedConstraints<6.0.18
- Version 7.0.0StatusaffectedConstraints<7.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Microsoft .NET Framework 2.0 Service Pack 2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.0 Service Pack 2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.7.2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 AND 4.8.1 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5 and 4.6.2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 3.5.1 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 4.6.2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 | n/a |
| |||||||||
| Microsoft | Microsoft .NET Framework 4.8 | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2022 version 17.0 | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2022 version 17.2 | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2022 version 17.4 | n/a |
| |||||||||
| Microsoft | Microsoft Visual Studio 2022 version 17.6 | n/a |
| |||||||||
| Microsoft | PowerShell 7.2 | n/a |
| |||||||||
| Microsoft | PowerShell 7.3 | n/a |
| |||||||||
| Microsoft | n/a | n/a |
|
Configuration 1
- 4.8
Running on/with
- n/a
- n/a
- r2
- n/a
- r2
- n/a
Configuration 2
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
Running on/with
- r2
- n/a
- r2
Configuration 3
- 4.6.2
Running on/with
- n/a
- n/a
- n/a
- r2
Configuration 4
- 3.5.1
Running on/with
- r2
Configuration 5
- 3.5
- 4.6.2
Running on/with
- n/a
- n/a
Configuration 6
- 3.5
- 4.8.1
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 7
- 3.5
- 4.8
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 8
- 3.5
- 4.7.2
Running on/with
- n/a
- n/a
- n/a
Configuration 9
- 3.5
- 4.6.2
- 4.7
- 4.7.1
- 4.7.2
Running on/with
- n/a
- n/a
- n/a
Configuration 10
- 3.5
Running on/with
- n/a
- r2
Configuration 11
- 3.0
Running on/with
- n/a
- n/a
Configuration 12
- 2.0
Running on/with
- n/a
- n/a
No data.
.NET Core on Red Hat Enterprise Linux
rh-dotnet60-dotnet-0:6.0.118-1.el7_9
Fixed · RHSA-2023:3580
Red Hat Enterprise Linux 8
dotnet6.0-0:6.0.118-1.el8_8
Fixed · RHSA-2023:3582
Red Hat Enterprise Linux 8
dotnet7.0-0:7.0.107-1.el8_8
Fixed · RHSA-2023:3593
Red Hat Enterprise Linux 8.6 Extended Update Support
dotnet6.0-0:6.0.120-1.el8_6
Fixed · RHSA-2023:4448
Red Hat Enterprise Linux 9
dotnet6.0-0:6.0.118-1.el9_2
Fixed · RHSA-2023:3581
Red Hat Enterprise Linux 9
dotnet7.0-0:7.0.107-1.el9_2
Fixed · RHSA-2023:3592
Red Hat Enterprise Linux 9.0 Extended Update Support
dotnet6.0-0:6.0.120-1.el9_0
Fixed · RHSA-2023:4449
.NET Core 3.1 on Red Hat Enterprise Linux
rh-dotnet31-dotnet
Not affected
.NET Core 5.0 on Red Hat Enterprise Linux
rh-dotnet50-dotnet
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet60-dotnet-0:6.0.118-1.el7_9 | Fixed | RHSA-2023:3580 |
| Red Hat Enterprise Linux 8 | dotnet6.0-0:6.0.118-1.el8_8 | Fixed | RHSA-2023:3582 |
| Red Hat Enterprise Linux 8 | dotnet7.0-0:7.0.107-1.el8_8 | Fixed | RHSA-2023:3593 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | dotnet6.0-0:6.0.120-1.el8_6 | Fixed | RHSA-2023:4448 |
| Red Hat Enterprise Linux 9 | dotnet6.0-0:6.0.118-1.el9_2 | Fixed | RHSA-2023:3581 |
| Red Hat Enterprise Linux 9 | dotnet7.0-0:7.0.107-1.el9_2 | Fixed | RHSA-2023:3592 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | dotnet6.0-0:6.0.120-1.el9_0 | Fixed | RHSA-2023:4449 |
| .NET Core 3.1 on Red Hat Enterprise Linux | rh-dotnet31-dotnet | Not affected | n/a |
| .NET Core 5.0 on Red Hat Enterprise Linux | rh-dotnet50-dotnet | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-29331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2212617 Issue Tracking
- https://github.com/advisories/GHSA-555c-2p6r-68mm Advisory
- https://github.com/dotnet/announcements/issues/257
- https://github.com/dotnet/core/blob/c73158b8ef08db362585f9ed16b97c1d1372c666/release-notes/6.0/6.0.18/6.0.18.md
- https://github.com/dotnet/core/blob/c73158b8ef08db362585f9ed16b97c1d1372c666/release-notes/7.0/7.0.7/7.0.7.md
- https://github.com/dotnet/runtime/security/advisories/GHSA-555c-2p6r-68mm
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29331 vendor-advisoryPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-29331
- https://support.microsoft.com/kb/5025823
- https://www.cve.org/CVERecord?id=CVE-2023-29331
Change history (0)
No recorded changes yet.