CVE-2020-1108
published 2020-05-21CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
11.68%
95.6th percentile
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Affected
136 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.win-arm | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.win-arm64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.win-x64 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft.netcore.app.runtime.win-x86 | >= 3.1.0 < 3.1.4 | 3.1.4 |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_2.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.0 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5.1 | — | — |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_10_version_1607 | — | — |
| microsoft | microsoft_net_framework_3.5_and_4.6.2_4.7_4.7.1_4.7.2_on_windows_server_2016 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
.NET Core & .NET Framework Denial of Service Vulnerability
ghsa·2022-05-24
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability
.NET Core & .NET Framework Denial of Service Vulnerability
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
OSV
.NET Core & .NET Framework Denial of Service Vulnerability
osv·2022-05-24
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability
.NET Core & .NET Framework Denial of Service Vulnerability
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Red Hat
dotnet: Denial of service via untrusted input
vendor_redhat·2020-05-12·CVSS 7.5
CVE-2020-1108 [HIGH] CWE-20 dotnet: Denial of service via untrusted input
dotnet: Denial of service via untrusted input
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
An integer overflow condition was found in dotnet and dotnet3.1's BinaryReader Read7BitEncodedInt() method. This method is used by BinaryReader's ReadString() method, and given a certain input, and cause a denial of service to dotnet applications using BinaryReader. The exploitation of this flaw depends on the application but does not inherently require the attacker to be authenticated or have any specific privileges. An attacker could exploit this flaw remotely via the internet by sending crafted data to a dotnet application that is passed into Read7BitEncodedInt(), resul
Microsoft
.NET Core & .NET Framework Denial of Service Vulnerability
vendor_msrc·2020-05-12·CVSS 7.5
CVE-2020-1108 [HIGH] .NET Core & .NET Framework Denial of Service Vulnerability
.NET Core & .NET Framework Denial of Service Vulnerability
Description: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
.NET Core: .NET Core
Issuing CNA: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;L
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901 , a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provi
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
CVE-2020-0901 [CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule
Bugzilla
CVE-2020-1108 dotnet: Denial of service via untrusted input
bugzilla·2020-04-24·CVSS 7.5
CVE-2020-1108 [HIGH] CVE-2020-1108 dotnet: Denial of service via untrusted input
CVE-2020-1108 dotnet: Denial of service via untrusted input
A vulnerability related to handling web requests has been reported in .NET Core and .NET Framework. A remote, unauthenticated attacker can exploit this vulnerability to cause a Denial of Service by sending specially crafted requests to a .NET Core or .NET Framework application.
Discussion:
Acknowledgments:
Name: Microsoft
---
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1108
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:2143 https://access.redhat.com/errata/RHSA-2020:2143
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/
2020-05-21
Published