CVE-2019-0757
published 2019-04-09CVE-2019-0757: A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
2.70%
84.2th percentile
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nuget | — | — |
| microsoft | microsoft_visual_studio | — | — |
| microsoft | mono_framework | — | — |
| microsoft | mono_framework | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | net_core_sdk | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| microsoft | nuget | — | — |
| mono-project | mono_framework | — | — |
| mono-project | mono_framework | — | — |
| msrc | mono_framework_version_5.18.0.223 | — | — |
| msrc | mono_framework_version_5.20.0 | — | — |
| msrc | net_core_sdk_1.1_on_net_core_1.0 | — | — |
| msrc | net_core_sdk_1.1_on_net_core_1.1 | — | — |
| msrc | net_core_sdk_2.1.500_on_net_core_2.1 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_debian6.5LOW
vendor_msrc6.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c2wg-p84q-4x76: A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's
ghsa_unreviewed·2022-05-13
CVE-2019-0757 [MEDIUM] GHSA-c2wg-p84q-4x76: A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Microsoft
NuGet Package Manager Tampering Vulnerability
vendor_msrc·2019-03-12·CVSS 6.5
CVE-2019-0757 [MEDIUM] NuGet Package Manager Tampering Vulnerability
NuGet Package Manager Tampering Vulnerability
Description: A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure. An attacker who successfully exploited this vulnerability could potentially modify files and folders that are unpackaged on a system.
To exploit this vulnerability, an attacker would need to log on to the affected system and tamper with the folder contents of a package prior to building or installation of an application.
The security update addresses the vulnerability by correcting permissions on folders inside the NuGet packages folder structure.
FAQ: Is there any additional information I need to apply the updates?
Yes. To apply the updates, follow step A1 or A2,
Red Hat
dotnet: NuGet Tampering Vulnerability
vendor_redhat·2019-03-12·CVSS 6.5
CVE-2019-0757 [MEDIUM] CWE-732 dotnet: NuGet Tampering Vulnerability
dotnet: NuGet Tampering Vulnerability
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
A flaw was found in dotnet. A tampering vulnerability exists in NuGet software when executed in a Linux or Mac environment. An attacker who successfully exploits the vulnerability could run arbitrary code in the context of the current user. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Debian
CVE-2019-0757: nuget - A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac ...
vendor_debian·2019·CVSS 6.5
CVE-2019-0757 [MEDIUM] CVE-2019-0757: nuget - A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac ...
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Scope: local
bookworm: resolved
bullseye: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0757 rh-dotnet22: Update to .NET Core Runtime 2.2.3 and SDK 2.2.105 [dotnet-2.2]
bugzilla·2019-03-05·CVSS 6.5
CVE-2019-0757 [MEDIUM] CVE-2019-0757 rh-dotnet22: Update to .NET Core Runtime 2.2.3 and SDK 2.2.105 [dotnet-2.2]
CVE-2019-0757 rh-dotnet22: Update to .NET Core Runtime 2.2.3 and SDK 2.2.105 [dotnet-2.2]
The next version of .NET Core 2.2 is expected to be .NET Core Runtime 2.2.3 and SDK 2.2.105.
We should include it in RHEL 7 to pick up all the bugfixes it provides.
Discussion:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2019:0544
Bugzilla
CVE-2019-0757 dotnet: NuGet Tampering Vulnerability
bugzilla·2019-03-05·CVSS 6.5
CVE-2019-0757 [MEDIUM] CVE-2019-0757 dotnet: NuGet Tampering Vulnerability
CVE-2019-0757 dotnet: NuGet Tampering Vulnerability
A tampering vulnerability exists in NuGet software when executed in a Linux or Mac environment. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:0544 https://access.redhat.com/errata/RHSA-2019:0544
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1259 https://access.redhat.com/errata/RHSA-2019:1259
---
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0757
Bugzilla
CVE-2019-0757 rh-dotnet21: Update to .NET Core Runtime 2.1.9 and SDK 2.1.505 [dotnet-2.1]
bugzilla·2019-03-05·CVSS 6.5
CVE-2019-0757 [MEDIUM] CVE-2019-0757 rh-dotnet21: Update to .NET Core Runtime 2.1.9 and SDK 2.1.505 [dotnet-2.1]
CVE-2019-0757 rh-dotnet21: Update to .NET Core Runtime 2.1.9 and SDK 2.1.505 [dotnet-2.1]
The next version of .NET Core 21 is going to be Runtime 2.1.9 and SDK 2.1.505.
We need to update the version we ship for RHEL 7 to include all the various bugfixes present in this version.
Discussion:
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHSA-2019:0544
2019-04-09
Published