Lucene search

K
ubuntuUbuntuUSN-6438-2
HistoryOct 25, 2023 - 12:00 a.m.

.Net regressions

2023-10-2500:00:00
ubuntu.com
38
ubuntu
dotnet6
dotnet7
.net
regressions
cve-2023-36799
cve-2023-44487
denial of service
kestrel web server
http/2
x.509 certificates

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

8.8

Confidence

High

EPSS

0.816

Percentile

98.4%

Releases

  • Ubuntu 23.10

Packages

  • dotnet6 - dotNET CLI tools and runtime
  • dotnet7 - dotNET CLI tools and runtime

Details

USN-6438-1 fixed vulnerabilities in .Net. It was discovered that the fix
for CVE-2023-36799 was incomplete. This update fixes the problem.

Original advisory details:

Kevin Jones discovered that .NET did not properly process certain
X.509 certificates. An attacker could possibly use this issue to
cause a denial of service. (CVE-2023-36799)

It was discovered that the .NET Kestrel web server did not properly
handle HTTP/2 requests. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2023-44487)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchaspnetcore-runtime-6.0< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchaspnetcore-targeting-pack-6.0< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-apphost-pack-6.0< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-apphost-pack-6.0-dbgsym< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-host< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-host-dbgsym< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-hostfxr-6.0< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-hostfxr-6.0-dbgsym< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-runtime-6.0< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Ubuntu23.10noarchdotnet-runtime-6.0-dbgsym< 6.0.124-0ubuntu1~23.10.1UNKNOWN
Rows per page:
1-10 of 341

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

8.8

Confidence

High

EPSS

0.816

Percentile

98.4%