CVE-2018-8409
published 2018-09-13CVE-2018-8409: A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.56%
93.0th percentile
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | >= 2.1 < 2.1.4 | 2.1.4 |
| microsoft | net_core | — | — |
| microsoft | net_core | >= 2.1 < 2.1.4 | 2.1.4 |
| microsoft | system.io.pipelines | — | — |
| microsoft | system.io.pipelines | — | — |
| microsoft | system.io.pipelines | >= 4.5.0 < 4.5.1 | 4.5.1 |
| msrc | asp.net_core_2.1 | — | — |
| msrc | net_core_2.1 | — | — |
| msrc | system.io.pipelines | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
System.IO.Pipelines Denial of Service
vendor_msrc·2018-09-11·CVSS 7.5
CVE-2018-8409 [HIGH] System.IO.Pipelines Denial of Service
System.IO.Pipelines Denial of Service
Description: A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an application that is leveraging System.IO.Pipelines.
The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by providing specially crafted requests to the application.
The update addresses the vulnerability by correcting how System.IO.Pipelines handles requests.
.NET Core: .NET Core
Issuing CNA: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitatio
Red Hat
NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
vendor_redhat·2018-09-11·CVSS 7.5
CVE-2018-8409 [HIGH] CWE-400 NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
Package: rh-dotnetcore10-dotnetcore (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-dotnetcore (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet20-dotnet (.NET Core 2.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet21-dotnet (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
GHSA
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
ghsa·2018-10-16
CVE-2018-8409 [HIGH] Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
OSV
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
osv·2018-10-16
CVE-2018-8409 [HIGH] Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
As per usual, the bulk of the fixes from Microsoft tackle security weaknesses in the company’s Web browsers, Internet Explorer and Edge . Patches also are available for Windows, Office , Sharepoint , and the .NET Framework , among other components.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or m
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to break into Windows computers with little or no help from users.
The zero-day flaw, CVE-2018-8440, affects Microsoft operating systems from Windows 7 through Windows 10 and allows a program launched by a restricted Windows
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
Bugzilla
CVE-2018-8409 .NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
bugzilla·2018-09-06·CVSS 7.5
CVE-2018-8409 [HIGH] CVE-2018-8409 .NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
CVE-2018-8409 .NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
If ReadAsync is being cancelled while producer allocates memory using GetMemory subsequent ReadAsync calls would never block even if there is no new data available causing a tight loop. ReadAsync would start blocking again when producer calls FlushAsync. Only consumers that do not observe IsCancelled flag on ReadResult are affected. .NET Core ≤ 4.5.0 are believed to be vulnerable.
Discussion:
Acknowledgments:
Name: Microsoft
---
External Reference:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8409
---
This was shipped and can be closed.
2018-09-13
Published