CVE-2019-0820
published 2019-05-16CVE-2019-0820: A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.72%
92.2th percentile
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Affected
150 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0980 [HIGH] CWE-835 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
Red Hat
dotnet: timeouts for regular expressions are not enforced
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0820 [HIGH] CWE-400 dotnet: timeouts for regular expressions are not enforced
dotnet: timeouts for regular expressions are not enforced
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Microsoft
.NET Framework and .NET Core Denial of Service Vulnerability
vendor_msrc·2019-05-14·CVSS 7.5
CVE-2019-0820 [HIGH] .NET Framework and .NET Core Denial of Service Vulnerability
.NET Framework and .NET Core Denial of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET application.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to a .NET Framework (or .NET core) application.
The update addresses the vulnerability by correcting how .NET Framework and .NET Core applications handle RegEx string processing.
.NET Framework: .NET Framework
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:Pe
Red Hat
dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
vendor_redhat·2019-05-14·CVSS 7.5
CVE-2019-0981 [HIGH] CWE-400 dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
GHSA
Denial of service in ASP.NET Core
ghsa·2022-05-24·CVSS 7.5
CVE-2019-0980 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
OSV
Denial of service in ASP.NET Core
osv·2022-05-24·CVSS 7.5
CVE-2019-0981 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
GHSA
Denial of service in ASP.NET Core
ghsa·2022-05-24·CVSS 7.5
CVE-2019-0981 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
OSV
Denial of service in ASP.NET Core
osv·2022-05-24·CVSS 7.5
CVE-2019-0980 [HIGH] Denial of service in ASP.NET Core
Denial of service in ASP.NET Core
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
GHSA
Regular Expression Denial of Service in System.Text.RegularExpressions
ghsa·2021-08-04·CVSS 7.5
CVE-2019-0820 [HIGH] CWE-1333 Regular Expression Denial of Service in System.Text.RegularExpressions
Regular Expression Denial of Service in System.Text.RegularExpressions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
OSV
Regular Expression Denial of Service in System.Text.RegularExpressions
osv·2021-08-04·CVSS 7.5
CVE-2019-0820 [HIGH] Regular Expression Denial of Service in System.Text.RegularExpressions
Regular Expression Denial of Service in System.Text.RegularExpressions
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5051 SDL2_image: missing error handler when loading a PCX file can lead to a heap-based buffer overflow and potential code execution
bugzilla·2019-11-29·CVSS 8.8
CVE-2019-5051 [HIGH] CVE-2019-5051 SDL2_image: missing error handler when loading a PCX file can lead to a heap-based buffer overflow and potential code execution
CVE-2019-5051 SDL2_image: missing error handler when loading a PCX file can lead to a heap-based buffer overflow and potential code execution
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
Reference:
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0820
Discussion:
Created mingw-SDL2_image tracking bugs for this issue:
Affects: epel-7 [bug 1778275]
Bugzilla
CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
bugzilla·2019-05-02·CVSS 7.5
CVE-2019-0820 [HIGH] CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
CVE-2019-0820 dotnet: timeouts for regular expressions are not enforced
It was discovered that RegEx strings were not properly processed, which can be exploited by anauthenticated remote attackers to cause a Denial of Service by sending specially crafted requests to a .NET Core application.
External references:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0820
Discussion:
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2019:1236 https://access.redhat.com/errata/RHSA-2019:1236
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1259 https://access.redhat.com/errata/RHSA-2019:1259
2019-05-16
Published