Lucene search

K
redhatRedHatRHSA-2020:2249
HistoryMay 21, 2020 - 3:09 p.m.

(RHSA-2020:2249) Important: .NET Core on Red Hat Enterprise Linux security and bug fix update

2020-05-2115:09:36
access.redhat.com
47

0.001 Low

EPSS

Percentile

50.5%

.NET Core is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.

New versions of .NET Core that address security vulnerabilities are now available. The updated versions are .NET Core SDK 3.1.104 and .NET Core Runtime 3.1.4.

Security Fix(es):

  • dotnet: Denial of service via untrusted input (CVE-2020-1108)
  • dotnet: Denial of service due to infinite loop (CVE-2020-1161)

Default inclusions for applications built with .NET Core have been updated to reference the newest versions and their security fixes.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.