CVE-2018-0875
published 2018-03-14CVE-2018-0875: .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
9.44%
94.9th percentile
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | powershell_core | — | — |
| microsoft_corporation | net_core | — | — |
| msrc | net_core_1.0 | — | — |
| msrc | net_core_1.1 | — | — |
| msrc | net_core_2.0 | — | — |
| msrc | powershell_core_6.0.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
.NET Core Denial of Service Vulnerability
osv·2022-05-13
CVE-2018-0875 [HIGH] .NET Core Denial of Service Vulnerability
.NET Core Denial of Service Vulnerability
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".
GHSA
.NET Core Denial of Service Vulnerability
ghsa·2022-05-13
CVE-2018-0875 [HIGH] .NET Core Denial of Service Vulnerability
.NET Core Denial of Service Vulnerability
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".
Red Hat
Core: Hash Collision Denial of Service
vendor_redhat·2018-03-13·CVSS 7.5
CVE-2018-0875 [HIGH] Core: Hash Collision Denial of Service
Core: Hash Collision Denial of Service
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".
It was found that string comparisons in .NET Core did not use a secure hashing algorithm. This could allow an attacker to predict string hashes and cause a denial of service by intentionally creating collisions thus forcing long look up times.
Microsoft
.NET Core Denial of Service Vulnerability
vendor_msrc·2018-03-13·CVSS 7.5
CVE-2018-0875 [HIGH] .NET Core Denial of Service Vulnerability
.NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists in the way that .NET Core handles specially crafted requests, causing a hash collision.
To exploit the vulnerability, an attacker could send a small number of specially crafted requests to an .NET Core web application, causing performance to degrade significantly enough to cause a denial of service condition.
The security update addresses the vulnerability by correcting how .NET Core handles specially crafted requests to prevent a hash collision.
.NET Core: .NET Core
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Remediation: Commit
Reference: https://github.com/do
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
### Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
#### Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability
CVE-2018-0876 - Scripting Engine Memory Corruption Vulnerabi
Talos
Microsoft Patch Tuesday - March 2018
blogs_talos·2018-03-13·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018
## Microsoft Patch Tuesday - March 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 74 new vulnerabilities, with 14 of them rated critical and 59 of them rated important. These vulnerabilities impact Internet Explorer, Edge, Exchange, Scripting Engine, Windows Shell and more.
## Critical Vulnerabilities This month, Microsoft is addressing 14 vulnerabilities that are rated as critical.
The vulnerabilities rated as critical are listed below:
CVE-2018-0872 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0874 - Chakra Scripting Engine Memory Corruption Vulnerability CVE-2018-0876 - Script
Bugzilla
CVE-2018-0875 .NET Core: Hash Collision Denial of Service
bugzilla·2018-03-06·CVSS 7.5
CVE-2018-0875 [HIGH] CVE-2018-0875 .NET Core: Hash Collision Denial of Service
CVE-2018-0875 .NET Core: Hash Collision Denial of Service
Case insensitive string comparison uses an insecure hashing algorithm which can be compromised in .NET Core 1.x (Unix) and .NET Core 2.0. The attack vector could be a Dictionary which uses case invariant keys.
Discussion:
Acknowledgments:
Name: Ben Adams (Illyriad Games)
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2018:0522 https://access.redhat.com/errata/RHSA-2018:0522
http://www.securityfocus.com/bid/103225http://www.securitytracker.com/id/1040505https://access.redhat.com/errata/RHSA-2018:0522https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0875http://www.securityfocus.com/bid/103225http://www.securitytracker.com/id/1040505https://access.redhat.com/errata/RHSA-2018:0522https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0875
2018-03-14
Published